Airport Extreme: PEAP authentication failure when NAT is enabled

Setup: Airport Extreme firmware 5.6, Windows Admin Utility 5.2
Airport's WAN port connected to an internal network with Windows 2003 IAS RADIUS server; Airport's LAN port disconnected.
Windows XP client (using Microsoft zero-configuration client)
client and server set up to use PEAP authentication
If I set up the Airport in bridge mode (uncheck the "Distribute IP Addresses" box in the Network setup tab), the client can authenticate correctly and can obtain an IP address from a DHCP server on my internal network.
If I check the "Distribute IP Addresses" box, select "Share a single address with DHCP & NAT" and the 192.168.1.1/24 address range, the client can no longer authenticate. I haven't changed anything else on either the Airport or the RADIUS server.
Network traces taken on the wired (WAN) and wireless side of the Airport show that the first few exchanges of the EAP handshake go through fine, but the server's reply to the client's "TLS Hello" message are being blocked by the Airport. Up to that point, I don't see any significant difference between the exchanges with NAT enabled or disabled; it's just that the Airport passes the server's message to the client correctly when NAT is off and blocks it when NAT is on.
Airport Extreme   Windows XP  

My mistake - posted to the wrong forum! I've restarted the thread on the Airport Extreme forum.

Similar Messages

  • How do you use Airport extreme at hotels etc, when traveling? I can plug my computer into the Airport with my ethernet but how does Airport pickup signal?

    How do you use Airport extreme at hotels etc, when traveling? I can plug my computer into the Airport with my ethernet but how does Airport pickup signal? What equipment & devices do I need to travel with to make this possible?

    You may mean the AirPort Express.....not AirPort Extreme.....as the Express is a popular travel router.
    The whole idea behind using this device is that the hotel must provide an Ethernet jack in the hotel room. Then you connect the AirPort Express to the Ethernet jack with an Ethernet cable and configure it to provide your own wireless network in the room. You still have to agree to terms, pay the fees, etc.
    The problem with this approach is that it is getting very difficult to find hotels in North America that prrovide an Ethernet jack....most have moved to wireless networks and the others are not far behind.
    So, if the hotel is already providing a wireless signal, the AirPort Express is of no use in that situation.
    If you normally stay at the same hotels, and know that they provide Ethernet ports, an AirPort Express might make sense in terms of convenience.

  • How to solve the error message "Could not activate cellular data network: PDP authentication failure"when using 3g or gPRS on safari with an iphone 4 and latest software updates

    Please can someone help me to solve the error message "Could not activate cellular data network: PDP authentication failure"when using 3G or GPRS on safari with an iphone 4GS and latest software updates. I have tried resetting the network and phone settings. I have restored the factory settings on itunes and still the problem persists.

    All iPhones sold in Japan are sold carrier locked and cannot be officially unlocked by the carrier. If you unlocked it, it was by unauthorized means (hacked), and support cannot be given to you in this forum.
    Hacked iPhones are subject to countermeasures by Apple, particularly when updating the firmware. It is likely permanently re-locked or permanently disabled.
    Message was edited by: modular747

  • Airport Extreme intermittent WiFi failure

    Airport Extreme used as a wireless network bridge to a DSL (Cincinnati Bell) modem with multiple devices without fail for 2 years.  Lately the Airport intermittently drops the wireless connection. After a short, inconsistent duration, the AIrport reestablishes the connection.  During the failure the status light remains green and no failure is detected or annunciated in the management app.  This failure frequency has inreased over several months.
    I've ruled out modem failure by trying another brand wireless router.  I've reset the Airport and updatred to latest firmware without success.

    O.R.E, Welcome to the discussion area!
    Which Power Mac G5 do you have? The latest models are not compatible with the AirPort Extreme card. See KB 302721, Power Mac G5 (Late 2005) AirPort and Bluetooth options.
    Assuming you have an earlier Power Mac G5 which is compatible with the AirPort Extreme card, one or more of the following must be true:
    The AirPort Extreme card is not installed correctly.
    The AirPort Extreme card is defective.
    The Power Mac G5's motherboard is defective.

  • Airport Extreme emitting flickering sound when Airplaying...is this normal?

    Hi all...I just got my ATV2 over the weekend...and am really excited over it. It was really an experience airplaying. Yesterday, I realised while my ATV2 is airplaying, my Airport Extreme (which is the connecting modem) emits a flickering sound...like a time bomb. it stops when I stop airplaying. It was loud, cos I had both devices in my bedroom. Extreme is just beside my bed. I checked, and its definitely coming from my Extreme, and dependable on Airplay. My thought was it was running the wifi connection at an usually fast rate than usual (It stops immediately when I turned off my wifi on my iPhone4 which I sent my songs over from). Is the flickering sound normal?

    If the Extreme is under warranty I think I'd enquire with Apple direct as even if it's working ok now, it may be the sign of another problem, and if nothing else that ticking noise will be annoying/distracting for you.
    Just make sure it is the extreme not the audio from AppleTV 2 when streaming to it - if you have interference on a wi-fi connection you can get choppy sound from Airport devices including AppleTV.
    Also you might want to post in the Airport discussion area in case anyone has experienced similar issues:
    https://discussions.apple.com/community/wireless/airport
    Good luck.
    AC

  • Authentication failure when attempting to pair mouse

    For the last couple years I've had my Iogear Bluetooth mouse paired nicely with my Powerbook via a USB Bluetooth dongle (the built-in bluetooth doesn't work). Last week I paired my mouse with a friend's MacBook for several hours. When I tried to resume using the mouse with my own Powerbook, it was no longer paired, so I made a trip to Bluetooth Mouse Setup to initiate a new pairing. Unfortunately this no longer works; it finds the mouse successfully, but shortly after it reaches the "Pairing with your Bluetooth mouse" step, it displays a message in red lettering:
    The pairing attempt was unsuccessful due to authentication failure. When ready, click Continue to try again.
    I've retried the process many times during the last few evenings, but to no avail. Discoverable is turned on. I even reinstalled the Mac OS X 10.5.8 Combo update - still no go. Today I took my Bluetooth USB dongle and mouse to a Windows computer at work, and pairing worked just fine there, so I know it is not a hardware issue. Has anyone encountered this pairing error, and been able to resolve it?

    I've been going crazy with this issue the last two days.
    I had previously been using a Targus Bluetooth Mouse for Mac, but I have had to revert to an old Powerbook G4 as my main computer. I wanted to continue using my bluetooth mouse so after two tries I finally found a bluetooth dongle that the Mac recognizes. It seems to work like a charm, and is only annoying because of its bright green LED that blinks ceaselessly.
    However I was most disappointed to find that when attempting to pair with my mouse, it recognized the mouse, connected, but then stalled out on the pairing process with the same red text message mentioned here.
    I tried pairing with my old Palm m515 and that worked perfectly.
    I booted up to a 10.4.11 install on an external drive and found the mouse to pair up and work perfectly.
    Then I installed 10.5.4 on an external drive and it too connected perfectly. I tried creating a new user on my main drive's 10.5.8 install and that did not solve the problem. At this point I thought my main drive's 10.5.8 install was corrupt for some reason. I backed up my drive via Time Machine and proceeded the 6 hour new system fresh install.
    My Leopard install disc is version 10.5.4. The mouse paired and worked great after the initial install. It was all for nought, however, because upon installing the 10.5.8 update on this untouched fresh system, the mouse was no longer recognized and would stall at the pairing process. I even got a kernel panic this time.
    I don't know what Apple did between 10.5.4 and 10.5.8, but whatever it is made pairing with a bluetooth mouse via a Bluetooth dongle seemingly impossible. I assume there will be no fix for this since they have moved on to Snow Leopard.
    Since people are having this same problem regardless of their dongle brand or mouse brand, I suppose I can be confident that this is not a hardware issue. Especially since the hardware all works perfectly up to at least 10.5.4. I'm not sure when it breaks because I just go straight from 10.5.4 to the 10.5.8 combo update.

  • Airport Extreme Intermittent Network Interruption when Downloading Large Amounts of Data.

    I've had an Airport Extreme Base Station for about 2.5 years and have had no problems until the last 6 months.  I have my iMac and a PC directly connected through ethernet and another PC connected wirelessly.  I occasionally need to download very large data files that max out my download connection speed at about 2.5Mbs.  During these downloads, my entire network loses connection to the internet intermittently for between 2 and 8 seconds with a separation between connection losses at around 20-30 seconds each.  This includes the hard wired machines.  I've tested a download with a direct connection to my cable modem without incident.  The base station is causing the problem.  I've attempted to reset the Base Station with good results after reset, but then the problem simply returns after a while.  I've updated the firmware to latest version with no change. 
    Can anyone help me with the cause of the connection loss and a method of preventing it?  THIS IS NOT A WIRELESS PROBLEM.  I believe it has to do with the massive amount of data being handled.  Any help would be appreciated.

    Ok, did some more sniffing around and found this thread.
    https://discussions.apple.com/thread/2508959?start=0&tstart=0
    It seems that the AEBS has had a serious flaw for the last 6 years that Apple has been unable to address adequately.  Here is a portion of the log file.  It simply repeats the same log entries over and over.
    Mar 07 21:25:17
    Severity:5
    Associated with station 58:55:ca:c7:c2:ae
    Mar 07 21:25:17
    Severity:5
    Installed unicast CCMP key for supplicant 58:55:ca:c7:c2:ae
    Mar 07 21:26:17
    Severity:5
    Disassociated with station 58:55:ca:c7:c2:ae
    Mar 07 21:26:17
    Severity:5
    Rotated CCMP group key.
    Mar 07 21:30:43
    Severity:5
    Rotated CCMP group key.
    Mar 07 21:36:41
    Severity:5
    Clock synchronized to network time server time.apple.com (adjusted +0 seconds).
    Mar 07 21:55:08
    Severity:5
    Associated with station 58:55:ca:c7:c2:ae
    Mar 07 21:55:08
    Severity:5
    Installed unicast CCMP key for supplicant 58:55:ca:c7:c2:ae
    Mar 07 21:55:32
    Severity:5
    Disassociated with station 58:55:ca:c7:c2:ae
    Mar 07 21:55:33
    Severity:5
    Rotated CCMP group key.
    Mar 07 21:59:47
    Severity:5
    Rotated CCMP group key.
    Mar 07 22:24:53
    Severity:5
    Associated with station 58:55:ca:c7:c2:ae
    Mar 07 22:24:53
    Severity:5
    Installed unicast CCMP key for supplicant 58:55:ca:c7:c2:ae
    Mar 07 22:25:18
    Severity:5
    Disassociated with station 58:55:ca:c7:c2:ae
    Mar 07 22:25:18
    Severity:5
    Rotated CCMP group key.
    Mar 07 22:30:43
    Severity:5
    Rotated CCMP group key.
    Mar 07 22:36:42
    Severity:5
    Clock synchronized to network time server time.apple.com (adjusted -1 seconds).
    Mar 07 22:54:37
    Severity:5
    Associated with station 58:55:ca:c7:c2:ae
    Mar 07 22:54:37
    Severity:5
    Installed unicast CCMP key for supplicant 58:55:ca:c7:c2:ae
    Anyone have any ideas why this is happening?

  • Airport Extreme and boot failure....

    I just installed a brand new Airport Extreme card into my G5 and after the installation, the computer refuses to start.
    Instantly after the card is removed, the computer works perfectly.
    Any suggestions why?

    O.R.E, Welcome to the discussion area!
    Which Power Mac G5 do you have? The latest models are not compatible with the AirPort Extreme card. See KB 302721, Power Mac G5 (Late 2005) AirPort and Bluetooth options.
    Assuming you have an earlier Power Mac G5 which is compatible with the AirPort Extreme card, one or more of the following must be true:
    The AirPort Extreme card is not installed correctly.
    The AirPort Extreme card is defective.
    The Power Mac G5's motherboard is defective.

  • Random Authentication Failures when using AdminConnectionFactory

    Has anyone experienced this problem when using the AdminConnectionFactory to create a JMXConnector. I have a Sun ticket open on this issue, but wanted to see if anyone else had any suggestions. Ticket # is 72502922
    Our application uses the Sun AdminConnectionFactory to obtain a JMXConnector object. The code is being executed in a loop at a regular frequency. There is no dynamic nature to the code. All the information required to open a connection using the AdminConnectionFactory comes from static property files. So there is no question of one call being any different than a second call.
    Every so often the call to create a connection fails with the exception message:
    Cannot create JMXConnector to JMS server [jmssys.putnaminv.com:7683] using username [JMXMetricsClient.User] and password [XXX]
    at com.putnam.jms.jmx.JMXUtil.<init>(JMXUtil.java:146)
    at com.putnam.jms.metrics.core.MetricsRetrievalJob.run(MetricsRetrievalJob.java:58)
    at com.putnam.jms.metrics.core.MetricsRetrievalJob.execute(MetricsRetrievalJob.java:37)
    at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
    at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:529)
    Caused by: javax.management.JMException: Caught exception when creating JMXConnector
    at com.sun.messaging.AdminConnectionFactory.createConnection(AdminConnectionFactory.java:219)
    at com.putnam.jms.jmx.JMXUtil.<init>(JMXUtil.java:138)
    ... 4 more
    Caused by: java.lang.SecurityException: JMX connector server jmxrmi: Failure detected during authentication java.security.AccessControlException: [B4043]: Connection not authenticated
    at com.sun.messaging.jmq.jmsserver.management.agent.MQJMXAuthenticator.authenticate(MQJMXAuthenticator.java:125)
    at javax.management.remote.rmi.RMIServerImpl.doNewClient(RMIServerImpl.java:213)
    at javax.management.remote.rmi.RMIServerImpl.newClient(RMIServerImpl.java:180)
    at sun.reflect.GeneratedMethodAccessor60.invoke(Unknown Source)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    at java.lang.reflect.Method.invoke(Method.java:597)
    at sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:305)
    at sun.rmi.transport.Transport$1.run(Transport.java:159)
    at java.security.AccessController.doPrivileged(Native Method)
    at sun.rmi.transport.Transport.serviceCall(Transport.java:155)
    at sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:535)
    at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:790)
    at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:649)
    at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(ThreadPoolExecutor.java:886)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:908)
    at java.lang.Thread.run(Thread.java:619)
    at sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:255)
    at sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:233)
    at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:142)
    at javax.management.remote.rmi.RMIServerImpl_Stub.newClient(Unknown Source)
    at javax.management.remote.rmi.RMIConnector.getConnection(RMIConnector.java:2312)
    at javax.management.remote.rmi.RMIConnector.connect(RMIConnector.java:277)
    at javax.management.remote.JMXConnectorFactory.connect(JMXConnectorFactory.java:248)
    at com.sun.messaging.AdminConnectionFactory.createConnection(AdminConnectionFactory.java:217)
    ... 5 more
    The code to create a connection using the AdminConnectionFactory is straight forward:
         JMXConnector jmxc = null;
    try {
    AdminConnectionFactory acf = new AdminConnectionFactory();
    acf.setProperty(AdminConnectionConfiguration.imqAddress, hostname + ":" + port);
    jmxc = acf.createConnection(user, password);
    } catch (JMSException jmse) {
    message = logMsgPrefix + "Cannot create JMXConnector to JMS server [" + hostname + ":" + port + "] using username [" + user + "] and password [" + password + "]";
    log.error(message);
    throw new GenericJMXException(message, jmse);
    } catch (JMException jme) {
    message = logMsgPrefix + "Cannot create JMXConnector to JMS server [" + hostname + ":" + port + "] using username [" + user + "] and password [" + password + "]";
    log.error(message);
    throw new GenericJMXException(message, jme);
    What is causing this connection creation to fail. The same application will work just fine a few minutes later.
    Thanks
    Aspi Engineer
    Putnam Investments

    Thank you for the response.
    Bug 6906978 is a defect that shows itself under high concurrency situations. In our case, we have a single quart based timer that is being triggered every 2 minutes to open a JMX connector. So my guess is that bug 6906978 and the problem that we have been experiencing are two different things.
    But I am willing to try out 4.4U1P1. Any idea where I can download it from?
    - Aspi

  • Airport extreme uses its ip when forwarding ports

    Ive set the extreme to forward port 21
    the trouble is that the ip that the client is forwarded as is the airports external ip rather than the connecting external ip
    In other words when a server on the net with ip 200.200.200.200 tries to connect to the ftp server the IP the FTP server sees is the airports external IP
    This makes it impossible to filter access by IP
    Is there something Im doing wrong ?

    thats unfortunate
    every other router Ive tried on the market works the "other" way and forwards the actual client ip
    I wouldn't be surprised if there was an RFC that covered it
    time to send the extreme back

  • Authentication failure when adding new 'Segment in Use'

    Hi all!
    I've set up integration between Siebel 8.1.1.9 and OBIEE 11.1.1.5.0. I've applied My Oracle Support article ID 1400715.1, importing the modified SIF and Workflow definitions and re-deployed the SRF to the server.
    When attempting to drill into a folder in the 'Pick Segment' applet, I get the following error:
    Operation 'impersonate' of Web Service 'com.siebel.analytics.web/soap/v1.SAWSessionService' at port 'SAWSessionServiceSoap' failed with the following explanation:
    "Authentication error. An invalid User Name or Password was entered.".(SBL-EAI-04308)
    I cannot for the life of me work out why this is happening. I've followed 1400715.1:
    1. Created a new OBIEE user called 'impersonateuser' and added the 'oracle.bi.server.impersonateUser' permission
    2. In Siebel, Marketing - Administration > Servers, I've set the User Id and Password fields for the 'Default Analytics Web Server' entry, ensuring that the password contains more than 8 characters and contains a number, with the 'impersonateuser' details. The 'impersonateuser' user can successfully log in to OBIEE / Dashboard
    I've checked the Web Service definitions and replaced host name with host:port. The Web Service is definitely getting invoked but there seems to be a problem with the impersonation.
    Any thoughts on how to resolve this?
    Many thanks!
    mroshaw

    DOH - failed to RTFM correctly!
    I'd not followed the instructions for adding the permission correctly - you have to read very cafrefully how to get to the right page to add the permission.
    Working now! :)
    Regards,
    Oli

  • Windows 7 802.1x (Wired) Authentication Failure when logging into Lync 2010

    Hi
    My company has implemented 802.1x Wired authentication, we use GPO to specify a
    Wired Profile that uses a COMPUTER certificate.
    We are finding that when a Windows 7 laptop comes out of sleep or hibernation, the laptop fails 802.1x authentication and does not connect to the network.
    This issue only occurs intermittently, but have been proven to occur only when Lync 2010 is open.  If we close Lync 2010 the issue does not occur.  Lync 2010 installs a self signed USER certificate for authentication.
    I am aware that there are some issues around Windows 7 not selecting the correct certificate when responding to authentication requests (KB2710995,
    KB2769121) but these always specify that the issue occurs when 802.1x authentication uses USER certificates, not a mix of USER and COMPUTER.  We have installed these hotfixes and the
    issue still occurs.

    Hi,
    From the description, you suspect the DHCP request cause this issue. Would you please send us the packets? Since it seems that you have looked into the traffic and found some clues.
    Meanwhile, I found the following hotfix which may related to this issue.
    No response to 802.1X authentication requests after authentication fails on a computer that is running Windows 7 or Windows Server 2008 R2 http://support.microsoft.com/kb/980295/en-us
    Next Action Plan:
    1.Clean Boot
    a. Click Start, click Run, type "msconfig" (without the quotation marks) in the Open box, and then click OK.
    b. In the Startup tab, click the "Disable All" button.
    c. In the Services tab, check the "Hide All Microsoft Services" checkbox, and then click the "Disable All" button.
    ======================================================
    Clean Boot + binary search
    In a Clean Boot, all the 3rd party services and startup programs are disabled. If the server can start normally in Clean Boot, we can be sure that the issue was caused by some 3rd party service or application. And then we can do a "binary search".
    You can enable half of all the services in Services tab, and then restart the server to check the result. If the issue reoccurs, it means the culprit is in this list; if not, the culprit is in the other half. And then, we can continue the binary search, until
    we find out the root cause. Please let me know if this action plan is OK for you.
    2.Collect etl trace on the problematic client.
    netsh trace start capture=yes overwrite=yes tracefile=c:\net.etl filemode=circular
    ****Try to reproduce this issue****
    netsh trace stop
    Please send the net.etl to us for underlying analysis.
    For any concerns, please let us know.
    Best regards,
    Steven Song
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • PAM authentication failure when attempting to run job

    I'm attempting to run a scheduled job from grid control (version 10.2.0.5.0) against a Solaris server and it keeps failing with:-
    Error Log
    ERROR: Invalid username and/or password
    Output Log
    LOG: Local Authentication Failed...Attempt PAM authentication...PAM failed with error:
    Despite entering an os username and password into the preferred credentails for this server which work when I try to logon to using putty, I can't connect to the server using the preferred credentils screen either. However, the agent can upload data without any problems. Can anyone point me in the correct direction as towards a resolution for this issue.

    Thanks for the information, Oracle support came up with this technical note also. Its a bit strange as it mentions using the shared object for ldap in the pam.conf even though I'm not using ldap. Out of interest, do you use grid control, Solaris and pam authentication ?

  • Lost connection between airport extreme and macbook air when transferring large files

    Can anyone help...?
    I have an imac and macbook air wirelessly connected to a airpot extreme being used as a router with a hard drive for sharing files accross the network.
    It connects ok but when we try and look at a number of large files one after the other, or copy files from the shared hard drive onto the macbook air, the macbook loses wireless connection?
    A very strange issue which i cant figure out....
    Can anyone help?
    Thanks
    Shirmy

    It could be a wireless interference or strength of wireless signal issue.
    What happens when you connect the MacBook Air to the router via an Ethernet connection?

  • Setting up the airport extreme so i can get nat-2 for Ps3

    what are the Settings i need to know to do this ? I have a dsl modem and my airport is set up to share a public IP address.

    Anytime you change networking hardware it is always a good idea to perform a complete power recycle of that hardware. Check out the following AirPort User Tip for details. Please post back your results.

Maybe you are looking for

  • External hard drive gone!!

    Don't know if it's the right forum to post, but anyway: I pluged in my external harddrive (Western Digital 2TB),but suddenly i could read the files, but i couldn't open them! So I tried to remove the disk usig disk utilities but it couldn't. And afte

  • XSTRING to PDF ? AIF.

    Hi, I want to show Adobe Interactive Form PDF: REPORT  zz_aa_aif. TABLES: lfa1. DATA: wa_lfa1 TYPE lfa1. DATA: fm_name TYPE funcname. DATA: fp_formoutput   TYPE fpformoutput,       fp_docparams    TYPE sfpdocparams. DATA: fp_outputparams TYPE  sfpout

  • Safari 3.2 newest Version crashes all the time...

    Hi, since I downloaded the latest version of safari it keeps crashing, often even on startup. Took me nearly 10 tries to get this text online... I tried uninstalling plugins, removing all USB and firewire devices, nothing works... I even downloaded s

  • Multi-touch

    browse in app store,I can't use 2 fingers to change the page,why?

  • Why is my trackpad is not functioning properly?

    i have a problem with my trackpad, it is not working properly, its moving erratically, i dont know what wrong with it, ive tried to reset my SMC and it works fine at first but after about 20 minutes, it goes back to moving erratically, please help me