Got it

After enable MAC address-prioritized Portal authentication, some user cannot reconnect after lock and unlock screen.

Latest reply: Mar 24, 2020 13:36:16 2130 12 8 0 0

Hi all,

This is a case about portal authentication.

[Issue Description]

After enabling MAC address-prioritized Portal authentication, some users cannot reconnect after lock and unlock the screen.

[Analyze]

The root cause is that the SSID tpmpad that uses MAC address authentication is configured on the AC with local database. After the terminal is connected to this SSID, the terminal will remember it. After the terminal is locked and unlocked, the terminal connects to this SSID. But if the terminal does not have a local account, the authentication fails. After the authentication fails, the terminal will be silent for 60 seconds. In this case, the terminal cannot perform MAC address-prioritized Portal authentication.

[AC6605]dis mac-authen 

  MAC address authentication is Enabled.

  Username format: use MAC address without-hyphen as username

  Quiet period is 60s

  Authentication fail times before quiet is 1

  Offline detect period is 300s

  Server response timeout value is 120s

  Reauthenticate period is 1800s

  Guest user reauthenticate period is 60s

  Maximum users: 10240

  Current users: 0

//The global domain is not configured

#
interface Wlan-Ess10
port hybrid pvid vlan 10
port hybrid untagged vlan 10
mac-authen
permit-domain name test
force-domain name test
mac-authen username macaddress format with-hyphen password cipher %@%@_MK_U"UQ|S{:|5#m4M-QSjmJ%@%@
#
[AC6605]display  aaa  online-fail-record  mac-address xxxx-xxxx-xxxx
  ------------------------------------------------------------------------------
  Are you sure to display some information?(y/n)[y]:y
  ------------------------------------------------------------------------------
  User name               : xxxx-xxxx-xxxx
  Domain name             : test
  User MAC                : xxxx-xxxx-xxxx
  User access type        : MAC
  User access interface   : Wlan-Dbss10:190
  Qinq vlan/User vlan     : 0/10
  User IP address         : -
  User ID                 : 3191
  User login time         : 2018/10/10 10:48:09
  User online fail reason : Authenticate fail
  Authen reply message    : -

[Solution]
1. Other devices connect to SSID Test is not allowed, hide this SSID, so other device cannot search and connect to it. 
[AC6605-wlan-service-set-Test]dis this
#
  forward-mode tunnel
  wlan-ess 221
  ssid Test
  ssid-hide
#

2. For the devices that have ever connected to it, delete the SSID on the device. 

Thanks for the share
View more
  • x
  • convention:

Good case
View more
  • x
  • convention:

12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.