<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X EAP-TLS authentication fails on second Canon iR-ADV C3730 – only working with MAC Bypass in Production Printing</title>
    <link>https://community.usa.canon.com/t5/Production-Printing/802-1X-EAP-TLS-authentication-fails-on-second-Canon-iR-ADV-C3730/m-p/553925#M2704</link>
    <description>&lt;P&gt;Thanks for joining the conversation, stefanlog!&lt;BR /&gt;&lt;BR /&gt;While our forum community members are welcome to chime in, Canon does not provide direct support for imageRUNNER series products. Instead, your dealer will be able to help you! If you don't have a dealer and you're in the United States, please call us at 1-800-OK-CANON (1-800-652-2666) and we will be happy to provide you with the names of dealers in your area.&lt;BR /&gt;&lt;BR /&gt;If you're outside the USA, visit &lt;A href="http://global.canon" target="_blank" rel="noopener"&gt;http://global.canon&lt;/A&gt; and choose your country or region from the map for local support.&lt;BR /&gt;&lt;BR /&gt;We hope this helps!&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2025 12:37:25 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2025-06-18T12:37:25Z</dc:date>
    <item>
      <title>802.1X EAP-TLS authentication fails on second Canon iR-ADV C3730 – only working with MAC Bypass</title>
      <link>https://community.usa.canon.com/t5/Production-Printing/802-1X-EAP-TLS-authentication-fails-on-second-Canon-iR-ADV-C3730/m-p/553912#M2703</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we're currently rolling out 802.1X authentication in our environment using EAP-TLS with NPS (Windows Server) and Meraki switches.&lt;/P&gt;&lt;P&gt;We have two identical Canon iR-ADV C3730 devices. Both are configured identically with:&lt;/P&gt;&lt;P&gt;- 802.1X enabled&lt;BR /&gt;- "Use TLS" set to On&lt;BR /&gt;- A valid client certificate selected (including SAN with UPN)&lt;BR /&gt;- Login Name:&amp;nbsp;printername@domain.local (and others like MAC)&lt;BR /&gt;- PEAP, TTLS, MSCHAPv2: disabled&lt;BR /&gt;&lt;SPAN&gt;- Certificate chain trusted (CA is known and valid)&lt;BR /&gt;&lt;/SPAN&gt;- Firmware is up to date (as far as we can tell)&lt;/P&gt;&lt;P&gt;Now the issue:&lt;/P&gt;&lt;P&gt;-&amp;gt; Printer A authenticates successfully with MAC bypass (Meraki sends MAC address as username).&lt;/P&gt;&lt;P&gt;-&amp;gt; Printer B, with the same MAC-based configuration, fails.&lt;/P&gt;&lt;P&gt;In the Windows Event Log on the NPS server, we get:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Security ID: NULL SID Failure Reason: Unknown user name or bad password Status: 0xC000006D SubStatus: 0xC000006A&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This typically means the account name could not be resolved in Active Directory. However:&lt;/P&gt;&lt;P&gt;- The AD account with MAC-adress (74bfc0de5fa0) exists&lt;BR /&gt;- Password is correct and set to never expire&lt;BR /&gt;- Account is enabled&lt;BR /&gt;- Account name matches the MAC format exactly&lt;BR /&gt;- UserPrincipalName and altSecurityIdentities are configured&lt;/P&gt;&lt;P&gt;On the Meraki switch, we see:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;802.1X client timeout&lt;/FONT&gt;&lt;BR /&gt;Indicating that the printer does not respond to EAPOL packets when MAC bypass is disabled.&lt;/P&gt;&lt;P&gt;What we’ve tried so far:&lt;BR /&gt;- Swapped switch ports – the issue follows the printer, not the port&lt;BR /&gt;- Re-created the certificate&lt;BR /&gt;- Restarted the printer after reconfiguring 802.1X&lt;BR /&gt;- Compared all 802.1X settings between both printers – they are identical&lt;BR /&gt;- Verified NPS policy (PAP allowed for MAC-based fallback, EAP-TLS otherwise)&lt;BR /&gt;- Checked AD replication and DNS – all fine&lt;/P&gt;&lt;P&gt;Questions:&lt;BR /&gt;Is there a known issue with 802.1X EAP-TLS on Canon iR-ADV C3730, where the supplicant sometimes doesn't initialize properly?&lt;/P&gt;&lt;P&gt;Is there a debug mode or log within the printer UI or service menu that shows 802.1X authentication status?&lt;/P&gt;&lt;P&gt;Are there firmware builds that improve 802.1X reliability?&lt;/P&gt;&lt;P&gt;Any help would be appreciated – it's extremely frustrating that one device works and the other doesn’t, even though they’re configured the same.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 06:45:45 GMT</pubDate>
      <guid>https://community.usa.canon.com/t5/Production-Printing/802-1X-EAP-TLS-authentication-fails-on-second-Canon-iR-ADV-C3730/m-p/553912#M2703</guid>
      <dc:creator>stefanlog</dc:creator>
      <dc:date>2025-06-18T06:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS authentication fails on second Canon iR-ADV C3730 – only working with MAC Bypass</title>
      <link>https://community.usa.canon.com/t5/Production-Printing/802-1X-EAP-TLS-authentication-fails-on-second-Canon-iR-ADV-C3730/m-p/553925#M2704</link>
      <description>&lt;P&gt;Thanks for joining the conversation, stefanlog!&lt;BR /&gt;&lt;BR /&gt;While our forum community members are welcome to chime in, Canon does not provide direct support for imageRUNNER series products. Instead, your dealer will be able to help you! If you don't have a dealer and you're in the United States, please call us at 1-800-OK-CANON (1-800-652-2666) and we will be happy to provide you with the names of dealers in your area.&lt;BR /&gt;&lt;BR /&gt;If you're outside the USA, visit &lt;A href="http://global.canon" target="_blank" rel="noopener"&gt;http://global.canon&lt;/A&gt; and choose your country or region from the map for local support.&lt;BR /&gt;&lt;BR /&gt;We hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 12:37:25 GMT</pubDate>
      <guid>https://community.usa.canon.com/t5/Production-Printing/802-1X-EAP-TLS-authentication-fails-on-second-Canon-iR-ADV-C3730/m-p/553925#M2704</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-06-18T12:37:25Z</dc:date>
    </item>
  </channel>
</rss>

