Skip to main content
dalon
Staff
Staff
February 28, 2017

Technical Note: Radius reject with message 'MS-CHAP-Error: \000E=691 R=0 V=3'

  • February 28, 2017
  • 1 reply
  • 21656 views
Description
This article provides an explanation and workaround for "MS-CHAP-Error(2): \000E=691 R=0 V=3" message, which can come in Access-Reject from Radius.

Sniffer    
2    0.001287    10.10.10.10    10.10.10.254    RADIUS    84
    Access-Reject(3) (id=5, l=42)
AVP: l=22  t=Vendor-Specific(26) v=Microsoft(311)
VSA: l=16 t=MS-CHAP-Error(2): \000E=691 R=0 V=3

Solution
Windows server 2008 might refuse NTLM connections because NTLMv1 is disabled by default.

Enable NTLMv1 in the server as follows:

Start > Administrative Tools > Local Security Policy > Local Policies > Security Options > Network security: LAN Manager authentication level entry > Send NTLM response only.

tn_FD40275-1.jpg

1 reply

dzbonski
Staff
Staff
September 21, 2023

In FortiOS 7.2.5 we received this message and the solution was to add the NAS IP to the NPS policy.

We used the info from MS to enable audit logs: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/troubleshoot-network-policy-server