IAS rejecting authentication requests
i have ias server running on windows 2003. server has been in production 5 years, authenticating requests netscreen 5gt firewall. last week replaced 5gt new juniper ssg20 firewall. cannot authenticate. i've worked juniper support , we've rebuilt entire configuration , continue access denied due incorrect username or password. i've pasted parsed logs failed authentication attempt below. can see in there might causing problem?
thanks,
joe
nas ip: 192.168.10.254
client username: administrator
timestamp: 07/03/2014 14:05:29
service: ias
radius server: server001
acct-session-id: ns-0000000b
nas-ip-address: 192.168.1.254
nas-port: 11
nas-port-type: virtual (vpn)
called-station-id: 70.110.119.250
calling-station-id: 99.190.125.225
vendor-specific: 0x00000c980a0600000003
client-ip-address: 192.168.11.254
nas-manufacturer: 0
client-friendly-name: netscreen fw
provider-type: windows
proxy-policy-name: use windows authentication users
sam-account-name: domain\administrator
fully-qualified-user-name: domain\administrator
authentication-type: 1
class: 311 1 192.168.1.251 07/03/2014 18:29:58 12
packet-type: accept-request
reason-code: success
--------------------------------------------
nas ip: 192.168.1.254
client username: administrator
timestamp: 07/03/2014 14:05:29
service: ias
radius server: infratrol001
class: 311 1 192.168.1.251 07/03/2014 18:29:58 12
authentication-type: 1
fully-qualified-user-name: domain\administrator
sam-account-name: domain\administrator
proxy-policy-name: use windows authentication users
provider-type: windows
client-friendly-name: netscreen fw
nas-manufacturer: 0
client-ip-address: 192.168.1.254
packet-type: access-reject
reason-code: authentication failure
--------------------------------------------
it turns out problem incorrect shared secret between firewall , ias. problem, ias/windows returns error of bad username or password. misleading , hard track down! working now.
thanks,
joe
Windows Server > Security
Comments
Post a Comment