IAS rejecting authentication requests


i have ias server running on windows 2003.  server has been in production 5 years, authenticating requests netscreen 5gt firewall. last week replaced 5gt new juniper ssg20 firewall.  cannot authenticate.  i've worked juniper support , we've rebuilt entire configuration , continue access denied due incorrect username or password.  i've pasted parsed logs failed authentication attempt below.  can see in there might causing problem?

thanks,
joe

nas ip: 192.168.10.254
client username: administrator
timestamp: 07/03/2014 14:05:29
service: ias
radius server: server001
acct-session-id: ns-0000000b
nas-ip-address: 192.168.1.254
nas-port: 11
nas-port-type: virtual (vpn)
called-station-id: 70.110.119.250
calling-station-id: 99.190.125.225
vendor-specific: 0x00000c980a0600000003
client-ip-address: 192.168.11.254
nas-manufacturer: 0
client-friendly-name: netscreen fw
provider-type: windows
proxy-policy-name: use windows authentication users
sam-account-name: domain\administrator
fully-qualified-user-name: domain\administrator
authentication-type: 1
class: 311 1 192.168.1.251 07/03/2014 18:29:58 12
packet-type: accept-request
reason-code: success
--------------------------------------------

nas ip: 192.168.1.254
client username: administrator
timestamp: 07/03/2014 14:05:29
service: ias
radius server: infratrol001
class: 311 1 192.168.1.251 07/03/2014 18:29:58 12
authentication-type: 1
fully-qualified-user-name: domain\administrator
sam-account-name: domain\administrator
proxy-policy-name: use windows authentication users
provider-type: windows
client-friendly-name: netscreen fw
nas-manufacturer: 0
client-ip-address: 192.168.1.254
packet-type: access-reject
reason-code: authentication failure
--------------------------------------------

it turns out problem incorrect shared secret between firewall , ias.  problem, ias/windows returns error of bad username or password.  misleading , hard track down!  working now.

thanks,

joe



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client