802.1x trouble: Can't get Nortel IP Phone to authenticate to NPS server through HP ProCurve switch
I've been working on getting 802.1x set up. I've so far gotten WinXP clients to authenticate through our HP ProCurve switch to the NPS server using PEAP/EAP-MSCHAPv2, and to put different authorized users on different VLANs based on AD Groups, as well
as unauthorized users onto a separate VLAN. Also, the switch is using the NPS server for securing management logons.
However, when I configure and plug in a Nortel phone, I can see the EAP packets going to the switch, which then send the Access-Request message to the NPS server. On the NPS server, I can see that the NIC receives the Access-Request packet, but it
never responds to it. When I compare the packet to an Access-Request packet from a WinXP client, the only differences I can see are User-Name (1), Port (5), Port-ID (87), Calling-Station-ID (31) and the EAP-Message (79), which to me are the fields that
*should* be different. I can also see that the packet is coming in on the correct port (1812). Nothing gets logged in Event Viewer, nor in the NPS log (c:\windows\system32\logfiles\inDDMMYY.log).
It's my understanding that at least, I should be getting an IAS_NO_POLICY_MATCH in the log, as I haven't set up a policy for it yet. Also, if I set up a dummy policy to accept all requests on all days and times, using any authentication method, I still
get nothing.
The phone is set to use PEAP, but if I understand correctly, even if that was set wrong, I should at least see an Access-Challenge response packet from the server; PEAP doesn't factor in quite that early. Or do I misunderstand?
Any help would be appreciated.
Thanks for the reply.
> At the command prompt, type the following command, and then press ENTER:
> auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
I had read about that previously. I had checked whether it was enabled or not, and it only had failure enabled. So following the recomendation on that
page, I disabled both, then enabled both. So yes, it's currently enabled. And after this, I tried both the PC and phone again, and while I saw the PC's authentication succeed in the Event Log, I still see nothing for the phone.
> PEAP does not specify an authentication method, but provides additional security for other EAP authentication protocols, such as Extensible
Authentication Protocol-Microsoft Challenge Handshake Authentication Protocol version 2 (EAP-MS-CHAP v2), that can operate through the TLS encrypted channel provided by PEAP.
Yeah, but
if I understand correctly (and I'm going to read your link right after I post this), after the switch sends the initial Access-Request message in the clear, the RADIUS server should then respond with an Access-Challenge to begin securing the connection beween
itself and the phone, regardless of what the phone has set for it's security type. If the phone can't talk in a way that the server is set to accept, then it won't respond to the Access-Challenge packet, but the server should be sending that Access-Challenge
in the first place. Or is there something I've missed in the Access-Request packet that specifies what security type(s) it can handle? I thought that happened after the Access-Challenge?
> Please also provide us the type of your Nortel IP Phone, because some types of Nortel IP Phone may only support EAP-MS-CHAP v1 which is not supported by Windows
2008. We also suggest that you might post your issue on Nortel forums to ask for some more help.
I'm
using a Nortel 1120e phone for testing; we also have 1140e phones that will be used with this when it's working, but they should be the same as far as this setup is concerned. I read somewhere that perhaps the Nortel phones only support PEAP-MD5, which
doesn't seem to be an option in NPS without a reghack. I'm also following up with our Nortel support locally, as the phone itself and the manual for the phone only says "PEAP" without specifying what it's using inside, but right now I'm trying to determine
whether the problem lies with the phone or the server or both. So I thought I'd ask the experts here.
FWIW,
I've been testing using a HP ProCurve 3400cl with the lastest firmware. I've managed to get the same setup on a Cisco Catalyst 3550 switch, also on it's latest firmware, and I get the same results. The PCs can authenticate, the phone can't; NPS
still isn't responding.
Similar Messages
-
I've forgotten my passcode and can't get into the phone to turn off "find my iphone" in order to restore it... Can anyone help?
If you know the password to your apple id login - you can then do a restoration once you have put your device into recovery mode using itunes.
read this article to give you direction how to put your device into recovery mode.
Once you have put in your apple id login and password this then will allow you to restore the device once the device is placed in recovery mode.
good luck!
http://support.apple.com/kb/ht1808 -
My iPhone is locked due to setting up a passcode after loading new version 7. I have tried to reset but keep getting turn of "find my iphone". I can't get into the phone to turn this off. What do I do now?
Try this - http://support.apple.com/kb/ht1212 - also you can sign into www.icloud.com and remote erase the phone
recovery mode restore as descibed in HT1808 might be your last resort though -
I just bought a Iphone 5 -- my Iphone 4 and my ipad used to automatically sinc calendars via the Icloud whenever I entered anything on either device -- I can not get the new phone to do this.I have check the settings on both devices and they seem to be t
There are only two things that you must do to connect a device to calendars:
1) In settings>icloud, you must log in, WITH THE CORRECT ID/PASSWORD, and
2) Turn on calendars on the same page.
You said that the iphone 4 and ipad **used** to automatically sync. Do they no long sync? -
How do I transfer contacts from an Android to an iphone 6? I have backed up everything to Verizon Cloud but I can't get the two phones to pair up?
The problem is non compatible devices. You could go to a Verizon corporate store and they could try to transfer them, however many customers stated this has resulted in loss of contacts. They don't guarantee a transfer.
http://www.macworld.co.uk/how-to/iphone/transfer-contacts-music-photos-apps-from-android-iphone-3459466/
Move content from your Android phone to iPhone - Apple Support
Verizon's cloud is rated at the bottom.
Good Luck -
Help please anyone...I can't get into my phone and I don't know what to do!
iPhone and iPod touch: Unable to restore
-
My iPhone five decided to go crazy and give me a white screen with black stripes and I can't get into my phone. I can only use Siri! What's happening?
You posted in the iPad forum instead of the iPhone forum. To get answers to your question, next time post in the proper forum. See https://discussions.apple.com/index.jspa I'll request that Apple relocate your post.
Cheers, Tom -
My Iphone is disabled and I plugged it into Itunes to restore it but it's saying that I can't do it without turning off "Find My Phone" in my setting, but obviously I can't get into my phone. What do I do?
www.cloud.com
-
Can't get iphone to connect to itunes...went through all 7 steps on this site....any advice
It has just occurred to me to ask what seems like a dumb question, when it says to plug in, that does mean plug into electric power, not your iMac, right?
-
TS2734 Passcode has been forgotten...How can I get into the phone?
Help! My passcode has ben lost/forgotten....How can I get into the phone?
Try this
http://support.apple.com/kb/HT1212 -
HT1212 My iPhone has been disabled because of a forgotten passcode how can I get into my phone
My iPhone has been locked because I forgot my passcode. How can I get into my phone?
Restore it as explained in the article you were just reading. If you're running iOS 7 with Find My iPhone enabled, you'll have to force it into recovery mode in order to restore it (see http://support.apple.com/kb/ht1808).
-
Forgot my 4 number passcode... how can i get into my phone?
how can i get into my phone or reset it if i forgot the 4 number passcode?
http://support.apple.com/kb/ht1212
-
I can't get the finger service to work in Messaging Server 3.01.
I can't get the finger service to work in Messaging Server 3.01.
<P>
This is a known problem in 3.01. There is a patch which
fixes this problem. It is available at:
<P>
ftp://[email protected]/messaging/m301ptch.exe
<P>
the password is: bet@NOW!Hi David
Say you have term <foo> and definition <bar> pair. Here term (any text you want highlight) is used in document at many places and definition is defined once as complete paragraph anywhere (i.e. in table cell). if same term is define at multiple places first definition is taken.
Use marker text same as your term text <foo> for tagging both term and definition.
Use Glossary marker to tag definition
Use GlossaryTerm marker to tag term
We have taken feedback to update the FrameMaker help on this.
For in place highlighting you may also try expanded text http://help.adobe.com/en_US/FrameMaker/9.0/Using/WS9FDAD957-2A30-4251-B520-EC32E0A8097B.ht mlhttp://help.adobe.com/en_US/FrameMaker/9.0/Using/WS9FDAD957-2A30-4251-B520-EC32E0A8097B.ht ml Now in FM 12 expanded text is inside Special > Publish Options > …
Hope it clarifies your doubts
Thanks
Amit -
I can not get my I phone 4 to turn on. I have plugged it in and followed the instructions. I keep getting an error message on my phone.
Excellent!
Please note the following:
Note: iCloud Backup does not back up music, movies, and TV shows that you did not purchase from the iTunes Store, or any podcasts, audio books, or photos that you originally synced from your computer. iCloud Backup will restore your purchased music, movie, and app content from the iTunes and App Stores during the background restore process. Previous purchases may be unavailable if they are no longer in the iTunes Store, App Store, or iBookstore.
The above comes from this article:
Choosing an iOS backup method (Should I use iTunes or iCloud to back up my iOS device?)
Best of luck with this. -
My iPhone was set up by a friend and she put her email address in and I do not have her password and can not get into my phone to download anything now...what can I do ? Thanks in advance
As explained here, have your friend turn off Find My iPhone (iPad).
http://support.apple.com/kb/HT5818
Hand her the iPad so she can do that.
Then do Settings > General > Reset > Erase all content and settings and start over with a brand new iPad (as if it just came out of the box).
Maybe you are looking for
-
IPhone 4 will not activate with Apple for update
No matter how hard I try, or how many times I try I cannot get my sister in law's iPhone 4s to update it's software to 5.1 Despite it being connected to a strong wireless signal that I managed to update mine from on my laptop, it downloads the updat
-
ARQ: "No Provisioning log available" message in Access Request
Hi, I am facing a problem wherein, a request is duly provisioned and closed. However, in email notification, I get below message: Hi XXX, The Request number : 123 , has been processed by XYZ and the Request is Closed. The details are as follows: No P
-
Detach BT Keyboard/Mouse, attaching to another...t
I have my Bluetooth keyboard and mouse attached to my PowerBook. But now I have a new Mac Pro, I want to connect them to the new system. Any idea how do I detach it? Without disabling the bluetooth, just in case if I need to use some other device wit
-
Here is the crash report: Process: Adobe Photoshop CS4 [1176] Path: /Applications/Adobe Photoshop CS4/Adobe Photoshop CS4.app/Contents/MacOS/Adobe Photoshop CS4 Identifier: com.adobe.Photoshop Version: 11.0.1 (11.0.1x2
-
My hot corners suddenly stopped working. settings are correct. os 10.6.8
my hot corners suddenly stopped working. settings are correct. os 10.6.8