Having an issue with Macbook authentication. All Macbooks at this one site, on same switch, going to same RADIUS server, work except for one. Looking at logs it appears server and client never exchange certificates. Attached is log for failed Macbook authentication. Any help is appreciated.
Do the other macbooks have a machine account in Active directory? If so then this machine doesnt exist in AD. It looks like the client to radius authentication is working, its the issue with ACS to AD not being able to find the machine account:
24433 Looking up machine/host in Active Directory - host/GVLMB009.internal.cigna.com
Thanks for the reply. All macbooks are in AD and have machine accounts. The host GVLMB009 had its certificate replaced. Do you think perhaps the AD machine account is corrupt or the shared secret between client and AD no good??
How are the certificates issue? It looks as if the for some reason this ACS is unable to find the machine account. What you can do to troubleshoot this issue is to go the Active Directory Settings then go to attributes, here it will ask you type in a username and you can use GVLMB009$ to see if acs is able to pull the attributes from AD for this account. That will get us started in the troubleshooting process.
Here is a screenshot that will explain what I mean.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...