Machine authentication and MAR not working.

Hi, I'm using ACS 4.1.23 with MS AD for authentication in a wireless network environment. Users connect to one of the (Suppliers and Employees) SSID's and based on group authorization in AD are allowed to access. The SSID to the Employees network has an additional policy: only registered hosts in AD are allowed. For authentication is the standard MS supplicant used with PEAP-MSCHAPV2 configured.
According to the Cisco documentation ACS supports Machine Authentication and in combination with MAR, authenticated hosts required before user authentication, is possible.
BUT, it doesn't work. I do see successful host and user authentication, but the MAR policy doesn't kick in when a user authenticates without host authentication. I was able to turn debug logging for the CSAuth service, giving me the extra information in the AUTH.log.
I have no clue what is missing or how to troubleshoot from this point on.
Has anyone got this setup working or help me a step further ?

Found it !
Within the MAR configuration, the "host/" definition is required for ACS to identify hosts.
ACS has the worst GUI of all software I know of ... :-(

Similar Messages

  • Authentication and Debugging not working -- since Saturday, July 12

    Hi everyone,
    Since Saturday (July 12), the iTunes U launcher that my institution uses (a Moodle block) has ceased successfully authenticating users. From all the looking I've done, nothing has changed from our side, although I am having to do the investigation remotely, and can only be about 95% certain of that so far.
    I'm also not able to use the debug string to see what credentials are being sent to iTunes U, because there appears to be no difference in the launcher process, whether debugging is enabled or not.
    Is anyone aware of any changes or glitches in the system in the last few days? Any information at all will be very greatly appreciated.
    -JR

    Woolamaloo lives to help with such problems. Woolamaloo is an application specifically designed to access your iTunes U site without any CGI, BlackBoard or Moodle building blocks, etc. It accesses your site directly ... using any credential you supply. In effect, you can use it to "be" any user at your site. It can even show you Apple's debug webpage (if you want to see it). You can use Woolamaloo to verify that your site is not working ... or that it is and you have a local problem. You can find out and download the app here:
    http://itunes.uic.edu/Woolamaloo.html
    It comes in both a Windows and Mac OS version (though I admit to having a Mac OS X bias).

  • Just upgraded machine, Dreamweaver and Flash not working

    I've been using Dreamweaver MX and Flash MX on my old Power Mac G5 for the last 5 years and just upgraded to a new Mac Pro Quad Core Intel Xeon processor. It is a 64 bit system using Mac OS10.6.4.
    They do not run on this new machine. Is there any way to get them to run on it?
    If not, do I have to pay full price for new software or is there an upgrade available?
    Thanks,
    Glenn Nevill

    If you want the new version you would have to pay the full price.  The Adobe policy is upgrade once every 3 versions.  MX was version 6, CS5 is version 11.  I would recommend purchasing the new suite if you can.  Otherwise, if it ran under Leopard, you may (I am not positive) be able to run Parallels with 10.5 and run MX in a virtual environment.

  • I just fix my macbook air because it was kernel panic. They changed the hard drive. I could not back up with Time Machine, because it did not work and I had over Adobe creative suite 5 design premium student. But I finished my studies last year and I'd li

    I just fix my macbook air because it was kernel panic. They changed the hard drive. I could not back up with Time Machine, because it did not work and I had over Adobe creative suite 5 design premium student. But I finished my studies last year and I'd like to know how to get the serial number for me to reinstall Adobe creative suite 5 design premium when I am no longer study because I would still like the used? It is not fair if I do anymore because I really need.

    You can download Creative Suite 5 here:
    Other downloads
    To deal with the issue of the serial number and using it again, you'll have to use Web Chat. Here's a link:
    Adobe ID, sign in, and account help
    See the bottom of the page for a link

  • Wireless network and bluetooth not working on touchsmart 600

    This has not worked since day 1 and I have been using wired internet.
    I really need to setup a home network and need to use wireless.
    Research on the net has led me to belive I should have HP WIRELESS ASSISTANT on my machine... is that correct?
    Everytime I try to download it is seem to be for a notepad... mine is a touchsmart desktop...
    Please advise  

    Hi coffee12345,
    Welcome to the HP Forums!
    I have read your post on your wireless keyboard and mouse not working with your desktop, and I would be happy to help you! To begin, I need to ask you a few introductory questions:
    What is the Product and Model Number of your desktop?
    What version of Windows are you using?
    Is this a recent issue, or has it been like this since day one?
    Are you using a USB hub to connect your peripherals or is it directly plugged into the computer?
    Please re-post with the necessary information, and I look forward to your reply!
    Regards
    MechPilot
    I work on behalf of HP
    Please click “Accept as Solution ” if you feel my post solved your issue, it will help others find the solution.
    Click the “Kudos, Thumbs Up" on the right to say “Thanks” for helping!

  • I baught Seagate Backup plus 2T hard drive to use as my Backup time machine. But its not working when i connect to time machine its not coping files, it keep saying preparing files. Can someone help me please...

    i baught Seagate Backup plus 2T hard drive to use as my Backup time machine. But its not working. when i connect to time machine its not coping files, it keep saying preparing files. Can someone help me please...

    Please read this whole message before doing anything.
    This procedure is a diagnostic test. It’s unlikely to solve your problem. Don’t be disappointed when you find that nothing has changed after you complete it.
    The purpose of the test is to determine whether the problem is caused by third-party software that loads automatically at startup or login, by a peripheral device, by a font conflict, or by corruption of the file system or of certain system caches.
    Disconnect all wired peripherals except those needed for the test, and remove all aftermarket expansion cards, if applicable. Start up in safe mode and log in to the account with the problem. You must hold down the shift key twice: once when you turn on the computer, and again when you log in.
    Note: If FileVault is enabled, or if a firmware password is set, or if the startup volume is a Fusion Drive or a software RAID, you can’t do this. Ask for further instructions.
    Safe mode is much slower to start up and run than normal, with limited graphics performance, and some things won’t work at all, including sound output and Wi-Fi on certain models. The next normal startup may also be somewhat slow.
    The login screen appears even if you usually login automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
    Test while in safe mode. Same problem?
    After testing, restart as usual (not in safe mode) and verify that you still have the problem. Post the results of the test.

  • Machine Authentication and User Authentication with ACS v5.1... how?

    Hi!
    I'm having trouble setting up Machine Authentication and User Authentication on ACS v5.1 using WinXP SP3 (or SP2) as supplicant.
    This is the goal:
    On wireless (preferably on wired too) networks, get the WinXP to machine authenticate against AD using certificates so the machine is possible to reach via for example ping, and it can also get GPO Updates.
    Then, when the user actually logs in, I need User Authentication, so we can run startup scripts, map the Home Directory and so on.
    I have set up a Windows Sertificate server, and the client (WinXP) are recieving both machine and user certificates just fine.
    I have also managed to set up so Machine Authenticaton works, by setting up a policy rule that checks on certificate only:
    "Certificate Dictionary:Common Name contains .admin.testdomain.lan"
    But to achieve that, I had to set EAP Type in WinXP to Smart Card or other Certificate, and then no PEAP authentication occurs, which I assume I need for User Authentication? Or is that possible by using Certificates too?
    I just don't know how to do this, so is there a detailed guide out there for this? I would assume that this is something that all administrators using wireless and WinXP would like to achieve.
    Thank you.

    Hello again.
    I found out how to do this now..
    What I needed to do was to add a new Certificate Authentication Profile that checks against Subject Alternative Name, because that was the only thing I could find that was the same in both user certificate and machine certificate.
    After adding that profile to the Identity Store Sequences, and making tthe appropriate rule in the policy, it works.
    You must also remember to change the AuthMode option in Windows XP Registry to "1".
    What I really wanted to do was to use the "Was Machine Authenticated" condition in the policies, but I have never gotten that conditon to work, unfortunately.
    That would have plugged a few security holes for me.

  • Ultraslim wireless keyboard and mouse not working

    Hi ,  I purchased the Lenovo Ultraslim Wireless Keyboard & Mouse (pn: 57Y4700) about 4 months ago for use with my T60 laptop (which i use with a docking station and large lenovo monitor at work).
    Everything was woking fine until last Monday when I can into work after the weekend and neither the mouse or keyboard worked. I replaced the batteries in both, rebooted the machine several time, switch the USB ports for the nano receiver, but nothing seems to have worked.
    I looked online for troubleshooting options, but did not find anything.
    The mouse and keyboard don't seem to have a "sych" button - if I recall correctly everything worked right out of the box.
    My theory is that the nano reciever was damaged (not sure how) -- but don't know how to proceed:
    can the nano reciever be replaced;
    any other options to troubleshoot;
    any chance that this could be a software problem
    Thanks

    Hi coffee12345,
    Welcome to the HP Forums!
    I have read your post on your wireless keyboard and mouse not working with your desktop, and I would be happy to help you! To begin, I need to ask you a few introductory questions:
    What is the Product and Model Number of your desktop?
    What version of Windows are you using?
    Is this a recent issue, or has it been like this since day one?
    Are you using a USB hub to connect your peripherals or is it directly plugged into the computer?
    Please re-post with the necessary information, and I look forward to your reply!
    Regards
    MechPilot
    I work on behalf of HP
    Please click “Accept as Solution ” if you feel my post solved your issue, it will help others find the solution.
    Click the “Kudos, Thumbs Up" on the right to say “Thanks” for helping!

  • How do I know WinRM uses Kerberos for authentication, and does not fall-back to NTLM?

    Hi,
    How do I know WinRM uses Kerberos for authentication, and does not fall-back to NTLM?
    /SaiTech

    Hi SaiTech,
    Kerberos will be selected by default in an AD domain, The default (assuming the client is in a domain, and is not connecting to itself via 127.0.0.1 or ::1 addresses) is to use Kerberos authentication, and not to fall back to NTLM.
    Please also Note that you may have to take some other steps as well to get non-Kerberos authentication working.  Specifically, you'd have to set up an HTTPS listener on the remote host, or modify the client's TrustedHosts list.
    Refer to:
    WINRM kerberos & Negotiate
    Authentication for Remote Connections
    In addition, you can also use Network Monitor to check the authentication method.
    If there is anything else regarding this issue, please feel free to post back.
    If you have any feedback on our support, please click here.
    Best Regards,
    Anna Wang
    TechNet Community Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • My Ipod touch 4th generation is not working, its frozen, ive tried everything and its not working, its just frozen on an app and i really really need HELP!!!

    My Ipod is frozen!!! Its a 4th generation and its frozen on an app, Ive tried everything like holding down the lock screen and stuff and its not showing the red thing to slid to shut it down....This is my only thing to use to contact my friends and its not working, i dont have a phone and i cant get one, so this is the onlything i have.....PLEASE HELP!!!

    Try:
    - iOS: Not responding or does not turn on
    - Also try DFU mode after try recovery mode
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings
    - If not successful and you can't fully turn the iOS device fully off, let the battery fully drain. After charging for an least an hour try the above again.
    - Try on another computer
    - If still not successful that usually indicates a hardware problem and an appointment at the Genius Bar of an Apple store is in order.
    Apple Retail Store - Genius Bar       

  • How can I get my itunes onto my new laptop? Do I need to download itunes again or can I just copy it? My ipod classic has since been soaked in water and does not work so I cannot copy from there. Can anyone help?

    How can I get my itunes onto my new laptop? Do I need to download itunes again or can I just copy it? My ipod classic has since been soaked in water and does not work so I cannot copy from there. Can anyone help?

    You should copy everything from your old comptuer to your new one.

  • Keyboard and Trackpad Not Working; Mac OSX Unexpectedly Quit?

    Hey everyone... I think I may need to stop by the Apple store to figure this one out, but I just wanted to make sure if there was anything I could do on my own first.
    So basically, on my MacBook Pro that I got nearly two years ago (late September of 2006) for the past month and a half has had problems. In the beginning, the mouse and keyboard would freeze up and just not work. Restarting the comp did nothing. Some times were worse than others (once it was frozen for 1.5 hours). Then it stopped, every now and then having a few freezes (sometimes when the keyboard froze but the trackpad was still good), but two days ago I had my comp not hooked up to an adapter. When the battery got low, the comp froze. I went to bed and closed the laptop, and the next day it was still frozen. I unfroze it, but then it happened again (I'm pretty sure the same situation... almost no battery)... and it is still frozen, even after multiple restarts.
    Also, during the time when freezes weren't as bad, sometimes the keyboard would get stuck on one key, usually the volume up button (very annoying)... then I was told to restart the comp. When I came back, I was told that Mac OS X had unexpectedly quit.
    Sorry that was a lot to read, but any help is really appreciated! Thanks!
    Not sure if this is also important, but I did spill some water on the keyboard a very long time ago (late December '06)... it wouldn't take this long for that to cause the problem, would it?

    Does booting up in [Safe Mode|http://support.apple.com/kb/HT1455?viewlocale=en_US] help at all? This boot mode checks the disk on startup and disables non-apple start up items and certain kernel extensions.
    Steve

  • While updating my ipad to new software through itunes it got stuck and does not work anymore - it just displays the screen with symbols of itunes and the cable to connect to it - help - what should i do?

    while updating my ipad to new software through itunes it got stuck and does not work anymore - it just displays the screen with symbols of itunes and the cable to connect to it - help - what should i do?

    Disconnect the iPad, do a Reset [Hold the Home and Sleep/Wake buttons down together for 10 seconds or so (until the Apple logo appears) and then release. The screen will go blank and then power ON again in the normal way.] It is 'appsolutely' safe!, reconnect and follow the prompts.
    If that does not work then see here http://support.apple.com/kb/HT1808

  • Hi i have a ipod touch 4 generation 64gb and my camera is blocked and dose not work i cant update the ipod either

    hi i have a ipod touch 4 generation 64gb and my camera is blocked and dose not work i cant update the ipod either

    Try:
    - Reset the iOS device. Nothing will be lost       
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Reset all settings      
    Go to Settings > General > Reset and tap Reset All Settings.
    All your preferences and settings are reset. Information (such as contacts and calendars) and media (such as songs and videos) aren’t affected.
    - Restore from backup. See:                                                
    iOS: How to back up                                                                                     
    - Restore to factory settings/new iOS device.             
    If still problem, make an appointment at the Genius Bar of an Apple store since it appears you have a hardware problem.
      Apple Retail Store - Genius Bar

  • Since I downloaded the upgraded software, my charger that came with my phone says "this cable or accessory is not certified and may not work reliably with this iphone"  It worked before but now it doesn't...I don't think I should have to buy a new one...

    since I upgraded to the new operating system my charger no longer works...
    It says"this cable or accessory is not certified and may not work reliably with this iPhone"

    Try checking your cable socket/lightning cable for dirt, grime, pocket lint, etc. I could not find the solution to this issue myself and after much searching I found someone stating that cleaning this out helped them immensely.
    After taking a wooden toothpick (making sure the phone was OFF first) and gently clearing out the edges and inside of the lightning socket this went away.) It is worth noting that I had a significant amount of dust or lint buildup along the edge rails which I think was causing the iphone to believe it was plugged into something when it was not.
    Try it and see, ensure you are very careful and do not use any conductive tools to clean the area in question. Compressed air also does wonders here.

Maybe you are looking for

  • Downloading Adobe Acrobat 9 Pro on a new laptop

    I need to download Acrobat 9 Pro on a new laptop (it's already on my old laptop). How do I do this?

  • Trying to sync maps on a N8 with OVI

    I went to the maps 'sync' tool, and tried to do a sync but it failed.  After reading the manual, I see I need to be logged in first: Synchronise your favourite locations with Ovi Maps The Ovi website contains the internet services that Nokia provides

  • My keys for F1 to F12 are messed up and I can't seem to fix it in the system pref.

    I can't seem to sync my F1 to F12 Keys to what they are supposed to do. I checked all the system preference settings, even set all to default and nothiung works. Can someone please help?

  • How to set a row as default row in adf table

    Hi, I have a requirement: when page is launched there are multiple records with different status displayed on the page and i had to make the first record with Status = XXX as default selected row in adf table. How to code it? Thanks! Susan

  • Media Corrupted Exception On MediaPlayer Restart

    I have created a simple application to test out JavaFX. Withing that Proof-Of-Concept application, I load both sound and video into separate instances of a MediaPlayer. While running the application from the IDE, I can stop and start both the sound a