Nokia Issues in the Enterprise

I have (2) Nokia clients that are unable to connect to the enterprise WLAN.
Client Data:
Nokia N8 Symbian Belle
Nokia N900 running Maemo5
Wireless Setup:
WiSM2s running 7.0.230
APs: 1142 & 3500
WPA2 Enterprise AES PEAP/MSCHAPv2
Certificate is with GeoTrust Global CA
Microsoft IAS
All other clients work perfectly (laptops, cell phones, tablets).
I have checked the Nokia forums and it seems that many people have experienced WPA2 enterprise issues, but the company states that they support it.
The Radius servers are controlled by the server admin group which can make troubleshooting timely.  We did receive this log message on one of the unsuccessful attmepts from the Radius server.
Reason Code: 3
Reason: The RADIUS Request message that Network Policy Server received from the network access server was malformed.
One more note, troubleshooting the clients is timely as well because they have to be available since we do not have a Nokia device to test with.
Thanks for any help.

Thomas:
Make sure that GeoTrust Global CA is listed on trusted CA list on Nokia phone. (this should be Ok I guess).
Make sure about the configuration on the nokia phone; This is where your problem could be.
Make sure that you configured the device correctly.
- PEAPv0, PEAPv1 enabled.
- PEAPv2 disabled.
- TLS privacy is off.
- Make sure that only PEAP-MSCHAPv2 is enabled and on top of the list of your PEAP methods on the phone.
- Make sure that "Authority Certificate" list on the phone has " GeoTrust Global" listed and choose it from the config page.
- under Mschapv2 config provide your username and password.
with the above config it should work. I tested with too many nokia devices and it worked fine with this config.
However, I was troubleshooting (about two years ago) an issue with a big implementation of nokia 7x series in Australia. We found that there was a problem with the phones. we did sniffer trace and found that the phone does not reply at some point with the needed data.
They had to troubleshoot with Nokia and -as I remember- they mentioned there was a problem with certificate storage on the phone. The phone saves certificates in location X but tries to find the certificate in location Y when it tries to authenticate.
If you have correct config and still not working, try do debug client for a nokia device:
debug client
then try to connect. collect the debugs.
I am sure it will end with access-reject from the radius. I just want to know if there are other informaiton that may be useful.
HTH
Amjad

Similar Messages

  • Issues with the Nokia N96????

    Im currently on a contract with THREE network here in england. I am due my upgrade, and I was planning to go from the N95 to the N96 - on paper it looks like an awesome handset.
    Ive been into my network suppliers shop today to ask about the N96, and was warned by the manager in the shop that Nokia have ceased shipping these handsets to them due to complaint and problems with the processor on the handset.
    Ive been warned by several people that the handset is very slow, freezes up when performing anything demanding, or even when trying to find a file on the handsets internal memory and thats its just not fast enough.
    The manager in the Three shop told me that there is an issue with the processor not being powerful enough for the phone, and the amount of memory the phone has. He also said that software teams across most UK networks were working around the clock on a software update to paper over the cracks, but he reckoned that this wouldnt fix the problem completely, as the chip is just not up to scratch full stop.
    I just wanted to find out how true everything he is saying actually is. I know first hand from people I know who own them that this handset is infact really quite slow, and Im now put off owning one at all. If there is someone in the know actually from Nokia reading this, your replies would be appreciated I really want this phone and have done since I heard about it, but Im not prepared to risk signing a new 18 month contract with my network, and then end up with a handset which is not fit for purpose!
    Cheers
    Message Edited by cleggsta on 10-Feb-2009 05:02 PM

    The N96 as shipped with the v10 firmware had major issues.
    The v11 update fixed most of these and the v12 was a further improvement.
    Your shop manager is lost about what is happening with the firmware. The networks themselves don't write it or fix problems, instead nokia provides them with the updates and they alter them with there own network branding, add apps etc. before allowing Nokia to make it available to those who hold there branded handsets, some of these alterations have made the problems worse.
    Because it takes the networks time and money to do this to every firmware patch they are sometimes slow to release or don't release at all.
    Note that it is rumoured that Nokia are working on the v20 update but no release date has even been rumoured yet

  • The Enterprise theme for Nokia 6300

    It's a theme look like Nokia E51 style theme.
    http://riyadus.deviantart.com/art/The-Enterprise-for-Nokia-6300-72200041
    Thanks.

    Here some themes I've made or modified for Nokia 6300:
    http://rapidshare.com/users/IFX0I5
    Rockado

  • Issues with Ovi store in Nokia N8 and the OS is ha...

    Hi,
    I have taken Nokia N8 in the month of March. It was all working fine and all of sudden I am noticing that the Ovi store is not opening tried resetting to factory settings, It did not help. Tried reinstalling the Ovi It also did not help. I went to Nokia Care and they said that they need to upgrade the software, They did but after that also the Ovi store is not opening they were also not able to install the ovi. they said that they need to check and if they cant then they need to send it to Delhi, I asked them for a Back up phone but they say that they cant give. what is this we take a Branded mobile paying such huge amount and when we have to give it service they say it will take a week to 10 days and for a time untill they confirm when they would give the mobile they cant provide a back up phone. Its really bad on Nokia. Its damaging the reputation of Nokia. Can this be looked into. Well I went to nokia care expecting a good hospitality but I felt like I went an Open market where if you want leave it else please keep moving....

    Hi smartboy4u,
    You may try to check this link for further resolutions:
    http://discussions.europe.nokia.com/t5/Ovi-com-Ovi-Store-Ovi-Share-and/Ovi-Store-Problems-After-Upda...

  • Have Nokia fixed all the issues with E90?

    Hello all.
    I am thinking of buying the Nokia E90. But i want to be sure of something first. I hope that you can help me Thanks.
    Have Nokia fixed all the problems now with the E90? The keyboard hitting the screen? The microphone? etc?
    How is the build quality of the E90? I had the Nokia N95 but i did not have it for long because of the bad slider. So if there is any clicking or anything when you are using the keyboard outside. Then i dont think it will be a phone for me. If you can press on the side and it will move. Like the slider on the N95 that also said a click sound.
    Thanks.
    From Kehaan - Denmark.

    I bought my E90 in South Africa last year and have been over the moon with it. It does everything I can think of and I have loaded stacks of applications on its 2GB card. I use it daily in my work for meeting minutes, calendaring etc and live on the Internet with it...
    I fitted screen protectors on it which prevents the inner screen scratching on the keys. Only problem I have had is I tried upgrading the firmware at home from the Internet and it overwrote something it should not have. It rebooted once but did not reboot a second time and Nokia took it in and are reflashing it with the new version for me free of charge (I will probably not try doing this at home again).
    Better news is something happened to my phone while they were working on it and they are replacing it with a brand new E90. I cannot wait to get it back and am having major withdrawal symptoms while having to work on my old 9300!

  • Implementing the Enterprise Support in Solution Manager

    Hi Experts,
    Can anybody tell me what are the pre requisites to implement Enterprise support in solution manager?
    Also let me know what are steps involved in implementing the enterprise support.
    Thanks in Advance
    Hari

    Hello Hari,
    In order to implement Enterprise Support your organization should registered as a Value Added Reseller(VAR) with SAP. You can get all the required documentation under https://websmp104.sap-ag.de/solutionmanager --> Information for VARs, ASPs and AHPs which is in the left hand side of the page. However, you need to have a S-user ID of the VAR.
    The following are the steps need to perform in implementing the Enterprise Support firmly known as Service Desk for VARs.
    1. SAP Solution Manager basic settings (IMG)
      a) Initial Configuration Part I
      b) Maintain Profile Parameters
      c) Maintain Logical Systems
      d) Maintain SAP Customer Numbers
      e) Initial Configuration Part II
         1) Activate BC Set
             a) Activate Service Desk BC Set
             b) Activate Issue Monitoring BC set
             c) Set-up Maintainance optimizer
             d) Change online Documentation Settings
             e) Activate Solution Manager Services
             f) Activate integration with change request Managemnt
             g) Define service desk connection in Solution Manager
       2)Get components for SAP Service Market place
            a) Get SAP Components
       3) Get Service Desk Screen Profile
           a)generate Business Partener Screen
       4)Copy By price list
           a)activate Service Desk BC Set
           b)Activate Issue Monitoring BC set
           c)Set-up Maintainance optimizer
          f) Business Add-In for RFC Connections with several SAP customers
          g) Business Add-In for RFC Connection of Several SAP Cust. no.
          h) Set-Up SAP Support Connection for Customers
          i) Assign S-user for SAP Support Portal functionality
          j) Schedule Background Jobs
          k) Set-Up System Landscape
          l) Create Key Users
          m) Create Message Processor
    2. Multiple SAP Customer Numbers
          a) Business Add-In for RFC Connections with several SAP customer numbers
          b) Set-Up SAP Support Connection for Customers
    3. Data transfer from SAP
          a) Data Transfer from SAP
    4. Create u201COrganizationu201D Business Partner
    5. Service Provider function (IMG)
          a) Business Add-In for RFC Connections with several SAP customer numbers
          b) Business Add-In for Text Authorization Check
          c) Activate BC Set for Service Provider
          d) Activate Text Types
          e) Adjust Service Desk Roles for Service Provider Menu
    6. Service Provider: Value-Added Reseller (VAR)
          a) Business Add-In to Process Actions (Post-Processing Framework)
         b) Activate BC Sets for Configuration
         c) Create Hierarchy and Product Category
         d) Set-Up Subcategories
         e) Create Business Partner as Person Automatically
         f) Set-Up Automatic Confirmation of Messages
        g) Maintain Business Partner Call Times
        h) Set-Up Incident Management Work Center
    7. Work Center (Web UI)
        a) Activate Solution Manager Services
        b) Assign Work Center Roles to Users
    Hope it helps.
    Regards,
    Satish.

  • Branding bar in  the Enterprise Portal

    Hi,
    All the requirements is  to build of the header bar (branding bar) in  the Enterprise Portal.
    Currently when I click in left nav  , the SAP EP Links open up in new window.
    These pages do not have any Company  Branding header on the top.
    I am required to put Branding header  on these EP Pages and call them on to MOSS UI.
    Plz refer the solution to me.
    Thanks,

    Dear Sanjay ,
    Please clarify the below points so that we can understand exactly what issue you are facing .
    1. " requirements is to build of the header bar (branding bar)"  --- Are you referring to the portal  MastHead ?
    (typically mastheadincludes -- welcome "name of user who logs in " , Branding Image - horizontal image bar, help , log off n personalize button"
    2. "when I click in left nav , the SAP EP Links open up in new window. "
    In the left Navigation what are you clicking , what exactly is opening in a new window .
    Kind Regards,
    Ronica

  • Stopping the Enterprise Manager Console (Oracle 10g on SuSE 9.1)

    I'm trying to stop the Enterprise Manager Console by issuing the command:
    ${ORACLE_HOME}/bin/emctl stop dbconsole
    Unfortunately, the command fails to stop the EM Console. Here's the output I get:
    TZ set to US/Pacific
    Oracle Enterprise Manager 10g Database Control Release 10.1.0.2.0
    Copyright (c) 1996, 2004 Oracle Corporation. All rights reserved.
    http://<hostname>:5505/em/console/aboutApplication
    Stopping Oracle Enterprise Manager 10g Database Control ...
    --- Failed to shutdown DBConsole Gracefully ---
    failed.
    The only way I can stop the EM Console (and related services--i.e., emagent) is to kill its process.
    Everything (Listener, DB Instance, EM Console) starts fine. I can stop the Listener and DB Instance without any problems. It's just the EM Console shutdown that doesn't happen cleanly.
    Has anyone else encountered the same condition? If so, what was the solution?
    Here's my operating environment:
    SuSE 9.1 (Kernel 2.6.5-7.108-default)
    Oracle 10g
    Thanks in advance for any help/insight.

    Has anyone else encountered the same condition? If so, what was the solution?Yes. Shutdown/reboot of the system made the error go away.
    Sorry, no better clues,
    Toni

  • ICloud Usage In The Enterprise

    Forgive me if I've posted this in the wrong location, but it seemed to be the best suited area...
    With the announcement of iCloud, I've been trying to find information on how it will be managed on devices that are used in the enterprise? The company I work for has approximately 200 iPad users and 300 iPhone 4 users that sync their corporate mail, calendar and contacts to their devices.
    Each of these users has tethered their device to their own personal iTunes account so they can add music, apps, video, etc to the device as they wish. We secure these devices using a MobileIron appliance along with Apple MDM certificates that allow us to implement security policies on the devices.
    If these users choose to sign up for iCloud, does anyone yet know if it will only allow your me.com account to sync to the cloud? The last thing we would want is for these users to have their corporate mail/contacts/calendars synched to the devices and then simultaneously synched up to iCloud.
    Anyone have any suggestions on how we might combat this? Or if it will even be possible to sync accounts via iCloud for anything other than me.com accounts? Thanks!

    HI All,
    Actually I face the same problem, only mine is using Apple MDM on Lion Server. We plan to deploy 2000 or more iphone 3gs on company cost. Currently in progress and already around 900 devices live using inhouse corporate application.
    Our challenge is on security administration things. Wondering if there is somekind like iCloud that we can use in corporate to track the location in case of lost. we are now experiencing already two device lost on duty.
    Currently all devices that we already deployed are registered to iCloud using one Apple-ID, no problem on registration process. However when I open iCloud, only limited devices was listed, I think just about 90 devices on the list. Unfortunately the two devices that reported lost are not on the list. So I feel hopeless now.
    While MDM can only do Wipe and other things, but can not tracking the location.
    Appreciate if someone can give me a clue the alternative to overcome those issue. Thanks.
    Regards
    AA

  • SSTP VPN fails with Error 0x80092013 when certificate is issued by an Enterprise CA

    I have spent several days trying to configure an SSTP VPN in an environment with a 2008R2 Enterprise CA server without much luck. I have been using the example found at   http://technet.microsoft.com/en-us/library/cc731352(v=ws.10).aspx which
    works very well as long as you configure the CA Extensions tab with an http CRL Distribution point that is included in the CRLs and CDP extension of issued certificates and is available to the client prior to VPN connection.
    Basically my lab environment is as follows:
    Separate 2008R2 domain controller, Single 2008R2 Enterprise CA / RRAS server with one nic. I know the instructions that I mentioned above use an RRAS server with 2 nics but I don't want my RRAS server serving as a router. I have an external hardware firewall
    that port forwards port 443 to my single nic in my RRAS server and this entire configuration works fine as long as I am using a standard CA configuration. The RRAS was configured using the custom option and only VPN was chosen. Since my RRAS server is behind
    a NAT router, the dns name my external client uses to connect is different than the internal name of my RRAS server.
    In the example above, a Windows 2008R2 CA server is configured as a standalone non-enterprise root CA. As long as I stick with a standard CA, I have no problem and everything works.
    My problem is that if I configure my Windows Server 2008R2 Enterprise server as an Enterprise Root CA, My Windows 7 client always gets an "Error 0x80092013 The revocation function was unable to check revocation because the revocation server was offline."
    I'm not certain, but I think the problem is with the way that I request the certificate for my RRAS server. When I configure a standalone standard root CA and use the web enrollment page and use an Advanced Certificate Request, I get a page that I can use
    to fill out the external dns name that I use to connect to SSTP, choose a Server Authentication Certificate,  choose to mark keys as exportable and submit my request. Once I install this key in the Certificates (local computer) / Personal / Certificates
    store, everything works and my client can connect as long as I have installed the root CA certificate on my client.
    When I install my CA as an Enterprise Root CA server, everything changes. I no longer have the same options to install a custom certificate. Instead of getting the same page as I do with a standard CA, I get my choice of Certificate Templates. Prior to this,
    I have duplicated the Computer template in the CA authority and configured the subject name to "supply in request" and configured my CA to issue it. I have tried issuing my RRAS SSTP certificate using the web enrollment and I have also tried using the certificates
    plugins in mmc to request custom certificates and tried using an alternative subject name, filling out the DNS option with my external dns name.
    When it is all said and done, I end up with an RRAS SSTP certificate that has CRL Distribution Points defined as URL=http://www.mywebsite/CertEnroll/myCA.crl and it is available to my client or anyone. I have compared the certificate issued by an Enterprise
    CA vs the Standard CA and I find little difference in the two. I also know that I can reach this RRAS SSTP certificate from my client by going to  https://myexternaladdress.mydomain.com/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/and
    I can view the padlock in IE and view my internal RRAS certificate. The CRL Distribution point looks no different when I have a standard vs an Enterprise CA but my client always fails with the Error 0x80092013 when I have issued the RRAS SSTP certificate
    with the Enterprise CA.
    I have probably re-setup this lab about 20 times and am getting very familiar with getting it set up quickly and working with the standard CA but I want to use an Enterprise CA environment.
    What am I missing? How can I make this work with an Enterprise CA? How can I troubleshoot this?
    Thanks,
    Rod
    Rod Miller

    Thanks for  your reply. I did read the article and addressed that issue in the first part of my previous post. I don't think that the website where I am hosting my CRL has directory browsing permissions or that I have the ability to set them but the
    point of my question was everything works using that same public website when I use a standard CA to create my certificate but does NOT work when I create the certificate using an Enterprise CA.
    Rod
    Rod Miller

  • I am in the Enterprise Dashboard and I can't view User, Identity or Deployment areas, can anyone help?

    When I try to access the User, Identity or Deployment areas in the Enterprise Dashboard there appears to be issues, the page doesn't appear to be able to load.
    I wonder is anyone else experiencing this, for me and my colleague are having issues?
    Please come back to me asap as we are trying to role out the abobe creative suite to the business and already had several holdups
    Many thanks
    Sarah

    Hi Sarah,
    Can you please e-mail me your org name and customer ID via private message? I did check with your e-mail however I do not find any enterprise account.
    Thanks,
    Ashish

  • Using iPad in the Enterprise; close but challenges......

    Getting closer to being able to use iPad in the Enterprise.  Two challenges so far; sorting functions in Numbers Application not existent? Work around? and the second issue, tracking changes in a word document or Pages document when using Pages on iPad?
    Can't analyze data without sorting feature.  Can't review legal or contracts without seeing who changed what?  Any workarounds besides use my Mac Air?
    Thanks

    Getting closer to being able to use iPad in the Enterprise.  Two challenges so far; sorting functions in Numbers Application not existent? Work around? and the second issue, tracking changes in a word document or Pages document when using Pages on iPad?
    Can't analyze data without sorting feature.  Can't review legal or contracts without seeing who changed what?  Any workarounds besides use my Mac Air?
    Thanks

  • IPad in the Enterprise

    Hi all,
    Do you know if there is a way to limit the enterprise users to download only the applications that are "accepted" by the company? Is there kinda a config profile to set up?
    Any help greatly appreciated.
    Thanks and cheers,
    Pierreg256

    Dave, Tom,
    What I understand from the discussion I'm having with you both (and correct me if I'm wrong) is that there are two distinct channels to provide users with apps :
    - the apple appstore : gives users gazillion applications to download and install
    - one's company 'private' appstore : set up using enterprise over the air application distribution.
    The two channels can live together on the same device without interfering one with each other.
    But, when you want to apply restrictions at the application level, though, the configurations profiles you can apply are far too generic and prevent a company to list a predefined set of "allowed" apple appstore applications the users can download on their own.
    Whereas distributing your own applications and provisioning profiles via email or OTA is more fine grained and allows you to deliver only the ones you really want to selected users.
    As you stated, i will definitely contact an apple sales rep to see if I can get more info.
    I really want to thank you both in helping me find an "acceptable" solution to my current issue. This is the first time I join this discussion forum, and I already get very good answers! Thanks guys! I really appreciate and get back on this forum for my next questions.
    Cheers,
    Pierre.

  • Upgradng the enterprise portal from non HA to HA

    Dear Experts,
    We have Enterprise portal 7.01 on windows 2003 with db2 9.1. and 1 dialog instance. presently it is not in HA. We want to change this to HA using MSCS.
    Can any body share some knowledge on this. How to change the existing system.
    thanks alot

    Hi,
    I must want to correct this question as
    " Migrating the enterprise portal from non HA to HA".
    The only option i can see is reinstallation or i mean to say system copy to new HA system.
    Yoy have to plan your connectivity issues in case you are going to change hostname,IP etc.
    Steps:
    1) Install Fresh HA EP system
    2) Take export from source EP system and DB backup
    3) Perform system copy steps on new system
    4) In case host name is changed , inform the respective interfac eowners.
    Hope this will help you to plan better.
    Regards,
    Gagan Deep Kaushal

  • VRF Lite running in the enterprise network

    Hello everybody
    Altough VRF lite (or Mulit VRF) seems to be a Service Provider Tecnology.
    Does it make sense to use it in an Enterprise Network to isolate Networks from others ?
    I cant find any design paper which describes if this would make sense.
    What do you think. Is someone using it ? Does Cisco recommend it ?

    Yes, VRF-lite SHOULD be used in an Enterprise environment to isolate the different security classes of devices.
    In the past you would isolate different groups of users using Layer1, i.e. separate hubs either totally isolated or connected together by a router with ACLs. Since the PCs were only connected at shared 10 Mbit and the routers were such low performance and worms weren't really prevalent, this was not a big security issue at the time.
    Then we migrated to VLANs, which essentially allowed Layer2 isolation within the same switch to provide the same functionality of separating different classes of users and to break up broadcast domains. Unfortunately, everyone connected the VLANs together at Layer3 with a router (or SVI) which essentially connected everything together again! And almost no one gets the ACLs right (if at all) to isolate the VLANs from each other. In fact, in most cases every VLAN can automatically reach every other VLAN from a Layer3 or IP perspective. This is a huge security problem.
    Enter VRF-lite, essentially created by Cisco as their tag switching migrated to standards based MPLS and had a need to isolate Layer3 security domains from each other within the same switch (or router). Think of VLANs for routing tables. VRF stands for 'Virtual Route Forwarding', which basically means separate routing tables. Since VRF-lite is a per-switch feature (running locally to the switch) you will need to use other technologies to connect multiple VRF-lite switches together and keep the traffic isolated, see below.
    What makes this so secure is that there is no command within the switch to connect different VRFs together within the same switch. You would need to connect a cable between two ports on the same switch configured in different VRFs to be able to communicate between them (recent IOS 12.2SR allows tunnels with different source VRFs but that is a corner case). The reason for this is simple, remember the basis for VRF (and VRF-lite) is for a service provider to isolate multiple customers from each other within the same switch. Just like an ATM, Frame-Relay, SONET, or Optical switch, the command line makes it very difficult (or impossible) to accidentally connect 2 different customers together.
    Think about that. Even if someone was able to get ssh enable access to your switch (you aren't running telnet anymore, right?!), they CAN'T connect 2 VRFs together with any command.
    And, yes, this is highly recommended by Cisco Engineers and is actually deployed far more than you think. I have VRF-lite running on at least 10 client's networks and those are LARGE networks. VRF-lite was integrated into the environment purely to solve a Layer3 security class isolation issue. I have used Layer3 dot1q trunks on c6500 switches and tunnels to keep isolated connectivity between VRFs between switches.
    In Cisco speak, VRF-lite falls under the topic of 'Path Isolation' which is combined with other features that isolate traffic within the same network such as dot1q trunking, tunneling, VPN, policy-routing, and MPLS. Do a search on Cisco's web site for 'path isolation' and you will find a bunch of info.
    See the following URLs for a good start:
    http://www.cisco.com/en/US/netsol/ns658/networking_solutions_design_guidances_list.html
    http://www.cisco.com/en/US/netsol/ns658/netbr0900aecd804a17db.html
    http://www.cisco.com/en/US/netsol/ns658/networking_solutions_white_paper0900aecd804a17c9.shtml
    As always, rate all posts appropriately, particularly those that provide value and don't be shy about following up with additional questions or comments.
    Good luck!

Maybe you are looking for