Got it

RADIUS-reject VLAN ID

Created: Sep 14, 2021 20:18:08Latest reply: Oct 7, 2021 19:23:23 398 9 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi all.


I'm using a few AP4050DN in Fat AP mode (V200R019C00SPC903) in some of the installations and i'd like to have a single SSID - multiple VLAN setup, with MAC-based VLAN assingnment (external RADIUS server with MAC addresses as usernames).


The problem I'm facing is that for the guest network (unknown MACs, and nonexistent RADIUS users) the RADIUS answers with access-reject, and I can't change this behaviour. So I'd like such users to still be authorised locally, but to put them into the guest VLAN.

I see a setting to set a user group (and this way a VLAN ID) for situations, when RADIUS server is unavilble, but there is no such setting for situations when RADIUS server answers with access-reject.

Am I missing something, or what I want is not possible?


If so, can anyone suggest a workaround?


Thanks!


Featured Answers

Recommended answer

chenhui
Admin Created Sep 15, 2021 02:44:41

Hello,
You can configure the NAC escape mechanism to put the authentication failure users to a specific user group to authorize them.
You can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100096145&id=EN-US_CONCEPT_0176368612&lang=en
View more
  • x
  • convention:

xvo
xvo Created Sep 15, 2021 08:25:33 (0) (0)
Thanks for you answer.

That is exactly what I was trying to do, but there is no such event as "authen-fail" for me.
Only "authen-server-down" and "authen-server-up", hence the original question.

[nya Huawei-authentication-profile-nya_5G]authentication event ?
authen-server-down Authentication server down
authen-server-up Authentication server up  
chenhui
chenhui Reply xvo  Created Sep 16, 2021 06:56:23 (0) (0)
Well, it seems that this command is supported since V200R020.  
xvo
xvo Reply chenhui  Created Sep 16, 2021 08:43:12 (0) (0)
Will there be V200R020 for AP4050DN?
Or is there any chance that this will be backported to V200R019 release tree?  
chenhui
chenhui Reply xvo  Created Sep 16, 2021 09:41:30 (0) (0)
I'll confirm that, and will feedback to you as soon as I got the conculsion.  
xvo
xvo Reply chenhui  Created Sep 22, 2021 20:50:50 (0) (0)
Hi.
Any new info on the topic?  
chenhui
chenhui Reply xvo  Created Sep 23, 2021 07:50:19 (0) (0)
I'm sorry, but I didn't get the response either.  
All Answers
Hello! Thank you for contacting us.
We are working on an answer for you.
View more
  • x
  • convention:

Hello,
You can configure the NAC escape mechanism to put the authentication failure users to a specific user group to authorize them.
You can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100096145&id=EN-US_CONCEPT_0176368612&lang=en
View more
  • x
  • convention:

xvo
xvo Created Sep 15, 2021 08:25:33 (0) (0)
Thanks for you answer.

That is exactly what I was trying to do, but there is no such event as "authen-fail" for me.
Only "authen-server-down" and "authen-server-up", hence the original question.

[nya Huawei-authentication-profile-nya_5G]authentication event ?
authen-server-down Authentication server down
authen-server-up Authentication server up  
chenhui
chenhui Reply xvo  Created Sep 16, 2021 06:56:23 (0) (0)
Well, it seems that this command is supported since V200R020.  
xvo
xvo Reply chenhui  Created Sep 16, 2021 08:43:12 (0) (0)
Will there be V200R020 for AP4050DN?
Or is there any chance that this will be backported to V200R019 release tree?  
chenhui
chenhui Reply xvo  Created Sep 16, 2021 09:41:30 (0) (0)
I'll confirm that, and will feedback to you as soon as I got the conculsion.  
xvo
xvo Reply chenhui  Created Sep 22, 2021 20:50:50 (0) (0)
Hi.
Any new info on the topic?  
chenhui
chenhui Reply xvo  Created Sep 23, 2021 07:50:19 (0) (0)
I'm sorry, but I didn't get the response either.  
So I guess there is no solution for V200R019?
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.