
Reason: The RADIUS Request message that Network Policy Server received from the network access server was malformed.Ī malformed request you say, well OK I accept the challange! When I finally got it to work, I seen this event being logged: Authentication Details:Ĭonnection Request Policy Name: MY-WIFI-NETWORKĪuthentication Server: domain-controller.local I then seen that there were others on the Internet who had a bunch of NPS events in their Event Log while mine was pretty empty, so I spent a day trying to get the NPS Event Logging to work. Anyway my eyes got tired pretty fast looking at that stuff!

So I was there looking at the incredibly difficult to read Accounting Logs on the NPS server, but it appeared that the clients were completing the authentication just fine. I have this setup working perfectly fine behind Watchguards in other locations, so I’ve basically replicated the settings on the UniFI controller, but the clients refused to join the network for some reason. To give you a bit of background in this setup the domain joined wireless clients authenticate to the network using EAP-TLS against a NPS Radius server. Everything was pretty much fine, until we started converting wired computers to wireless in an effort to get rid of some obscure cabling.


As I previously wrote here, I’ve replaced one of the Watchguards with a UniFi AP and EdgerRouter X.
