<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC 5.1.0.140 PEAP Authentication fails if username does not match the exact sAMAccountName in Analytics &amp; Visibility</title>
    <link>https://community.extremenetworks.com/t5/analytics-visibility/nac-5-1-0-140-peap-authentication-fails-if-username-does-not/m-p/51708#M62</link>
    <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
Can you try to apply the following appliance property to the NAC appliance and see if it resolves the issue:&lt;BR /&gt;
&lt;BR /&gt;
Right click the NAC appliance and click "add appliance property"&lt;BR /&gt;
&lt;BR /&gt;
Click the small green "add property" button.&lt;BR /&gt;
&lt;BR /&gt;
For the property name use: RADIUS_XP_LOCAL_AUTH_FIX_USERNAME&lt;BR /&gt;
For the property value use: false&lt;BR /&gt;
&lt;BR /&gt;
Make sure there are no extra spaces and it is caps sensitive. If you have multiple appliances add the property accordingly.&lt;BR /&gt;
&lt;BR /&gt;
Does this appliance property resolve the issue?&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
    <pubDate>Fri, 21 Mar 2014 00:25:00 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2014-03-21T00:25:00Z</dc:date>
    <item>
      <title>NAC 5.1.0.140 PEAP Authentication fails if username does not match the exact sAMAccountName</title>
      <link>https://community.extremenetworks.com/t5/analytics-visibility/nac-5-1-0-140-peap-authentication-fails-if-username-does-not/m-p/51707#M61</link>
      <description>I upgraded NAC from 5.0.0.232 to 5.1.0.140. After the upgrade the PEAP Authentication of users failed with the error message: "The authentication request was rejected due to NTLM authentication error:  Logon failure (0xc000006d)"&lt;BR /&gt;
&lt;BR /&gt;
I figured out that this is because the username with which the user logs into windows does not match excactly the sAMAccountName of the Active Directory. E.g.: &lt;BR /&gt;
- AD: UserName&lt;BR /&gt;
- Winlogin: username&lt;BR /&gt;
&lt;BR /&gt;
When the user loggs in withe the exact typo - the authentication is passed.&lt;BR /&gt;
&lt;BR /&gt;
I get this out of tag.log:&lt;BR /&gt;
&lt;BR /&gt;
If auth passes:&lt;BR /&gt;
&lt;BR /&gt;
2014-02-26 13:47:13,424 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 Stripping domain from username: ACME\UserName to be: UserName for LDAP request... &lt;BR /&gt;
2014-02-26 13:47:13,424 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 Authenticate user: UserName with LDAP configuration: ACME-AD, ldapAuthType: NTLM_AUTH, ldapDomainName: acme.com, ldapPasswordAttr: null &lt;BR /&gt;
2014-02-26 13:47:13,424 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 getNacResponse for MAC: 70-5A-B6-9B-F8-38 =&amp;gt; NAC AAA Response [ID:2412, Command: Proxy User To LDAP Server(0x25), Version: NAC Version 5.1.0(7)] &lt;BR /&gt;
Proxy To: acme.com&lt;BR /&gt;
Stripped UserName: UserName&lt;BR /&gt;
Handle MsCHAP User-Name: Do Nothing(0x0) &lt;BR /&gt;
&lt;BR /&gt;
If auth fails:&lt;BR /&gt;
&lt;BR /&gt;
2014-02-26 13:39:28,650 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 Stripping domain from username: ACME\username to be: username for LDAP request... &lt;BR /&gt;
2014-02-26 13:39:28,650 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 Authenticate user: username with LDAP configuration: ACME-AD, ldapAuthType: NTLM_AUTH, ldapDomainName: acme.com, ldapPasswordAttr: null &lt;BR /&gt;
2014-02-26 13:39:28,650 DEBUG [NacAAAServerRequestProcessor] ESDMAC:9B-F8-38 getNacResponse for MAC: 70-5A-B6-9B-F8-38 =&amp;gt; NAC AAA Response [ID:1877, Command: Proxy User To LDAP Server(0x25), Version: NAC Version 5.1.0(7)] &lt;BR /&gt;
Proxy To: acme.com&lt;BR /&gt;
Stripped UserName: username&lt;BR /&gt;
Handle MsCHAP User-Name: Replace MsCHAP User-Name with User-Name(0x1) &lt;BR /&gt;
 &lt;BR /&gt;
Best Regards,&lt;BR /&gt;
Michael</description>
      <pubDate>Mon, 03 Mar 2014 16:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/analytics-visibility/nac-5-1-0-140-peap-authentication-fails-if-username-does-not/m-p/51707#M61</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2014-03-03T16:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC 5.1.0.140 PEAP Authentication fails if username does not match the exact sAMAccountName</title>
      <link>https://community.extremenetworks.com/t5/analytics-visibility/nac-5-1-0-140-peap-authentication-fails-if-username-does-not/m-p/51708#M62</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
Can you try to apply the following appliance property to the NAC appliance and see if it resolves the issue:&lt;BR /&gt;
&lt;BR /&gt;
Right click the NAC appliance and click "add appliance property"&lt;BR /&gt;
&lt;BR /&gt;
Click the small green "add property" button.&lt;BR /&gt;
&lt;BR /&gt;
For the property name use: RADIUS_XP_LOCAL_AUTH_FIX_USERNAME&lt;BR /&gt;
For the property value use: false&lt;BR /&gt;
&lt;BR /&gt;
Make sure there are no extra spaces and it is caps sensitive. If you have multiple appliances add the property accordingly.&lt;BR /&gt;
&lt;BR /&gt;
Does this appliance property resolve the issue?&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Fri, 21 Mar 2014 00:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/analytics-visibility/nac-5-1-0-140-peap-authentication-fails-if-username-does-not/m-p/51708#M62</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2014-03-21T00:25:00Z</dc:date>
    </item>
  </channel>
</rss>

