u/Manly009

Hi Guys,

I built a new Radius NPS server on Server 2025, imported the old config from the existing NPS server which is on the DC server. Registered the new NPS server via NPS service. Can see the Server object added to the security group "RAS and IAS Servers" on AD. Also updated the switch SSO to point to the new Radius. Can see Switch logs saying invalid Username Password. Tried New certificate and also weaker auth etc, none worked. Just Cannot SSO login to the switch....Once I change back the switch config to the old Radius server, it will work....

On DC server, if I run command "netsh ras show registeredserver" it only shows the old DC server registered, is the new Radius NPS server needed to be listed here as well? Should I run command to manually register new NPS server on AD server?

Thanks

John

reddit.com
u/Manly009 — 9 days ago