Article ID: 956923 - Last Review: November 11, 2008 - Revision: 1.0 FIX: A VPN client that uses RADIUS authentication may not log on to the internal network when the User Mapping option is enabled in ISA Server 2006
SYMPTOMSConsider the following scenario:
Note The User Mapping option is used to map VPN clients from non-Windows namespaces, such as RADIUS or Extensible Authentication Protocol (EAP) authenticated users, to the Windows namespace. CAUSEThis problem occurs because ISA Server 2006 does not recognize that the RADIUS user name is a UPN name format and incorrectly adds the domain name in front of the user name. When the computer that is running ISA Server tries to perform the User Mapping later, it cannot find the user because the user name format is invalid. RESOLUTIONTo resolve this problem, apply the hotfix that is mentioned in the following Microsoft Knowledge Base article: 956925
(http://support.microsoft.com/kb/956925/
)
Description of the ISA Server 2006 hotfix package: August 20, 2008
WORKAROUNDTo work around this problem, the VPN users can specify their credentials in a Security Accounts Manager (SAM) name format (DomainName\UserName). This will allow ISA Server to appropriately parse the credentials and perform the user mapping. STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATIONFor more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base: 824684
(http://support.microsoft.com/kb/824684/
)
Description of the standard terminology that is used to describe Microsoft software updates | Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
