Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

MSCHAP: AD status:Invalid workstation (0xc0000070)

This thread has been viewed 4 times
  • 1.  MSCHAP: AD status:Invalid workstation (0xc0000070)

    Posted Aug 23, 2014 06:13 AM

    Hi all expert , i got some problem that i used CPPM 6.3.2 and AD windows server 2008. I can added windows server to "authentication source" and can see all OU or tree under this server at CPPM. But when i authenticate with my notebook passthourgh 802.1x of Aruba controller, It show this error

     

    RADIUS MSCHAP: AD status:No logon servers (0xc000005e)
    MSCHAP: AD status:No logon servers (0xc000005e)
    MSCHAP: Authentication failed
    EAP-MSCHAPv2: User authentication failure

     

    with Error code 216.

     

    I saw some body used to posted with this error and Cappalli adviced to add ClearPass server's computer account to the Log On To list on Windows server. However i really don't know how to add this on windows server and "ClearPass server's computer account" is the account that i add on bind name on CPPM right?

    So could you please advice me how to add on windows , which menu on window that i must do it? And which ClearPass server's computer account that i must add it to?

     

    Thanks ...



  • 2.  RE: MSCHAP: AD status:Invalid workstation (0xc0000070)

    EMPLOYEE
    Posted Aug 23, 2014 07:49 AM
    Are your ClearPass servers joined to the domain?


  • 3.  RE: MSCHAP: AD status:Invalid workstation (0xc0000070)

    Posted Aug 24, 2014 04:03 AM

    Yes i got the solution. Due to my clearpass used to join with the previous DC , so after i leave the domain and try to join with my new DC. It's work. However i change DNS ip address on my clearpass  to point to the new DC too. But not sure it's the point or not.

     

    Thanks a lot ,


    @cappalli wrote:
    Are your ClearPass servers joined to the domain?