Windows 10: Windows Endpoint stop sending RADIUS Authentication

Discus and support Windows Endpoint stop sending RADIUS Authentication in Windows 10 Software and Apps to solve the problem; Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS... Discussion in 'Windows 10 Software and Apps' started by NET242, Mar 4, 2024.

  1. NET242 Win User

    Windows Endpoint stop sending RADIUS Authentication


    Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to authenticated with our NAC which cause Authentication failed. I have raised ticket via Forescout Support and they said issue is coming from endpoint itself.on Endpoint, We could see that Endpoint are not sending any authentication entity such as Username....etc for authentication.Endpoint Error Message is:ConnectionID 0x2

    :)
     
    NET242, Mar 4, 2024
    #1
  2. DimitarEX Win User

    Radius server + WLC and Client Certificate Authentication

    Hello people,

    We have an issue with our radius server.

    I will explain what is our goal and what configuration we have so far:

    Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication.

    Each client in our domain has a unique personal certificate.

    The idea is when an employee opens his PC automatically connects to the specified by the GPO recommended network by using the certificate and not the username and password.



    Currently, we configured the WLC Cisco controller to receive the client certificate, authenticate it and provide the IP address(of course if the policies are validated).

    Afterward that the WLC controller has to send the request to the radius server. The radius should check if the certificate is valid (not expired) and not included in the revocation list.

    Here our issue came. It seems that the radius cannot access the revocation list and cannot check if the certificate is revoked.

    We validated that by disabling the revocation list check in the Radius server registry settings.

    If we set it to ignore the revocation list check, the authentication succeeds, and the client is authenticated successfully.

    The thing is that this way we lower the security of the connection significantly and we would like to make sure the certificate is validated against the revocation list.

    At the same time, there are no issues in the connection between the RADIUS server and the server where the revocation list is stored/published.



    Could you please let me know if there is any specific configuration that should be made in order for the radius to be able to check the status of the authenticated certificate in the revocation list?

    Is there any configuration guide that we have to follow in order to implement the necessary configuration in the most proper way?
     
    DimitarEX, Mar 4, 2024
    #2
  3. AP unable to authenticate to RADIUS server

    Hi,



    Thank you for writing to Microsoft Community Forums.



    We understand the difficulties as AP is unable to authenticate a RADIUS server.



    In this scenario, we would suggest you to post your query in
    TechNet forums, where we have experts and support professionals
    who are well equipped with the knowledge on Access Protection to assist you with the appropriate troubleshooting steps



    Aditya Roy

    Microsoft Community – Moderator
     
    Aditya_Roy, Mar 4, 2024
    #3
  4. Windows Endpoint stop sending RADIUS Authentication

    windows RADIUS 2022 NPS server

    I have recently installed windows 2022 radius server and will need to understand about certificate and cisco switch configuration to authenticate and activate aaa.

    Could you please provide me step by step process to configure cisco switch and certificate? ?
     
    Darshan Desai1, Mar 4, 2024
    #4
Thema:

Windows Endpoint stop sending RADIUS Authentication

Loading...
  1. Windows Endpoint stop sending RADIUS Authentication - Similar Threads - Endpoint stop sending

  2. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

    in Windows 10 Gaming
    Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...: We are commencing a rollback of our employees' computer operating systems from Windows 24H2 to 23H2 due to complications with RADIUS Authentication for SmartCards and RADIUS VLAN Tagging on Wi-Fi networks in the newest version of Windows.Regarding RADIUS SmartCard...
  3. Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...

    in Windows 10 Software and Apps
    Windows 24H2 Broken Changes - Problem with RADIUS SmartCard Authentication & RADIUS VLAN...: We are commencing a rollback of our employees' computer operating systems from Windows 24H2 to 23H2 due to complications with RADIUS Authentication for SmartCards and RADIUS VLAN Tagging on Wi-Fi networks in the newest version of Windows.Regarding RADIUS SmartCard...
  4. Windows Endpoint stop sending RADIUS Authentication

    in Windows 10 Gaming
    Windows Endpoint stop sending RADIUS Authentication: Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to...
  5. Windows Endpoint stop sending RADIUS Authentication

    in AntiVirus, Firewalls and System Security
    Windows Endpoint stop sending RADIUS Authentication: Dear Team,We have many endpoint enabled RADIUS authentication via our NAC Solution Forescout. Around 2000+ Endpoints are authenticated via EAP-TLS Certificate but during Friday Morning, We noticed that many endpoint start failing authentication and try to use MAC Address to...
  6. Radius serer + WLC and Client Certificate Authentication

    in Windows 10 Gaming
    Radius serer + WLC and Client Certificate Authentication: Hello people,We have an issue with our radius server.I will explain what is our goal and what configuration we have so far: Our goal is to authenticate clients in the domain using WLC and Client Certificate Authentication. Each client in our domain has a unique personal...
  7. Windows 11 22H2 cannot authentication with 802.1x radius authentication server.

    in Windows 10 Gaming
    Windows 11 22H2 cannot authentication with 802.1x radius authentication server.: We try connnect wifi with security 802.1x authentication but it show can't connect this network and as I check the log on Wireless controller show that terminal not respond to radius server after EAP connect. How we can solve this issue because windows 10 can connect normally...
  8. Windows 11 22H2 cannot authentication with 802.1x radius authentication server.

    in Windows 10 Software and Apps
    Windows 11 22H2 cannot authentication with 802.1x radius authentication server.: We try connnect wifi with security 802.1x authentication but it show can't connect this network and as I check the log on Wireless controller show that terminal not respond to radius server after EAP connect. How we can solve this issue because windows 10 can connect normally...
  9. RADIUS WiFi authentication stopped working 1 site at a time

    in Windows 10 Customization
    RADIUS WiFi authentication stopped working 1 site at a time: Almost exactly 2 years ago, we setup RADIUS WiFi Authentication for our 4 sites, all with Unifi AP’s Unifi Controller running on 1 server, connecting to Network Policy Server on our Domain Controller. Out of the blue last week, users at site A discovered WiFi was not...
  10. AP unable to authenticate to RADIUS server

    in Windows 10 Network and Sharing
    AP unable to authenticate to RADIUS server: RADIUS is running on NPS Windows 2016 Datacenter AP is Meraki MR33 I have tried just about everything I can think of in this configuration and cannot get a connection. I have looked over some of the other articles in the forum also but no success. If anyone can point out...