Skip to main content

Posts

Featured

How to set Proxy settings for Microsoft Network Policy Server (NPS) Radius for Azure / Entra AD MFA

 I just worked on a fun one. My customer is spinning up a Microsoft NPS server to proxy authentication requests from Radius to Azure Entra Active Directory.  The problem was, when they tested the radius connection, it would never reply. We took a network trace, and sure enough, it never replied.  Here's what that looked like in Wireshark. Why though?  The next step that's supposed to happen after the radius request is received is the ping out to Entra AD.  Here's what that looked like in the trace, overlaid with the radius request. That's a problem.  In packet 129 the NPS server makes the initial TCP connection to login.microsoftonline.com.  That's SYN/ACKnowledged in packet 130, and the ACK in packet 131 finishes the three-way TCP handshake successfully.  Then in packet 131, the NPS server sends the TLS Client Hello message.  That packet is never acknowledged, so the NPS server retransmits it several more times (the packets in black and red.) This pattern of succe

Latest Posts

Quickie: How do I assign a drive letter to my OneDrive folder that persists after reboot?

Quickie: What network ports are listening on my machine in PowerShell?

Why aren't my Domain Controllers Global Catalogs?

Quickie: What update do I need to be able to install patch a Server 2012 r2 RTM machine?

Why did my box reboot? Getting Reboot information from the System and SCCM Reboot Coordinator logs

Fixed: Removing the "Edit with Acrobat" Ad in Edge's PDF Viewer.

Fixed: SCOM "No Device Ping" on network discovery

Fixed: Diagnosing a failing power supply

Weekend Report: Arduino + Multiple DS1820 Temperature Sensors Working

3D printed Liquid Piston Stirling Engine Cont'd: Minutiae research

3d Printed Liquid Piston Stirling Engine V4 reattempt and success!

LPSE v4 failure during assembly, and an adventure in O-rings.

LPSE v3 Two steps forward, one step back.

Thing I made: 3-D Printed Liquid Piston Stirling Engine Demonstrator v2

Thing I made: Toilet Flush Handle

So that's where they go? Where to attach the PSU Locks on a Prusa original enclosure

Feet Pics

Thing I made: Ryobi-compatible cordless TS100 soldering iron power adapter

Appcompat: 0x8007000B Bad Image Format - The format of DLL or executable being loaded is invalid

Breath holding record 4:02

Quickie: Powershell Base64 and Base64URL encoding and decoding functions

Fixed: Waiting for the .Net 4.8 installer to finish before continuing

Fixed: Resizing an ext4 filesystem and fixing a no-boot issue

Gotchas with Palo Alto Firewall App-IDs for Active Directory LDAPs and Windows KMS activation

Quickie: Connect to the WSUS "Windows Internal Database" with SQL Management Studio

A performant way to work with obtusely large files in PowerShell #Quickie #PowerShell

Making a point

$6 flexible print bed for Monoprice Select Mini