Event Id | 26 |
Source | HRA |
Description | The Health Registration Authority was unable to validate the request with the Correlation ID %1 at IP address %2 (Principal: %3). The Network Policy Server denied the request (%4). See the Network Policy Server administrator for more information. |
Event Information | According to Microsoft : Resolve Install or enable NPS This error condition indicates that the NPS service is unavailable. Check that NPS is running and is not disabled, and make sure the NPS server role is installed correctly.If NPS on the local computer is configured as a RADIUS proxy, then confirm connectivity to the NAP health policy server in a remote RADIUS server group. To perform this procedure, you must be a member of the Administrators group or must have been delegated the appropriate authority.
This error condition indicates that the local NPS is not configured as a RADIUS proxy to forward client health credentials to the NAP health policy server for evaluation. Perform the following procedures to configure the local computer as a RADIUS proxy. These procedures apply if the NPS service on the local computer will forward connection requests to a remote NAP health policy server for evaluation.You should also confirm that the NAP health policy server added to remote RADIUS server groups in the first procedure is configured to evaluate NAP client heath status and has a corresponding RADIUS client entry to receive connection requests forwarded by the local computer. To determine if the RADIUS client entries are correct on remote RADIUS servers, see the section titled "Configure the NAP health policy server." To perform this procedure,must be a member of the Administrators group or must have been delegated the appropriate authority. Configuring a RADIUS proxy To configure remote RADIUS server groups:
Configure the NAP health policy server This error condition indicates that configuration of the NAP health policy server is not correct for the NAP IPsec enforcement method. To configure NPS on the local computer as a NAP health policy server,must configure the following policies and settings:
These procedures apply only if health policies configured in NPS on the local computer will be used to evaluate the health status of NAP client computers. If you have previously configured the server running NPS as a NAP health policy server, then use the following procedures to confirm the settings. To perform this procedure,must be a member of the Administrators group or must have been delegated the appropriate authority.
To configure RADIUS clients: The configuration of RADIUS clients is optional.If your NAP health policy server recieves requests from other HRAs that are running NPS in a RADIUS proxy configuration and will forward authentication requests to the local server, you must configure NPS on the local computer to evaluate these requests and return the results of this evaluation to other HRA servers.Use the following procedure to configure the local computer to process requests recieved from remote HRA servers.
HRA runs an IIS worker process, w3wp.exe, that works with NPS to issue health certificates when a NAP client initiates a connection. If the process is idle for several minutes, the process ends until it is called again. This error condition indicates that the NPS service has become unavailable while w3wp.exe is running, possibly due to a temporary loss of network connectivity or a restarting of the NPS service.Can wait for the w3wp.exe process to end or can end the current process, forcing a new w3wp.exe process to start. To perform this procedure,must be a member of the Administrators group or must have been delegated the appropriate authority. To end the w3wp.exe process:
|
Reference Links | Event ID 26 from HRA |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.