Wireless Access

last person joined: 22 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Multiple WPA2-AES Auths

This thread has been viewed 1 times
  • 1.  Multiple WPA2-AES Auths

    MVP
    Posted Aug 27, 2014 01:56 PM

    Customer running Aruba 7210 controller with WPA2-AES network. RADIUS server is Bradford CM3000, which talks to Windows NPS and AD. When a user connects to wireless, they have to enter their username/password twice every time to successfully connect. Is there any controller configuration that might be causing this?

     

    Were also having an issue with automatically reconnecting to the wireless, but I feel that is more a problem with GroupPolicy settings or the devices itself.


    #7210


  • 2.  RE: Multiple WPA2-AES Auths

    Posted Aug 27, 2014 02:00 PM
    That's seems like certificate issue


  • 3.  RE: Multiple WPA2-AES Auths

    EMPLOYEE
    Posted Aug 27, 2014 02:02 PM

    Are the users being prompted to accept a certificate?



  • 4.  RE: Multiple WPA2-AES Auths

    MVP
    Posted Aug 27, 2014 02:04 PM

    Customer was having issues where the certificate was saying "untrusted" although it was purchased through VeriSign. I'm finding out if it is still an issue, but I was advised that it was being fixed.



  • 5.  RE: Multiple WPA2-AES Auths

    EMPLOYEE
    Posted Aug 27, 2014 02:07 PM

    This is normal behavior. It has nothing to do with the certificate being signed by a public CA. It is saying that the certificate (server) has not been explicitly trusted for the SSID/network.

     

    Are all of your devices being configured through group policy?



  • 6.  RE: Multiple WPA2-AES Auths

    MVP
    Posted Aug 27, 2014 02:10 PM

    Ok, that's good to know. Yes, all devices are configured through Group Policy. Is there something in Group Policy they are missing?



  • 7.  RE: Multiple WPA2-AES Auths
    Best Answer

    EMPLOYEE
    Posted Aug 27, 2014 02:11 PM

    OK. So make sure that the Root CA (that signed the RADIUS server cert) is checked in the config as well as the server names (common name(s) of the certificate(s)) are entered. See below:

     

     peap-win-supplicant.png



  • 8.  RE: Multiple WPA2-AES Auths

    MVP
    Posted Aug 28, 2014 04:56 PM

    That seemed to be a major fix for the issues. 

     

    Customer did not have "Verify Server Certificate" checked, so they did not have the cert selected. Also they did not have "Use Windows credentials for authentication" checked, which was why it was not automatically connecting them and prompting them for passwords after logging in. Fixed settings and updated Group policy on devices. 

     

    We still had a few scattered problem, but determined it was still Microsoft server and Group OU misconfiguration. 

     

    Thanks for the help!



  • 9.  RE: Multiple WPA2-AES Auths

    Posted Aug 27, 2014 02:10 PM

    Also check in the security logs to see what errors messages are showing up ?

    In the NPS policy can you please check under the WPA2/AES settings to see if the correct cert was selected ?