• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

RADIUS to MS NPS/AD - CHAP/PAP failures

Scheduled Pinned Locked Moved General pfSense Questions
2 Posts 2 Posters 581 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bascom_joshg
    last edited by Feb 4, 2022, 4:53 PM

    Hello all,

    I am attempting to use our NPS server to authenticate RADIUS requests for user auth for OpenVPN. I have NPS configured on our internal AD DS server, with the pfSense box setup as a client. I have allowed PAP, MS-CHAP, and MS-CHAPv2. All of my NPS settings should be correct.

    When I attempt to connect via OVPN, or when I run an authentication test in Diagnostics, I am getting the following error: "No User or Chap Password attributes given"

    I have attempted the tests with both PAP and CHAPv2 methods in the Authentication Servers settings in pfSense, and neither seems to make a difference. Am I missing something simple here? This is my first pfSense spin-up, so I'm still trying to learn it.

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Feb 4, 2022, 9:28 PM

      Can we assume you have followed this doc?
      https://docs.netgate.com/pfsense/en/latest/recipes/radius-windows.html

      Is there anything logged in pfSense or on the server when you try to authenticate?

      That error sounds like there is simply some config missing, is that returned on the Diag > Auth page?

      Steve

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received