Got it

Authentication between AC and the RADIUS is denied by RADIUS server

Latest reply: Nov 17, 2021 08:40:02 619 4 3 0 0

Brief: 

We need to get the RADIUS authentication working on a new installation of an AC6005 controller with the APs. Looking at the logs, it does not seem to be sending out the request to the radius server. After some configuration we managed to get the packets to the RADIUS but they are denied.


Error: 

N/A RADIUS did not get to process the authentication packets


Handling:

1.    First we collected diagnostic and noticed some issues with the configuration:

2

2

It was set the accounting-scheme, but did not set the accounting server. Please check the link below for details how to set:

http://support.huawei.com/hedex/hdx.do?docid=EDOC1000153688&id=dc_cfg_wlan_sec_0083&text=Example%20for%20Configuring%20802.1X%20Authentication%20%28AAA%20in%20RADIUS%20Mode%29&lang=en

2.    Also we fired a ping using the command “ping –a 172.29.X.X 172.17.X.X“ to check the AC can reach RADIUS server or not and was successful;

3.    We also created vlan 753 in AC using command “vlan batch 753”

4.    Then we used test-aaa to check if the user can authenticate successfully on the RADIUS but seems the server deny the tests;

5.    We traced the station, but no information. So, we create a test SSID ‘HW_test’ and the station can connect to it;

6.    We suspected the station configuration has issues problem so we changed smart phone to test. In the trace information, we saw AC sent EAP_request packet to the user, but didn’t receive a response from the user.

3

And we noticed that the EAP_request packet is very large:

4   

Because some stations can’t receive or handle large packet of EAP_request, we changed the MTU value in radius server template:

5

7.    After we changed this, the smart phone was online:

 

6


8.    We checked the PC, and forgot the old WLAN network of ‘Test Corp’, and reset the configuration. And we traced the PC, we found radius server reject this user:

7

9.    Then after reboot the station, and the PC was online successfully:

8

 

Root Cause:

Some STAs cannot handle large MTU so it’s best to choose smaller in those cases.


Solution:

 Use commands “radius-attribute set Framed-Mtu 800” in the RADIUS server template.


Suggestions:

Always make sure the MTU is supported on both sides of the connection.


Authentication between AC and the RADIUS is denied by RADIUS server-3294720-1
View more
  • x
  • convention:

The locating procedure is detailed. Thanks for sharing.
View more
  • x
  • convention:

criss_tee_an
criss_tee_an Created Nov 18, 2020 07:49:12 (0) (0)
It took some time to hide all the GDPR data :D  
quality share. Thank you for the post.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.