Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

FAILED: MS-CHAP2-Response is Incorrect

This thread has been viewed 12 times
  • 1.  FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 16, 2017 12:59 PM

    I have two services setup. One is in production using EAP-TLS and working fine. I created another service and cloned the Authentication source used in the production servcice...using EAP-PEAP. In the logs I can see that the EAP-PEAP session establishes. Then there is an eap-mschapv2 challenge issued. I then get the following errors:

     

    2017-03-16 09:08:16,784[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - rlm_mschap: authenticating user xxx, domain xxxx
    2017-03-16 09:08:16,817[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - rlm_mschap: user xxx authentication failed
    2017-03-16 09:08:16,817[Th 21 Req 3234183 SessId R000781e9-01-58cab870] ERROR RadiusServer.Radius - rlm_mschap: AD status:No trusted SAM account (0xc000018b)
    2017-03-16 09:08:16,818[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - MS-Chap User Authentication time = 33 ms
    2017-03-16 09:08:16,818[Th 21 Req 3234183 SessId R000781e9-01-58cab870] ERROR RadiusServer.Radius - rlm_mschap: FAILED: MS-CHAP2-Response is incorrect

     

     



  • 2.  RE: FAILED: MS-CHAP2-Response is Incorrect

    EMPLOYEE
    Posted Mar 16, 2017 01:01 PM
    - Are your ClearPass servers joined to the domain?
    - Is your bind account valid?


  • 3.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 16, 2017 01:09 PM

    Thanks for pointing that out. So, we have 3 CPPM servers. 1 of them is joined and the bind account appears to be working becuase I can browse AD. The other 2 aren't joined;howerver, I don't think they are clustered...or done correctly...so not sure if that matters. 

     

    But the original Service utilizing the same autentiation source (although different authentication methods) is working just fine. 

     

     



  • 4.  RE: FAILED: MS-CHAP2-Response is Incorrect

    EMPLOYEE
    Posted Mar 16, 2017 01:11 PM
    If you’re using PEAPv0/EAP-MSCHAPv2, all servers servicing authentications must be joined to the domain(s).


  • 5.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 16, 2017 01:17 PM

    Ah, I think I see. 

     

    So because the original service is using EAP-TLS, not all servers need to be joined to the domain to work; however, using PEAPv0/EAP-MSCHAPv2, all servers need to be joined for the protocol/authentication to work?

     

    (I didn't set this up and got put on WiFi duty with little experience....so thanks for your patience and time)!



  • 6.  RE: FAILED: MS-CHAP2-Response is Incorrect
    Best Answer

    EMPLOYEE
    Posted Mar 16, 2017 01:30 PM
    Yes. In EAP-TLS, the certificate essentially replaces the password. In PEAPv0/EAP-MSCHAPv2, the actual password is in use and requires domain join in to build a trust domain for NTLMv2/Kerberos.

    That’s why EAP-TLS is the recommended authentication method when possible.


  • 7.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 16, 2017 02:05 PM

    Sorry Tim, one more question. The 2 other servers in the cluster I want to add to the domain. I'm dumb with this stuff and wanted to make sure there wouldn't be an outage with the services during this time? I'm assuming not, but wanted to make sure that I put in a change if there was a possibility of CPPM going offline or using a server that isn't fully connected/joined to the domain.


    Thanks Tim!



  • 8.  RE: FAILED: MS-CHAP2-Response is Incorrect

    EMPLOYEE
    Posted Mar 16, 2017 02:07 PM
    You will not have to reload the server but a few services will restart during the domain join process.


  • 9.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 16, 2017 02:09 PM

    Thanks man! I really appreciate it!



  • 10.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 20, 2017 01:53 PM

    Hey Tim, 

     

    So after adding all 3 servers to the domain, I'm still getting the same error. 


    I saw some other posts out there suggesting to unjoin and then join the servers back to the domain. Does that make sense? Is that suggested in this case?


    Thanks!



  • 11.  RE: FAILED: MS-CHAP2-Response is Incorrect
    Best Answer

    EMPLOYEE
    Posted Mar 20, 2017 01:57 PM
    Try that, but you should also open a TAC case.


  • 12.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 20, 2017 02:00 PM

    Thanks Tim! I will try that as well as open a TAC case. Thanks for your help again!!!



  • 13.  RE: FAILED: MS-CHAP2-Response is Incorrect

    Posted Mar 22, 2017 12:19 PM

    Thanks again Tim! It worked. Last night we had a change to rejoin the clearpass server to the domain. Once done, authentication via AD worked.

     

    It was showing the server as joined to the domain. Looking further in AD we did not see the server. I tried to leave the domain but I kept getting an error (suspecting because it wasn't being seen on the domain within AD). So we just hit join domain and entered in the same domain info and it joined just fine. 


    Thanks again for the help!