Networking Forums

Networking Forums > Computer Networking > Windows Networking > How to use PAP with IAS

Reply
Thread Tools Display Modes

How to use PAP with IAS

 
 
=?Utf-8?B?Um9nZXI=?=
Guest
Posts: n/a

 
      12-21-2004, 10:59 AM
Have been running a simple setup of IAS on windows 2000 to been able to use
Radius login from my HP switches for centralized management. After upgrade to
Windows 2003 that stopped working. I have investigated and have realized that
I can’t make IAS to accept PAP. If I change to CHAP it works fine. The
remote access policy is set to allow PAP. My logs looks like this
User roger was denied access.
Fully-Qualified-User-Name = MEAB\roger
NAS-IP-Address = 192.168.100.5
NAS-Identifier = HP ProCurve Switch 5308XL
Called-Station-Identifier = <not present>
Calling-Station-Identifier = <not present>
Client-Friendly-Name = Hp Procurve 5300
Client-IP-Address = 192.168.100.5
NAS-Port-Type = Virtual
NAS-Port = <not present>
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = PAP
EAP-Type = <undetermined>
Reason-Code = 16
Reason = Authentication was not successful because an unknown user name or
incorrect password was used.


 
Reply With Quote
 
 
 
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      12-21-2004, 05:57 PM
I searched the KB and didn't see anything about changes to PAP on IAS 2003.
You might need to call PSS, maybe you found a bug?

Why, though, are you using PAP? Do you know that PAP sends passwords in the
clear? We usually advise against it. If your routers can do CHAP, that's
a better choice. MS-CHAP and MS-CHAPv2 are increasingly even better.

Steve Riley
(E-Mail Removed)



> Have been running a simple setup of IAS on windows 2000 to been able
> to use
> Radius login from my HP switches for centralized management. After
> upgrade to
> Windows 2003 that stopped working. I have investigated and have
> realized that
> I can't make IAS to accept PAP. If I change to CHAP it works fine.
> The
> remote access policy is set to allow PAP. My logs looks like this
> User roger was denied access.
> Fully-Qualified-User-Name = MEAB\roger
> NAS-IP-Address = 192.168.100.5
> NAS-Identifier = HP ProCurve Switch 5308XL
> Called-Station-Identifier = <not present>
> Calling-Station-Identifier = <not present>
> Client-Friendly-Name = Hp Procurve 5300
> Client-IP-Address = 192.168.100.5
> NAS-Port-Type = Virtual
> NAS-Port = <not present>
> Proxy-Policy-Name = Use Windows authentication for all users
> Authentication-Provider = Windows
> Authentication-Server = <undetermined>
> Policy-Name = <undetermined>
> Authentication-Type = PAP
> EAP-Type = <undetermined>
> Reason-Code = 16
> Reason = Authentication was not successful because an unknown user
> name or
> incorrect password was used.



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




1 2 3 4 5 6 7 8 9 10 11