Aruba Central Mac-Authentication 802.1x NPS Error 6273 reason code 66

CTN 1 Reputation point
2021-04-29T09:48:19.84+00:00

Hi all.
I have next problem. When i  try enable mac-address authentication with 802.1x via NPS, i receive next error.
Without mac-address authentication client authenticated  successfully.

Authentication Details:
Connection Request Policy Name: ARUBA - Secure Wireless Connections
Network Policy Name: Connections to other access servers
Authentication Provider: Windows
Authentication Server: BAK-RDS.Bakotech.local
Authentication Type: PAP
EAP Type: -
Account Session Identifier: -
Logging Results: Accounting information was written to the local log file.
Reason Code: 66
Reason: The user attempted to use an authentication method that is not enabled on the matching network policy.

My Central configuration 
wlan ssid-profile Miratec
enable
index 3
type employee
essid Miratech
utf8
opmode wpa2-aes
max-authentication-failures 0
vlan DenyAny
auth-server BAK-RDS.bakotech.local
set-vlan Aruba-User-Vlan equals 50 BKT
set-vlan Aruba-User-Vlan equals 60 FND
rf-band all
captive-portal disable
mac-authentication
mac-authentication-upper-case
dtim-period 1
broadcast-filter arp
g-min-tx-rate 12
a-min-tx-rate 18
dmo-channel-utilization-threshold 90
local-probe-req-thresh 0
max-clients-threshold 64
dot11r
strict-svp

NPS Server Configuration
For 802.1x 
92600-image.png

For mac-auth
92529-image.png

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,205 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Candy Luo 12,661 Reputation points Microsoft Vendor
    2021-04-30T02:51:13.243+00:00

    Hi,

    In your case, we need to collect network packet capture to find the cause. However, analysis of network traffic is beyond our forum support level and due to forum security policy, we have no such channel to collect user log information. So we recommend you open a case with MS Professional tech support service, they will help you open a phone or email case to Microsoft, so that you would get a technical support on a one-to-one basis while ensuring private information.

    Here is the link:

    https://support.microsoft.com/en-us/gp/customer-service-phone-numbers

    Best Regards,
    Candy

    --------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments