Windows Netwok Policy Server as Radius

AdminSys
AdminSys Posts: 27  Freshman Member
First Comment Seventh Anniversary

We have a Flex 500 Zyxel firewall and a Windows 2019 Server on the system. The clients are remotely connecting to the network via L2TP VPN. We want to use the Windows Network Policy Server for Radius authentication on the firewall, but no matter what condition we specify in the NPS, in the Connection Request Policy, the error message is always the same:
Reason Code: 49
Reason: The RADIUS request did not match any configured connection request policy (CRP).

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,017  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @AdminSys ,

    This error indicates a mismatch between the RADIUS requests sent by the firewall and the policies defined on your Windows 2019 NPS server. Please follow the steps to troubleshoot:

    • Verify the USG FLEX 500 is defined as a RADIUS client in NPS by confirming the shared secret matches between client and server, and checking IP address configuration is correct.
    • Ensure your NPS policies are configured to accept RADIUS requests from your Zyxel Flex 500.
    • Confirm that the user account attempting to connect is a member of the Windows groups specified in the NPS policy's conditions.
    • Confirm that the RADIUS attributes sent by the Flex 500 match the attributes expected by the NPS server. Any discrepancies can cause a policy mismatch.
    • Verify that the authentication method configured on the Flex 500 for L2TP VPN clients matches the authentication methods allowed by your NPS policies.