<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39246#M2247</link>
    <description>Greetings,&lt;BR /&gt;
I have a customer running a PoC and now we have problems with the 802.1x EAP-TLS authentication since yesterday.&lt;BR /&gt;
&lt;BR /&gt;
No workstation is able to authenticate on a 802.1x VNS, while the legacy Cisco solution still working fine. All workstations use EAP-TLS for authentication (certificate installed).&lt;BR /&gt;
&lt;BR /&gt;
Maybe it's related to the new Microsoft Update (&lt;A href="https://support.microsoft.com/en-us/kb/3199173" target="_blank" rel="nofollow noreferrer noopener"&gt;https://support.microsoft.com/en-us/kb/3199173&lt;/A&gt;) they deployed yesterday?&lt;BR /&gt;
&lt;BR /&gt;
The customer is running EW 10.11.03.0004.&lt;BR /&gt;
&lt;BR /&gt;
The NPS logs show information like this:&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;Logging Results:&lt;BR /&gt;
Accounting information was written to the local log file.&lt;BR /&gt;
Reason Code:  22&lt;BR /&gt;
Reason:  The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.&lt;/BLOCKQUOTE&gt;Running some sniffing, we got something interesting:&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;The user tries to connect to the network and the EW send an Access-Request to the NPS 
&lt;/LI&gt;&lt;LI&gt;The NPS answer with a Access-Challenge. Inside the packet, there's an EAP-Message(79) indicating the type as "TLS EAP (EAP-TLS) (13)" 
&lt;/LI&gt;&lt;LI&gt;The EW send another Access-Request with an EAP-Message (79) containing: "Type Legacy Nak (Response Only) (3)" and "Desired Auth Type: Protected EAP (EAP-PEAP) (25)". 
&lt;/LI&gt;&lt;LI&gt;The NPS send an Access-Reject message with "Code: Failure (4)"&lt;/LI&gt;&lt;/OL&gt;It seems that the EW wants to use EAP-PEAP instead of the EAP-TLS (expected by the NPS Server and was working until yesterday).&lt;BR /&gt;
&lt;BR /&gt;
This makes sense? The customer is trying our solution to replace the existing Cisco infrastructure, but now we are in trouble.&lt;BR /&gt;
&lt;BR /&gt;
We asked GTAC, but there's nothing reported until now.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas? Maybe something needs to be fixed on a new FW release?&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
    <pubDate>Fri, 11 Nov 2016 05:00:00 GMT</pubDate>
    <dc:creator>LeoP1</dc:creator>
    <dc:date>2016-11-11T05:00:00Z</dc:date>
    <item>
      <title>ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39246#M2247</link>
      <description>Greetings,&lt;BR /&gt;
I have a customer running a PoC and now we have problems with the 802.1x EAP-TLS authentication since yesterday.&lt;BR /&gt;
&lt;BR /&gt;
No workstation is able to authenticate on a 802.1x VNS, while the legacy Cisco solution still working fine. All workstations use EAP-TLS for authentication (certificate installed).&lt;BR /&gt;
&lt;BR /&gt;
Maybe it's related to the new Microsoft Update (&lt;A href="https://support.microsoft.com/en-us/kb/3199173" target="_blank" rel="nofollow noreferrer noopener"&gt;https://support.microsoft.com/en-us/kb/3199173&lt;/A&gt;) they deployed yesterday?&lt;BR /&gt;
&lt;BR /&gt;
The customer is running EW 10.11.03.0004.&lt;BR /&gt;
&lt;BR /&gt;
The NPS logs show information like this:&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;Logging Results:&lt;BR /&gt;
Accounting information was written to the local log file.&lt;BR /&gt;
Reason Code:  22&lt;BR /&gt;
Reason:  The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.&lt;/BLOCKQUOTE&gt;Running some sniffing, we got something interesting:&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;The user tries to connect to the network and the EW send an Access-Request to the NPS 
&lt;/LI&gt;&lt;LI&gt;The NPS answer with a Access-Challenge. Inside the packet, there's an EAP-Message(79) indicating the type as "TLS EAP (EAP-TLS) (13)" 
&lt;/LI&gt;&lt;LI&gt;The EW send another Access-Request with an EAP-Message (79) containing: "Type Legacy Nak (Response Only) (3)" and "Desired Auth Type: Protected EAP (EAP-PEAP) (25)". 
&lt;/LI&gt;&lt;LI&gt;The NPS send an Access-Reject message with "Code: Failure (4)"&lt;/LI&gt;&lt;/OL&gt;It seems that the EW wants to use EAP-PEAP instead of the EAP-TLS (expected by the NPS Server and was working until yesterday).&lt;BR /&gt;
&lt;BR /&gt;
This makes sense? The customer is trying our solution to replace the existing Cisco infrastructure, but now we are in trouble.&lt;BR /&gt;
&lt;BR /&gt;
We asked GTAC, but there's nothing reported until now.&lt;BR /&gt;
&lt;BR /&gt;
Any ideas? Maybe something needs to be fixed on a new FW release?&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Fri, 11 Nov 2016 05:00:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39246#M2247</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2016-11-11T05:00:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39247#M2248</link>
      <description>Hi Leo.    The controller/AP is only encapsulating/decapsulating the traffic from EAPoL to EAP in the radius protocol. If there is wrong eap type it is on the client or on the radius server.    I would focus to client/radius server troubleshooting.    You may check the wireshark capture what eap is being sent by the client...    Good luck!    Z.</description>
      <pubDate>Fri, 11 Nov 2016 05:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39247#M2248</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-11-11T05:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39248#M2249</link>
      <description>Have you verified that the server and client certs are all valid.  Also, make sure the data / time is correct on the RADIUS server.  I have seen time drift cause this error before.  I suggest using a NTP server for everything (just making some suggestions).  &lt;BR /&gt;
&lt;BR /&gt;
Also, check to make sure EAP-MSCHAPv2 is selected for your authentication methods ... &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Nov 2016 05:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39248#M2249</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-11-11T05:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39249#M2250</link>
      <description>Greetings Pala and Jeremy,&lt;BR /&gt;
&lt;BR /&gt;
Following up with the issue, the customer called me telling the Cisco solution suddenly stopped working too...&lt;BR /&gt;
&lt;BR /&gt;
Some suspects have arisen about the MS KB&lt;A href="https://support.microsoft.com/en-us/kb/3199173" target="_blank" rel="nofollow noreferrer noopener"&gt;3199173&lt;/A&gt; and the customer decided to uninstall it and voialà... Everything come back to life!&lt;BR /&gt;
&lt;BR /&gt;
Both Cisco and Extreme wireless solutions are operational without touching anything in the configs, just uninstalling the KB from the PC clients.&lt;BR /&gt;
&lt;BR /&gt;
MS messed up with something in this update. The customer started a WSUS operation to mass-uninstall this KB from all PCs in the infrastructure.&lt;BR /&gt;
&lt;BR /&gt;
Maybe someone from the Wireless Engineering/PM should take a look at it to avoid issues with other customers and maybe inform the GTAC team about our findings.&lt;BR /&gt;
&lt;BR /&gt;
Thank you for your help!&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Fri, 11 Nov 2016 07:12:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39249#M2250</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2016-11-11T07:12:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39250#M2251</link>
      <description>Greetings,&lt;BR /&gt;
&lt;BR /&gt;
We are running a further investigation...&lt;BR /&gt;
&lt;BR /&gt;
Maybe the KB wasn't the only problem.&lt;BR /&gt;
&lt;BR /&gt;
I'll keep you informed about our progress to try to really pinpoint the root cause.&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Fri, 11 Nov 2016 07:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39250#M2251</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2016-11-11T07:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39251#M2252</link>
      <description>Have we tried going to 10.11.04?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Nov 2016 09:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39251#M2252</guid>
      <dc:creator>Joseph_Burnswor</dc:creator>
      <dc:date>2016-11-11T09:13:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39252#M2253</link>
      <description>Keep us posted.</description>
      <pubDate>Fri, 11 Nov 2016 13:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39252#M2253</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-11-11T13:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39253#M2254</link>
      <description>Greetings guys,&lt;BR /&gt;
&lt;BR /&gt;
After a further investigation with the customer we found the issue.&lt;BR /&gt;
&lt;BR /&gt;
After the MS KB something changed in the Windows EAP process. Taking a closer look at the NPS the customer added the PEAP method to the rule and now it works.&lt;BR /&gt;
&lt;BR /&gt;
Before the installation of the KB they only used the "Smartcard or certificate" method on the NPS rule.&lt;BR /&gt;
&lt;BR /&gt;
Maybe in other scenarios the customers already had Cert + PEAP configured on the NPS and will not be affected, but in this case the config adjustments in NPS solved the problem.&lt;BR /&gt;
&lt;BR /&gt;
It's cool to keep the community aware of this "new" issue and take a look at the NPS configs.&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your help!&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Fri, 11 Nov 2016 21:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39253#M2254</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2016-11-11T21:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39254#M2255</link>
      <description>Hi Leo, it was great meeting you at the partner summit a few weeks ago.  Thanks for coming back to the community and helping everyone to be aware of this issue!&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Nov 2016 21:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39254#M2255</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2016-11-11T21:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: ExtremeWireless 10.11.03.0004- 802.1x EAP-TLS auth failed</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39255#M2256</link>
      <description>It was very nice to meet you too! Thanks for your support! </description>
      <pubDate>Fri, 11 Nov 2016 21:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/extremewireless-10-11-03-0004-802-1x-eap-tls-auth-failed/m-p/39255#M2256</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2016-11-11T21:05:00Z</dc:date>
    </item>
  </channel>
</rss>

