- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Microsoft NPS + Microsoft NPS for MAC-Based RADIUS
Hi Guys,
Have any of you successfully setup MAC authentication bypass policy with NPS?
I'm following this document: Configuring Microsoft NPS for MAC-Based RADIUS - MS Switches - Cisco Meraki
All is set according to documentation but port with this policy is not forwarding traffic.
NPS logs are catchings my device request but it says: access denied because no matching network policy was found
Solved! Go to solution.
- Labels:
-
ACLs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you all for suggestions. I went for the 10th time through entire configuration and all was set correctly... except that I put test user in a wrong AD group 😛
This is why it's requests didn't match any of configured network policies 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Funny thing - I have also other Network policy which has NAS Port Type set to Wireless and is used for WIFI AD auth. If I remove NAS Port Type from it I have a match but then authentication method is not supported (unencrypted) and have access denied also:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe it will help you.
https://www.youtube.com/watch?v=Iput9nLnldA
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the authentication request is coming in using PAP, then you need to add that as an allowed method in your NPS policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is your Connection Request Policy ok?
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you all for suggestions. I went for the 10th time through entire configuration and all was set correctly... except that I put test user in a wrong AD group 😛
This is why it's requests didn't match any of configured network policies 😉
