RADIUS Authentication Failure with SSH Login

146 0 0 0

This is regarding a case I had with testing the RADIUS AAA on an S5700 Switch. I had configured an Agile Controller as the RADIUS Server on the Switch. In the Agile Controller, an Active Directory (AD) Server was already synchronized so that the AD users on the Agile Controller can be found by going to Resources > User Management.


Upon finishing the configuration of RADIUS AAA and on the Switch, I proceeded to test it on the Switch CLI using the following command:

<master switch> sys

[master switch] test-aaa <AD account username> <password> radius-template <template name> pap

Info: Account test succeeded


Note that when using the test-aaa command and testing with a synchronized AD account, the PAP protocol is used as the CHAP (which is the default when no protocol is stated) will fail. Also check the Agile Controller for the RADIUS login attempt after using this command so as to assure that the Agile Controller is being used a RADIUS Server for authentication. The RADIUS logs can be found by going to Resources > RADIUS Logs. Should there be any error, these logs can provide an even more detailed error message as resolution for each individual error message can vary.


Seeing that the test is successful, I then proceeded to try to log on to the Switch through SSH using the AD account but then got the following result.

login as: <AD account username>

SSH server: User Authentication

Using keyboard-interactive authentication.

Password: <password>

Access denied


After seeing the that the login through SSH has failed, I checked the Agile Controller for a RADIUS log pertaining to my failed login attempt but found none.


Although no logs or detailed error messages were found on the Agile Controller, the solution for this particular case was pretty simple. Executing the following command on the Switch CLI allowed for a successful authentication via SSH:

[master switch] ssh user <AD account username> authentication-type password

[master switch] ssh user <AD account username> service-type all


This command will allow the AD account specified to gain access to the Switch CLI via SSH. Do note that this command should be executed for every Agile Controller account that wishes to gain access to the Switch CLI via SSH.








  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login