Configuring FreeRADIUS to use ntlm_auth for MS-CHAP

Alan DeKok aland at
Wed Apr 28 21:59:08 CEST 2010

Pedro Alves wrote:
> This is the test with AD user:
> AP#test aaa group radius userad userpass new-code  
> Trying to authenticate with Servergroup radius
> User rejected
> rad_recv: Access-Request packet from host xx.xx.xx.xx port 1645, id=175, length=52
>         User-Password = "userpass"
>         User-Name = "userad"
>         NAS-IP-Address = xx.xx.xx.xx

  So... you're not doing MS-CHAP.

  Why is this message useful?

  Again... the Active Directory howto you were pointed to *documents*
this.  Go read it and follow the steps.  If you don't follow the
documentation, you probably won't be able to solve the problem.

  Alan DeKok.

More information about the Freeradius-Users mailing list