Monday, 2013-09-16

*** goutam (7c1ec732@gateway/web/freenode/ip.124.30.199.50) has joined #wikid08:01
goutamhi there08:01
goutamis there any one here?08:01
*** JasonRorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid11:58
JasonRorieI have setup WiKID. I set it up to authenticate directly to the WiKID server, and now am authenticating through NPS. I can connect just fine, but when I go to access network file shares it almost acts like it is holding my WiKID password as my network password. It never connects on a Mac or a domain Windows 7 machine. I got it to bounce back on a Windows 7 workgroup machine asking for username and password, but that is the only mach12:15
JasonRorieAny advice?12:15
*** JasonRorie has quit (Ping timeout: 250 seconds)12:22
*** jasonrorie (4b96d87d@gateway/web/freenode/ip.75.150.216.125) has joined #wikid12:36
*** nowen (~nowen@99-174-93-102.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:06
jasonrorieOkay. My problem is Windows authentication. I can connect directly to my NPS server and get to all of the network shares. If I have it hand off my authentication to the WiKID server, I cannot connect to the file shares. It is almost like it is retaining that login information that is within the VPN login for Windows authentication.13:13
jasonrorieOkay. My problem is Windows authentication. I can connect directly to my NPS server and get to all of the network shares. If I have it hand off my authentication to the WiKID server, I cannot connect to the file shares. It is almost like it is retaining that login information that is within the VPN login for Windows authentication.13:20
nowenmorning13:20
nowenjust saw your email13:20
jasonrorieMorning.13:21
nowenso, you can get a VPN connection via NPS and WiKID, but when you try to mount an SMB drive, no go?13:21
jasonrorieCorrect. Same result as when connecting directly to the WiKID server13:22
nowenWhat is the event viewer telling you?13:22
jasonrorieOn what?13:23
nowenwindows event viewer - are there any logs saying why you're not able to mount them?13:24
jasonrorieNot that I can see. If I connect directly to the NPS, without using WiKID, I can connect to the drives fine.13:25
nowenany errors in the WiKID logs?13:25
jasonrorieNo, it says it is successfully authenticated.13:26
jasonrorieSame on the NPS server.13:26
nowenand you're sure that is part of the SMB login?13:26
jasonrorieSure that what is part of the SMB login. It never prompts me for a new username or password for the SMB with the VPN going with WiKID. If I connect in office, it prompts for username and password.13:29
jasonrorieIt is like it is using my VPN login information to connect to the network shares.13:30
jasonrorieI tried setting Remote-RADIUS-to-Windows-User-Mapping to True, but it won't connect at all like that.13:31
nowenand you want it to use AD Creds13:31
jasonrorieI think that is what needs to be set.13:31
jasonrorieI turn that on, and it says it authenticates fine on the NPS and WiKID server, but the firewall kicks back and says CHAP authentication failed.13:32
*** goutam has quit (Quit: Page closed)13:33
nowenjasonrorie: can you access other resources over the vpn? is it just smb?13:40
*** jasonrorie has quit (Ping timeout: 250 seconds)13:43
*** jasonrorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid13:48
jasonrorieSorry, dropped off. I can ping the devices, just cannot SMB. It look like an authentication failure to the network share to me.13:48
nowenwhat firewall are you using?13:49
jasonrorieWatchguard13:49
jasonrorieIs there something that I need to setup on there for the Radius to Windows to work?13:50
nowennot sure13:50
nowenare you doing pptp, ssl, ipsec?13:51
jasonroriePPTP13:51
nowenwhat version of watchguard?13:52
jasonrorieXTM 50513:53
nowenwhat makes it look like an authentication error?14:01
nowencan you see the shared directories but not access them?14:06
jasonrorieI cannot access them. It never prompts for username and password, almost like it is trying to use the one from the VPN logon.14:24
nowendoes it return some error?14:24
nowenhttp://social.technet.microsoft.com/Forums/windowsserver/en-US/235f5d83-bd6f-475e-a63e-db9a037fa18a/file-sharing-problem-through-vpn14:29
nowenI'm wondering if the smb is looking for user@domainname14:29
jasonrorieThat is what I'm thinking is happening.14:38
nowenI feel like there should be an option to strip the domain part before sending the creds to wikid14:39
nowenbrb14:41
jasonrorie2013-09-16 10:40:34.670INFOcom.wikidsystems.radius.access.WikidAccess4Access granted for jrorie, domain code: 075150216125 client: /192.168.111.4  2013-09-16 10:40:34.670INFOcom.wikidsystems.radius.log.DBSvrLogImpl<2> Access-Accept(2) LEN=162 192.168.111.4:50191 Access-Request by jrorie succeeded14:42
jasonrorie2013-09-16 10:40:34.670INFOcom.wikidsystems.radius.access.WikidAccess4Access granted for jrorie, domain code: 075150216125 client: /192.168.111.4  2013-09-16 10:40:34.670INFOcom.wikidsystems.radius.log.DBSvrLogImpl<2> Access-Accept(2) LEN=162 192.168.111.4:50191 Access-Request by jrorie succeeded14:42
jasonrorie2013-09-16 09:38:18 admd Authentication of PPTP user [jrorie@RADIUS] from 12.110.224.2 accepted id="1100-0004" Event 2013-09-16 09:38:18 pptp auth: wgapi: rcved cmd=1 '/toAdmdClient/authResult'   Debug 2013-09-16 09:38:18 pptp get into test_auth_prcs_status(): xpath=/toAdmdClient/authResult    Debug 2013-09-16 09:38:18 pptp rcved auth reply: authResult=1   Debug 2013-09-16 09:38:18 pptp ---------<<<RESULT rcvd, [jrorie@RADIUS] A14:43
jasonrorie2013-09-16 09:38:18 pppd Peer ENVOY\\jrorie failed CHAP authentication  Debug 2013-09-16 09:38:18 pppd sent [CHAP Failure id=0x58 "E=691 R=1 C=e26e80c483c6281d88dbaf5240278699 V=0 M=Access denied"]  Debug 2013-09-16 09:38:18 pppd sent [LCP TermReq id=0x5 "Authentication failed"]  Debug 2013-09-16 09:38:18 pppd rcvd [LCP TermAck id=0x5 "Authentication failed"]  Debug 2013-09-16 09:38:18 pppd Connection terminated.  Debug14:43
jasonrorieWhen I enable radius to windows authentication, this is what happens. I have a feeling if I could get that to work, that it would put the domain information in there.14:44
jasonrorieIf I authenticate directly to the NPS server, it works fine.14:50
*** jasonrorie has quit (Ping timeout: 250 seconds)14:55
*** JasonRorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid14:56
JasonRorieSorry. Dropped off again.14:59
nowennp14:59
nowenare your usernames in wikid sans domain?14:59
nowenie, jrorie?14:59
*** JasonRorie_ (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid15:01
JasonRorie_Yes, they are the same username.15:01
nowenI wonder if you added a user to wikid that was username@domainname.com if it would work?15:01
*** JasonRorie has quit (Ping timeout: 250 seconds)15:03
*** JasonRorie_ has quit (Ping timeout: 250 seconds)15:09
*** JasonRorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid15:13
nowenrealm stripping; http://technet.microsoft.com/en-us/library/cc731342%28v=ws.10%29.aspx15:13
nowen I wonder if you added a user to wikid that was username@domainname.com if it would work?15:13
JasonRorieIt lets me connect with that, still no dice on connecting to the server shares though.15:13
JasonRorieWhat does the Remote-RADIUS0to-Windows-User-Mapping do?15:17
nowenI thought it told nps to proxy to the radius server15:20
nowendo you have   "Request must contain the message authenticator attribute" on?15:20
JasonRorieI do. I can't get it to connect at all with the Remote-Radius-to-Windows_User-Mapping on though.15:23
nowenhmm, because I once got an email from a customer saying that was what got it working for them15:29
*** JasonRorie has quit (Ping timeout: 250 seconds)15:40
*** JasonRorie (0c6ee002@gateway/web/freenode/ip.12.110.224.2) has joined #wikid18:02
JasonRorieHey Nick. It turns out for some reason the Radius users got removed from my radius group on the firewall. I am not sure how I was navigating the network at all, at that point. I added the users back and everything looks good now.18:04
nowengreat!18:05
nowenso, SMB is working?18:05
JasonRorieYes, it is.18:05
nowencan  you tell me your settings - is the radius mapping set to true?18:05
JasonRorieI am not sure why pings were working even.18:05
JasonRorieRadius Mapping is not set at all.18:05
nowenwow, I just can't figure out nps.  I guess I need to spend more time with it18:06
JasonRorieI can forward you screens if you need them.18:06
nowenthat would be great!18:07
JasonRorieWill do.18:07
nowenthanks JasonRorie18:15
*** JasonRorie has quit (Quit: Page closed)18:23
*** nowen has quit (Quit: Leaving.)22:30

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!