Radius authentication in Splash page not working

KBLatColonial
Here to help

Radius authentication in Splash page not working

I have MR46 APs.  I'm trying to set up Radius Authentication in the Splash page.

 

I followed the steps in https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Configuring_RADIUS_Au...

but every time I test, it fails.

I usually get reason code 22,  The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.

 

or reason code 66, The user attempted to use an authentication method that is not enabled on the matching network policy.

 

I also get "A RADIUS message was received from the invalid RADIUS client IP address xxx.xxx.xxx.xxx." (IP obfuscated) Windows event id 13 messages

 

I'm pulling what little hair I have left out trying to figure this one out!

 

bottom line, why is this not working?

3 Replies 3
Brash
Kind of a big deal
Kind of a big deal

Sounds like misconfiguration on your RADIUS server. What RADIUS server are you using, and what does the config look like?

Brash
Kind of a big deal
Kind of a big deal

I just realized you posted a Windows event ID, so you're likely using Microsoft NPS.

The event indicates that the Meraki AP IP address isn't included in the RADIUS Clients config (to allow it to perform RADIUS requests).

Check to make sure your config matches the following guide

Configuring RADIUS Authentication with WPA2-Enterprise - Cisco Meraki

 

If you're still having issues, can you post a screenshot of your RADIUS Clients config, connection request policy and network policy?

Hi, 

thanks for the reply.   You're right, it's a Windows NPS server.   

You're right, it's almost certainly a misconfiguration of the Radius server.   where the errors are is the big question.

However, I'm implementing Radius through the Spash Page, not the WPA2 enterprise route.  

I will review that doc just to see if there are any clues there for why it's not working.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels