Switches, Hubs, and Modems
Showing results for 
Search instead for 
Did you mean: 

Radius login for 4104 with 2003 IAS

Valued Contributor

Radius login for 4104 with 2003 IAS

I am trying to configure 4104 to authenticate with win server 2003 IAS, so I could login to switch management with windows accounts, not to implement port based authentication. Radius accounts fail to authenticate and IAS logs show that I try to use PAP method, instead of EAP. Any ideas if the problem is on IAS or 4104?

Event Type: Warning
Event Source: IAS
Event Category: None
Event ID: 2
Date: 30.3.2005
Time: 8:17:37
User: N/A
Computer: SRV
User INTRA\miika was denied access.
Fully-Qualified-User-Name = intra.foo.bar/users/Miika
NAS-IP-Address =
NAS-Identifier = HP ProCurve Switch 4104GL
Called-Station-Identifier =
Calling-Station-Identifier =
Client-Friendly-Name = procurve
Client-IP-Address =
NAS-Port-Type = Virtual
NAS-Port =
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server =
Policy-Name = Connections to other access servers
Authentication-Type = PAP
EAP-Type =
Reason-Code = 66
Reason = The user attempted to use an authentication method that is not enabled on the matching remote access policy.

Respected Contributor

Re: Radius login for 4104 with 2003 IAS

The IAS server is saying that you don't have PAP enabled for the remote access policy, while the 4104 is using PAP.
To enable this:
- go to the properties of the remote access policy
- Click "edit profile"
- Click the "authentication" tab
- Check the "Unencrypted Authentication (PAP, SPAP) checkbox
- Click "Ok" twice

You should now be able to log in using your windows accounts (if the rest is configured correctly also ;))
Valued Contributor

Re: Radius login for 4104 with 2003 IAS

I've enabled PAP in IAS by checking the PAP. But I am uncertain, if AD policies will prevent the login attempts or not, if PAP sends the request unencrypted. I am pretty sure that the procurve side is ok, but should need to configure Routing and remote access server, or is IAS enough? Some documents also suggest that I should check the "store passwords using reversible encryption" in AD user manager.
Respected Contributor

Re: Radius login for 4104 with 2003 IAS

Routing and Remote access is not needed for a working RADIUS solution, so you don't have to search there.
The user property of storing the password with reversible encryption is correct.
Do note that after checking that box you will have to reset the password to take actually effect.

Did you get another message after enabling chap? Because the message really implies it doesn't on the remote access policy. Maybe you have an access policy higher in the list that gets used?
Valued Contributor

Re: Radius login for 4104 with 2003 IAS

I deleted all other remote access policies and left only the one that I created for ad usergroup. This policy contains:

NAS-Port-Type matches "Ethernet" AND
Windows-Groups matches "INTRA\switch"

* Grant access permissions

Edit profile/Authentication, I've tried many possibilities (not the correct ones), checkin only PAP, CHAP, not checkin any.

After I got rid of the other policies, the event log changes slightly to this:

EAP-Type =
Reason-Code = 48
Reason = The connection attempt did not match any remote access policy.

To make sure, I am trying to login using DOMAIN\username syntax with the login session.

Procurve setup is like this:

HP ProCurve Switch 4104GL# show authentication

Status and Counters - Authentication Information

Login Attempts : 3

| Login Login Enable Enable
Access Task | Primary Secondary Primary Secondary
----------- + ---------- ---------- ---------- ----------
Console | Local None Local None
Telnet | Radius Local Radius Local
Port-Access | Local
SSH | Local None Local None

Status and Counters - General RADIUS Information

Deadtime(min) : 3
Timeout(secs) : 5
Retransmit Attempts : 3
Global Encryption Key :

Auth Acct
Server IP Addr Port Port Encryption Key
--------------- ----- ----- -------------------------------- 1812 1813 testi

Frequent Advisor

Re: Radius login for 4104 with 2003 IAS

From your former it seems that for logins the NAS-Port-Type is Virtual. Your policy matches only Ethernet. Remove the NAS-Port-Type from your policy or change it from Ethernet to Virtual.
New Member

Re: Radius login for 4104 with 2003 IAS

All setup guide that I've encountered seems very straight forward and easy to follow.
The only problem is when I tried to use authentication method other than PAP. Even when procurve authentication showing RadiusCHAP, you can only use PAP on the IAS.

Can any of the Procurve guru explain this? Seems to me for every single question about this never goes further than successful PAP authentication
New Member

Re: Radius login for 4104 with 2003 IAS

Wow, I did it.
Finally I got to use CHAP for authentication.
Actually I managed to do this last week but was not documented, and both server and switch were turned off on the weekend and has not work since.
This time I wrote down everything, rebooted both server and switch several time and tested successfully after each reboot (for stability and reliability measure)
If anyone interested I will post it here after I tidy up the documentation.
Honored Contributor

Re: Radius login for 4104 with 2003 IAS

Hi Iwan,

Do you mind posting your documentation on how you achieved this? I'm sure it will be helpful to others in the future.

New Member

Re: Radius login for 4104 with 2003 IAS

Could you post your documentation on here?