|
Possible Causes
|
Corrective Measures
|
|
The RADIUS shared secret on the wireless AP does not match the shared secret configured for RADIUS clients in IAS.
|
Configure the wireless AP to use the same shared secret. The shared secret is specified in the RADIUS Clients node of the IAS snap-in.
|
|
The IAS remote access policy properties are configured to reject the user or computer requests. For example:
-
On the Settings tab, the properties of the policy are set to Deny remote access permission.
-
On the Dial-in Constraints tab of the remote access policy, time restrictions prohibiting the connection are configured.
-
On the Dial-in Constraints tab, an incorrect media type is specified.
|
-
In the IAS snap-in, right-click the applicable remote access policy, click Properties, and then click Grant remote access permission.
-
In the IAS snap-in, right-click the applicable remote access policy, click Properties, click Edit Profile. On the Dial-in Constraints tab, select Allow access only on these days and at these times, and then click Edit to specify allowed access times.
-
In the IAS snap-in, right-click the applicable remote access policy, click Properties, click Edit Profile, and then on the Dial-in Constraints tab, do one of the following:
-
Clear Allow access only through these media (NAS-Port-Type)
-
Select Allow access only through these media (NAS-Port-Type), and then select Wireless - IEEE 802.11.
|
|
A mismatch exists between the trusted root CA that issued the RADIUS server certificate specified in the IAS remote access policy, and the trusted root CA specified in the selected EAP type in Wireless Network (IEEE 802.11) Policies.
|
-
In Group Policy Object Editor, open Wireless Network (IEEE 802.11) Policies.
-
In the details pane, right-click the applicable wireless policy, and then click Properties.
-
On the Preferred Networks tab, in Networks, select the corresponding wireless network, and then click Edit.
-
On the 802.1x tab, in EAP type, click Settings, and then in Trusted Root Certification Authorities, select the certificate that matches the IAS server certificate.
|
|
The vendor-specific attributes (VSAs) for the wireless AP are configured incorrectly.
|
Check the wireless AP product documentation for VSA usage, and then specify the IAS Vendor specific attributes in IAS. If you are unsure about the correct VSA setting, select RADIUS Standard.
|
|
The IP address of the wireless AP (RADIUS client) specified in IAS is incorrect.
|
-
In the IAS snap-in, select RADIUS Clients.
-
In the details pane, right-click the RADIUS client that corresponds to the wireless AP, and then click Properties.
-
On the settings tab, in Address (IP or DNS) type the correct IP address, and then click Verify.
|
|
The IAS server certificate has expired.
|
For information about requesting an IAS Server certificate, see the Windows Server 2003 Help topic Computer certificates for certificate-based authentication.
|
|
The IAS service is stopped.
|
In the Services snap-in, right-click Internet Authentication Service, and then click Start.
|
|
EAP is configured differently in the applicable remote access policy than it is in Wired Network (IEEE 802.11) Policy in Active Directory.
|
Configure both the IAS remote access policy and Wired Network (IEEE 802.11) Policy to use the EAP method that corresponds with your network deployment.
|
|
On a newly configured IAS server:
-
IAS is not registered in Active Directory.
-
The IAS server does not have a server certificate.
|
|