- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: Radius login for 4104 with 2003 IAS
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2005 04:57 PM
тАО03-29-2005 04:57 PM
Radius login for 4104 with 2003 IAS
Event Type: Warning
Event Source: IAS
Event Category: None
Event ID: 2
Date: 30.3.2005
Time: 8:17:37
User: N/A
Computer: SRV
Description:
User INTRA\miika was denied access.
Fully-Qualified-User-Name = intra.foo.bar/users/Miika
NAS-IP-Address = 192.168.168.235
NAS-Identifier = HP ProCurve Switch 4104GL
Called-Station-Identifier =
Calling-Station-Identifier =
Client-Friendly-Name = procurve
Client-IP-Address = 192.168.168.235
NAS-Port-Type = Virtual
NAS-Port =
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server =
Policy-Name = Connections to other access servers
Authentication-Type = PAP
EAP-Type =
Reason-Code = 66
Reason = The user attempted to use an authentication method that is not enabled on the matching remote access policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2005 10:53 PM
тАО03-29-2005 10:53 PM
Re: Radius login for 4104 with 2003 IAS
To enable this:
- go to the properties of the remote access policy
- Click "edit profile"
- Click the "authentication" tab
- Check the "Unencrypted Authentication (PAP, SPAP) checkbox
- Click "Ok" twice
You should now be able to log in using your windows accounts (if the rest is configured correctly also ;))
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2005 11:27 PM
тАО03-29-2005 11:27 PM
Re: Radius login for 4104 with 2003 IAS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2005 11:45 PM
тАО03-29-2005 11:45 PM
Re: Radius login for 4104 with 2003 IAS
The user property of storing the password with reversible encryption is correct.
Do note that after checking that box you will have to reset the password to take actually effect.
Did you get another message after enabling chap? Because the message really implies it doesn't on the remote access policy. Maybe you have an access policy higher in the list that gets used?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-30-2005 02:34 AM
тАО03-30-2005 02:34 AM
Re: Radius login for 4104 with 2003 IAS
NAS-Port-Type matches "Ethernet" AND
Windows-Groups matches "INTRA\switch"
* Grant access permissions
Edit profile/Authentication, I've tried many possibilities (not the correct ones), checkin only PAP, CHAP, not checkin any.
After I got rid of the other policies, the event log changes slightly to this:
EAP-Type =
Reason-Code = 48
Reason = The connection attempt did not match any remote access policy.
To make sure, I am trying to login using DOMAIN\username syntax with the login session.
Procurve setup is like this:
HP ProCurve Switch 4104GL# show authentication
Status and Counters - Authentication Information
Login Attempts : 3
| Login Login Enable Enable
Access Task | Primary Secondary Primary Secondary
----------- + ---------- ---------- ---------- ----------
Console | Local None Local None
Telnet | Radius Local Radius Local
Port-Access | Local
SSH | Local None Local None
Status and Counters - General RADIUS Information
Deadtime(min) : 3
Timeout(secs) : 5
Retransmit Attempts : 3
Global Encryption Key :
Auth Acct
Server IP Addr Port Port Encryption Key
--------------- ----- ----- --------------------------------
192.168.168.4 1812 1813 testi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-05-2005 12:22 AM
тАО04-05-2005 12:22 AM
Re: Radius login for 4104 with 2003 IAS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-22-2006 12:19 AM
тАО11-22-2006 12:19 AM
Re: Radius login for 4104 with 2003 IAS
The only problem is when I tried to use authentication method other than PAP. Even when procurve authentication showing RadiusCHAP, you can only use PAP on the IAS.
Can any of the Procurve guru explain this? Seems to me for every single question about this never goes further than successful PAP authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-22-2006 10:42 PM
тАО11-22-2006 10:42 PM
Re: Radius login for 4104 with 2003 IAS
Finally I got to use CHAP for authentication.
Actually I managed to do this last week but was not documented, and both server and switch were turned off on the weekend and has not work since.
This time I wrote down everything, rebooted both server and switch several time and tested successfully after each reboot (for stability and reliability measure)
If anyone interested I will post it here after I tidy up the documentation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-30-2006 02:22 PM
тАО11-30-2006 02:22 PM
Re: Radius login for 4104 with 2003 IAS
Do you mind posting your documentation on how you achieved this? I'm sure it will be helpful to others in the future.
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-02-2007 06:48 AM
тАО03-02-2007 06:48 AM
Re: Radius login for 4104 with 2003 IAS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-23-2008 08:55 AM
тАО10-23-2008 08:55 AM
Re: Radius login for 4104 with 2003 IAS
I found this old thread where this exact problems claims to have been solved. However, I don't see the solution. Can someone that has this working post the solution?