Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

2nd NPS server gives Message-Authenticator attribute not valid

This thread has been viewed 15 times
  • 1.  2nd NPS server gives Message-Authenticator attribute not valid

    Posted Mar 30, 2012 01:42 PM
      |   view attached

    Running 6.1.2 on a 3400, the first NPS server in the domain authenticates correctly, but the backup NPS has an issue with the request (Event ID 18). Could this be a certificate error? Our switches and applications authenticate OK on the 2nd NPS. I didn't configure our 3400 for the first NPS, so I'm not sure what I may be missing.


    #3400

    Attachment(s)

    zip
    NPS Error.zip   100 KB 1 version


  • 2.  RE: 2nd NPS server gives Message-Authenticator attribute not valid
    Best Answer

    EMPLOYEE
    Posted Mar 30, 2012 01:45 PM

    #1 reason - Makes sure the preshared key for Radius Clients is correct on the second NPS for that controller.

     



  • 3.  RE: 2nd NPS server gives Message-Authenticator attribute not valid
    Best Answer

    Posted Mar 30, 2012 01:47 PM

    Rick,

     

    Confirm the 2nd NPS server has the proper radius client secret defined. 

     

    Chris



  • 4.  RE: 2nd NPS server gives Message-Authenticator attribute not valid

    Posted Mar 30, 2012 02:12 PM

    If you've verified the preshared key and it's still giving that error,

    1.) Confirm that you have the controller listed as a RADIUS client on the second NPS server.

    2.) Make sure the RADIUS policy is enabled for the EAP type you're using (e.g. PEAP).

    3.) If you're using a server side certificate, make sure the correct one is selected for that policy.

     

    Hope this helps!

     

    - Jay



  • 5.  RE: 2nd NPS server gives Message-Authenticator attribute not valid

    Posted Mar 30, 2012 03:30 PM

    How embarrassing! I swore I copied the shared key correctly, BUT my 6th finger got in the way. Thanks, all.