Wired Intelligent Edge

 View Only
last person joined: 2 days ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Radius Authentication Using MS NPS Server

This thread has been viewed 40 times
  • 1.  Radius Authentication Using MS NPS Server

    Posted Sep 29, 2023 04:11 PM

    Hello all.  I am wanting to configure my 2930M switches using Radius authentication with a Windows NPS Server.  I have applied the following configuration to the switch:

    radius-server host x.x.x.x key <<insert-key>>
    radius-server dead-time 5
    radius-server timeout 10
    aaa authentication login privilege-mode
    aaa authentication ssh login radius local
    aaa authentication ssh enable radius local

    On the Windows Server, under the Network Policy Server module, I have applied the following:

    • Added one switch as a radius client
    ar1

    • Under the Network Policies Section, I have created a new policy with the following settings & attributes:
    ar2
    ar4

    ar5
    ar6
    ar7
    I've obtained some settings from previous discussion posts related to the same issue, but am not able to log in using my radius credentials, or the local (manager) account.  What would I be missing, or need to add in order to get this to work?  Thanks


  • 2.  RE: Radius Authentication Using MS NPS Server

    EMPLOYEE
    Posted Sep 30, 2023 06:21 PM

    In your 4th screenshot, try to enable "unencrypted authentication Pap/Spap".  To troubleshoot what is wrong, look at the eventviewer under NPS to see if it is even handling your messages.



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: Radius Authentication Using MS NPS Server

    Posted Oct 05, 2023 06:34 PM

    Hi Cjoseph.  I have enabled the option that you had suggested, but the problem still persists.  I looked at the NPS event logs on the Windows Server, and show the following message when attempting to SSH in:




  • 4.  RE: Radius Authentication Using MS NPS Server

    EMPLOYEE
    Posted Oct 06, 2023 05:45 AM

    You have something configured that I cannot see.  It is somehow hitting the "connections to other access servers" network policy.  Please start with this older post as a template:  https://community.arubanetworks.com/community-home/digestviewer/viewthread?MID=6586



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 5.  RE: Radius Authentication Using MS NPS Server

    Posted Oct 06, 2023 03:16 PM
      |   view attached

    Yes, I looked at my existing Network policies, and found that this new policy had the lowest processing order, and was being overridden by two other policies that were denying access using the EAP, MS-CHAP v1, MS-CHAP v2, SPAP and PAP authentication methods.

    I have moved the new policy higher in terms of processing order, yet the problem still persists.

    I have also followed the guide which you have referenced, but I am not sure whether if I should be applying the same attributes as the ones listed in the document, or keep the values which I had entered.





  • 6.  RE: Radius Authentication Using MS NPS Server

    EMPLOYEE
    Posted Oct 06, 2023 03:33 PM

    Is the NPS server denying the connection in the log or allowing it? 



    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 7.  RE: Radius Authentication Using MS NPS Server

    Posted Oct 06, 2023 06:15 PM

    The issue has now been resolved.  I re-created the Network Policy, and specified only 'PAP' as the authentication method.  Thanks for your assistance.