u/mohhsen1992

▲ 4 r/ArubaNetworks+1 crossposts

FortiOS update 7.4.11 to 7.4.12 crashed Clearpass EAP-PEAP / MS-CHAPV2 Auth

Hi,

we recently updated our FortiGate to 7.4.12 and directly afterwards the username+password authentication through Clearpass Radius Authentication stopped working:

MSCHAP: AD status:{Access Denied} A process has requested access to an object but has not been granted those access rights. (0xc0000022)
MSCHAP: Authentication failed
EAP-MSCHAPv2: User authentication or password change failed

The EAP-TLS Authentication from domain joined clients and mdm smartphones still work perfectly.

Right before the update everything worked fine with the username+password authentication.

Anyone has an idea what can be the problem here?

Best regards

reddit.com
u/mohhsen1992 — 10 days ago

Hi,

we have a FortiGate 600E with FortiOS 7.4.11 and FortiAPs (e.g. 431G) with 7.4.7.

Our clients disconnecting frequently. People are having meetings in the same room for 2-3 hours and they have ~ 10 disconnects.

We are using 802.1x radius authentication on our SSID.

---SSID-----
name : SSID-Name

fast-roaming : enable

external-fast-roaming: disable

atf-weight : 20

max-clients : 0

ssid : SSID-Name

broadcast-ssid : enable

security : wpa2-only-enterprise

pmf : disable

okc : enable

mbo : disable

80211k : enable

80211v : enable

neighbor-report-dual-band: disable

fast-bss-transition : disable

eapol-key-retries : enable

mac-username-delimiter: hyphen

mac-password-delimiter: hyphen

mac-calling-station-delimiter: hyphen

mac-called-station-delimiter: hyphen

mac-case : uppercase

radius-mac-auth : disable

auth : radius

encrypt : AES

akm24-only : disable

radius-server : RADIUS-Server1

nas-filter-rule : disable

local-standalone : disable

local-bridging : enable

captive-portal : disable

intra-vap-privacy : disable

schedule : "always"

ldpc : rxtx

high-efficiency : enable

target-wake-time : enable

port-macauth : disable

bss-color-partial : enable

nac : disable

vlanid : 0

dynamic-vlan : enable

multicast-rate : 0

multicast-enhance : disable

igmp-snooping : disable

dhcp-address-enforcement: disable

broadcast-suppression: dhcp-up dhcp-ucast arp-known

ipv6-rules : drop-icmp6ra drop-icmp6rs drop-llmnr6 drop-icmp6mld2 drop-dhcp6s drop-dhcp6c ndp-proxy drop-ns-dad

me-disable-thresh : 32

mu-mimo : enable

probe-resp-suppression: disable

radio-sensitivity : disable

vlan-name:

dhcp-option43-insertion: enable

dhcp-option82-insertion: disable

ptk-rekey : disable

gtk-rekey : disable

eap-reauth : disable

roaming-acct-interim-update: disable

qos-profile :

hotspot20-profile :

access-control-list :

primary-wag-profile :

secondary-wag-profile:

rates-11a : 12-basic 18 24-basic 36 48 54

rates-11bg : 12-basic 18 24-basic 36 48 54

rates-11n-ss12 :

rates-11n-ss34 :

rates-11ac-mcs-map :

rates-11ax-mcs-map :

rates-11be-mcs-map :

rates-11be-mcs-map-160:

rates-11be-mcs-map-320:

utm-status : disable

address-group-policy: disable

sticky-client-remove: disable

bstm-rssi-disassoc-timer: 200

bstm-load-balancing-disassoc-timer: 10

bstm-disassociation-imminent: enable

beacon-advertising :

application-detection-engine: disable

l3-roaming : disable

---AP-Profile----

name : FAP_431G_STD

comment :

platform:

type : 431G

mode : single-5G

ddscan : enable

control-message-offload: ebp-frame aeroscout-tag ap-list sta-list sta-cap-list stats aeroscout-mu sta-health spectral-analysis

bonjour-profile :

apcfg-profile :

ble-profile :

syslog-profile :

wan-port-mode : wan-only

lan:

port-esl-mode : offline

energy-efficient-ethernet: disable

led-state : enable

led-schedules :

dtls-policy : clear-text

max-clients : 0

handoff-rssi : 25

handoff-sta-thresh : 55

handoff-roaming : enable

deny-mac-list:

ap-country : --

ip-fragment-preventing: tcp-mss-adjust

tun-mtu-uplink : 0

tun-mtu-downlink : 0

split-tunneling-acl-path: local

split-tunneling-acl-local-ap-subnet: disable

split-tunneling-acl:

allowaccess : ssh

login-passwd-change : yes

login-passwd : *

lldp : enable

poe-mode : auto

usb-port : enable

frequency-handoff : disable

ap-handoff : disable

radio-1:

mode : ap

band : 802.11n-2G 802.11ax-2G

drma : disable

drma-sensitivity : low

airtime-fairness : disable

powersave-optimize :

amsdu : enable

coexistence : enable

bss-color-mode : auto

short-guard-interval: disable

mimo-mode : default

channel-bonding : 20MHz

auto-power-level : enable

auto-power-high : 10

auto-power-low : 6

auto-power-target : -70

dtim : 1

beacon-interval : 100

80211d : enable

rts-threshold : 2346

channel-utilization : enable

darrp : enable

arrp-profile : arrp-default

max-clients : 0

max-distance : 0

vap-all : manual

vaps : SSIDs

channel : "1" "6" "11"

call-admission-control: disable

radio-2:

mode : ap

band : 802.11n-5G 802.11ac-5G 802.11ax-5G

drma : disable

drma-sensitivity : low

airtime-fairness : disable

powersave-optimize :

amsdu : enable

coexistence : enable

bss-color-mode : auto

short-guard-interval: disable

mimo-mode : default

channel-bonding : 20MHz

auto-power-level : enable

auto-power-high : 14

auto-power-low : 8

auto-power-target : -70

dtim : 1

beacon-interval : 100

80211d : enable

rts-threshold : 2346

channel-utilization : enable

darrp : enable

arrp-profile : arrp-default

max-clients : 0

max-distance : 0

vap-all : manual

vaps : SSIDs

channel : "36" "40" "44" "48" "52" "56" "60" "64" "100" "104" "108" "112" "116" "120" "124" "128" "132" "136" "140"

call-admission-control: disable

radio-3:

mode : monitor

drma : disable

drma-sensitivity : low

channel-utilization : enable

wids-profile : WIDS-Profile

lbs:

ekahau-blink-mode : disable

aeroscout : disable

fortipresence : disable

station-locate : disable

ble-rtls : none

ext-info-enable : enable

indoor-outdoor-deployment: platform-determined

esl-ses-dongle:

compliance-level : compliance-level-2

scd-enable : disable

esl-channel : 127

output-power : a

apc-addr-type : fqdn

apc-fqdn :

apc-port : 0

coex-level : none

tls-cert-verification: enable

tls-fqdn-verification: disable

console-login : enable

wan-port-auth : none

----

Someone has an explanation for me?

reddit.com
u/mohhsen1992 — 4 months ago