Radius server authentication


i having trouble radius server. can not seem find article deals issue on internet here goes.  i getting id of 6274 reason code of 2.  there not sufficient access rights process request. can point me in right direction?

log name:      security
source:        microsoft-windows-security-auditing
date:          1/13/2015 2:16:37 pm
event id:      6274
task category: network policy server
level:         information
keywords:      audit failure
user:          n/a
computer:      msfc-server5.sltmas.et30.com
description:
network policy server discarded request user.

contact network policy server administrator more information.

user:
security id: sltmas\sltmas
account name: sltmas
account domain: sltmas
fully qualified account name: sltmas\sltmas

client machine:
security id: null sid
account name: -
fully qualified account name: -
os-version: -
called station identifier: 20-4e-7f-7b-f9-43
calling station identifier: 74:d0:2b:12:77:93

nas:
nas ipv4 address: 192.168.1.42
nas ipv6 address: -
nas identifier: 20-4e-7f-7b-f9-41
nas port-type: ethernet
nas port: 3

radius client:
client friendly name: testswitch
client ip address: 192.168.1.79

authentication details:
connection request policy name: secure wired (ethernet) connections
network policy name: -
authentication provider: windows
authentication server: msfc-server5.sltmas.et30.com
authentication type: eap
eap type: -
account session identifier: -
reason code: 2
reason: there not sufficient access rights process request.

event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>6274</eventid>
    <version>0</version>
    <level>0</level>
    <task>12552</task>
    <opcode>0</opcode>
    <keywords>0x8010000000000000</keywords>
    <timecreated systemtime="2015-01-13t20:16:37.941687000z" />
    <eventrecordid>373396</eventrecordid>
    <correlation />
    <execution processid="640" threadid="8520" />
    <channel>security</channel>
    <computer>msfc-server5.sltmas.et30.com</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-21-3664835645-39314575-1963916244-1103</data>
    <data name="subjectusername">sltmas</data>
    <data name="subjectdomainname">sltmas</data>
    <data name="fullyqualifiedsubjectusername">sltmas\sltmas</data>
    <data name="subjectmachinesid">s-1-0-0</data>
    <data name="subjectmachinename">-</data>
    <data name="fullyqualifiedsubjectmachinename">-</data>
    <data name="machineinventory">-</data>
    <data name="calledstationid">20-4e-7f-7b-f9-43</data>
    <data name="callingstationid">74:d0:2b:12:77:93</data>
    <data name="nasipv4address">192.168.1.42</data>
    <data name="nasipv6address">-</data>
    <data name="nasidentifier">20-4e-7f-7b-f9-41</data>
    <data name="nasporttype">ethernet</data>
    <data name="nasport">3</data>
    <data name="clientname">testswitch</data>
    <data name="clientipaddress">192.168.1.79</data>
    <data name="proxypolicyname">secure wired (ethernet) connections</data>
    <data name="networkpolicyname">-</data>
    <data name="authenticationprovider">windows</data>
    <data name="authenticationserver">msfc-server5.sltmas.et30.com</data>
    <data name="authenticationtype">eap</data>
    <data name="eaptype">-</data>
    <data name="accountsessionidentifier">-</data>
    <data name="reasoncode">2</data>
    <data name="reason">there not sufficient access rights process request.</data>
  </eventdata>
</event>

log name:      application
source:        microsoft-windows-eaphost
date:          1/13/2015 1:50:09 pm
event id:      1006
task category: authenticator
level:         information
keywords:      
user:          system
computer:      msfc-server5.sltmas.et30.com
description:
negotiation failed. requested eap methods not available
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-eaphost" guid="{6eb8db94-fe96-443f-a366-5fe0cee7fb1c}" />
    <eventid>1006</eventid>
    <version>0</version>
    <level>4</level>
    <task>1</task>
    <opcode>0</opcode>
    <keywords>0x8000000000000000</keywords>
    <timecreated systemtime="2015-01-13t19:50:09.219296600z" />
    <eventrecordid>418473</eventrecordid>
    <correlation />
    <execution processid="412" threadid="8984" />
    <channel>application</channel>
    <computer>msfc-server5.sltmas.et30.com</computer>
    <security userid="s-1-5-18" />
  </system>
  <eventdata>
  </eventdata>
</event>

hi,

please make sure nps server can access domain controller.

please check if nps server has been added ras and ias servers group.

if issue persists, please check if there log entries related issue in accounting log file.

best regards.


steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client