Got it

After enable MAC address-prioritized Portal authentication, some user cannot reconnect after lock and unlock screen.

Latest reply: Dec 20, 2021 13:57:51 589 7 6 0 1
The   root cause is that the SSID tpmpad that uses MAC address authentication is   configured on the AC with local database. After the terminal is connected to   this SSID, the terminal will remember it. After the terminal is locked and   unlocked, the terminal connects to this SSID. But if the terminal does not   have a local account, the authentication fails. After the authentication   fails, the terminal will be silent for 60 seconds. In this case, the terminal   cannot perform MAC address-prioritized Portal authentication.
    #
    interface Wlan-Ess100
    port hybrid pvid vlan 100
    port hybrid untagged vlan 100
    mac-authen
    permit-domain name test
    force-domain name test
    mac-authen username macaddress format with-hyphen password cipher   %@%@_MK_U"UQ|S{:|5#m4M-QSjmJ%@%@
    #
    [AC6605]dis mac-authen
   
 
MAC address authentication is   Enabled.
 
Username format: use MAC address   without-hyphen as username
 
Quiet period is 60s
 
Authentication fail times before   quiet is 1
 
Offline detect period is 300s
 
Server response timeout value is   120s
 
Reauthenticate period is   1800s
 
Guest user reauthenticate period is   60s
 
Maximum users: 10240
 
Current users: 0
 
Global domain is not   configured
   
    [AC6605]display
  aaa  online-fail-record 
mac-address xxxx-xxxx-xxxx
   
------------------------------------------------------------------------------
  User name              
: xxxxxxxxxxxx
  Domain name            
: test
  User MAC               
: xxxx-xxxx-xxxx
  User access type       
: MAC
  User access interface  
: Wlan-Dbss192:189
  Qinq vlan/User vlan    
: 0/192
  User IP address        
: -
  User ID                
: 4462
  User login time        
: 2018/10/10 10:48:10
 
User online fail reason :   Authenticate fail
  Authen reply message   
: -
   
------------------------------------------------------------------------------
   
    【Solution】
    1. Other device connect to SSID test is not allowed, hide this SSID, so   other device cannot search and connect to it.
    [AC6605-wlan-service-set-test]dis this
    #
   
 
forward-mode tunnel
 
wlan-ess 100
 
ssid test
 
traffic-profile id 1
 
security-profile id 3
 
service-vlan 100
 
ssid-hide
    #
    2. For the devices have ever connected to it, delete the SSID on the   device.
   
   
 
Are you sure to display some   information?(y/n)[y]:y
   
------------------------------------------------------------------------------
  User name              
: 0cd7-465c-d661
  Domain name            
: tpmpad
  User MAC               
: 0cd7-465c-d661
  User access type       
: MAC
  User access interface  
: Wlan-Dbss221:190
  Qinq vlan/User vlan    
: 0/221
  User IP address        
: -
  User ID                
: 3191
  User login time        
: 2018/10/10 10:48:09
 
User online fail reason :   Authenticate fail
  Authen reply message   
: -

configured on the AC with local database. After the terminal is connected to this SSID, the terminal will remember it. After the terminal is locked and unlocked, the terminal connects to this SSID. But if the terminal does not have a local account, the authentication fails. After the authentication fails, the terminal will be silent for 60 seconds. In this case, the terminal cannot perform MAC address-prioritized Portal authentication.
View more
  • x
  • convention:

Other device connect to SSID test is not allowed, hide this SSID, so other device cannot search and connect to it.
For the devices have ever connected to it, delete the SSID on the device.
good example .
View more
  • x
  • convention:

the SSID tpmpad that uses MAC address authentication is configured on the AC with local database. After the terminal is connected to this SSID, the terminal will remember it. After the terminal is locked and unlocked, the terminal connects to this SSID. But if the terminal does not have a local account, the authentication fails. After the authentication fails, the terminal will be silent for 60 seconds. In this case, the terminal cannot perform MAC address-prioritized Portal authentication.
View more
  • x
  • convention:

Access Authentication: 802.1X, Portal Authentication, MAC Address Authentication and Port Security 802.1X were proposed to solve the security problems of WLAN, and were widely used by Ethernet later.
View more
  • x
  • convention:

It is a good case showing us how to identify the cause when encounter the issues of portal authentication. Thank you very much but I would like to know more about the packets exchanging process of portal authentication , I believe that can help us better to understand how to solve such issues.
View more
  • x
  • convention:

The troubleshooting steps are very clear,Thanks for your sharing, I have been stuck for a long time on this problem. you gave me a very good idea ,I very much appreciate it.

Please keep on post and share more cases for all of us:)
View more
  • x
  • convention:

Good inputs all! It was helpful for me as well
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.