802.1x, XP Sp3 and Broadcom = windows logon delay


i know there several posts regarding 1200 second delay far can tell there's no real work around. want share our current setup see if has similar, and/or see if has found registry key or other switch option work around problem?

our current problem seems resolve around the broadcom 57xx drivers not sending credentials when first boots disabling 20 minutes. i've attempted contact broadcom told work thru vendor, , dell states broadcom issue. cisco mentions there ms hotfix unable locate , has assured me post bug notice it. 

all machines having issues windows xp sp3 installed , on active directory domain. switches @ least cisco 3550 series or 3560 series switches. we're using ms ias radius authentication of 802.1x clients , happens on our wired clients.

our client side configuration under authentication tab:

ms peap
do not validate server certificate
mschap v2
automatically use windows logon name

we've tried following things no avail far:
1. install latest 57xx driver broadcom
2. unjoin computer ad/domain, regenerate it's sid rejoin; thinking duplicate sid issue.
3. reordered startup order dot3svc make sure starts before netlogon service.

here entry event viewer of afflicted xp machine:

event type: information
event source: dot3svc
event category: none
event id: 15506
date:  12/8/2008
time:  9:19:32 am
user:  n/a
computer: ub900_helpdesk
description:
network authentication attempts have been temporarily suspended on network adapter.
 
 network adapter: broadcom netxtreme 57xx gigabit controller - packet scheduler miniport
 interface guid: 9219d220-ec6f-4380-8cdd-ea711fa843bf
 reason code: 327685
 length of block timer (seconds): 1200


more information, see , support center @ http://go.microsoft.com/fwlink/events.asp.

here our standard cisco switch config:
aaa authentication dot1x default group radius 
aaa authorization network default group radius 

dot1x system-auth-control 
dot1x guest-vlan supplicant 


interface fastethernet0/1 
description ub912g_1 
switchport access vlan 225 
switchport mode access 
switchport voice vlan 100 
switchport port-security aging time 2 
switchport port-security violation restrict 
switchport port-security aging type inactivity 
srr-queue bandwidth share 10 20 40 80 
srr-queue bandwidth shape 0 0 0 0 
auto qos voip cisco-phone 
dot1x pae authenticator 
dot1x port-control auto 
dot1x violation-mode protect 
dot1x timeout reauth-period 300 
storm-control broadcast level 50.00 25.00 
storm-control multicast level 50.00 25.00 
macro description cisco-phone 
spanning-tree portfast 
spanning-tree bpduguard enable 

ricky li
network engineer 
hawaii pacific university

how did this?
  reordered startup order dot3svc make sure starts before netlogon service.

have tried wait until networking administrative template see if delay login until it's ready?

derek


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file