It appears that it had been reset - instead of MSCHAPV1 it was listed as PAP. Saving it back to MSCHAPV1 and the error went away.
I am now having an issue where I am still being told "Invalid Login. Please try again."
Checking the log of the Windows Radius Server, it says that it granted access to the username.
Network Policy Server granted full access to a user because the host met the defined health policy.
User:
Security ID: TIS\nschirmer
Account Name: nschirmer
Account Domain: TIS
Fully Qualified Account Name: TIS\nschirmer
Client Machine:
Security ID: NULL SID
Account Name: -
Fully Qualified Account Name: -
OS-Version: -
Called Station Identifier: 192.168.1.1
Calling Station Identifier: 00:24:2c:7a:fc:7d
NAS:
NAS IPv4 Address: 192.168.1.1
NAS IPv6 Address: -
NAS Identifier: pfsense.campus.tisweb.net
NAS Port-Type: Ethernet
NAS Port: 5270
RADIUS Client:
Client Friendly Name: Firewall
Client IP Address: 192.168.1.1
Authentication Details:
Proxy Policy Name: Use Windows authentication for all users
Network Policy Name: Secure Wireless Connections
Authentication Provider: Windows
Authentication Server: china.campus.tisweb.net
Authentication Type: MS-CHAPv1
EAP Type: -
Account Session Identifier: -
Quarantine Information:
Result: Full Access
Extended-Result: -
Session Identifier: -
Help URL: -
System Health Validator Result(s): -
But in PFSense, I receive the following error in portalauth.log:
Sep 26 08:51:31 pfsense logportalauth6150: ERROR: nschirmer, 00:24:2c:7a:fc:7d, 192.168.1.100, Error sending request: No valid RADIUS responses received
So it appears that now I can connect to China (the radius server) to authenticate me (nschirmer) on PFSense (192.168.1.1) but PFSense isn't receiving the correct response.