
Aruba Instant AP | Troubleshooting Guide
32
(Instant AP)#aaa test-server <servername> username <username> password <passwd> auth-
type <type>
Debug the RADIUS Packets of the Client
Run the
debug pkt match <MAC address> type radius
command and check the RADIUS packets
exchanged between the client and the AP for more information. Use the MAC address of the client in the
match
parameter to filter packets specific to a client.
The following command syntax is used to view the radius packets specific to a client:
(Instant AP)#debug pkt match <MAC address> type radius
(Instant AP)#debug pkt dump
Wireless Client Fails MAC Authentication
Clients must pass MAC authentication to connect to the AP if MAC authentication is enabled. However
clients can connect to the AP despite MAC authentication failure, if MAC authentication is used in
combination with:
n
802.1X authentication and
MAC authentication fail-thru
is enabled.
n
Captive portal authentication and
MAC authentication fail-thru
is enabled.
The following procedure describes how to troubleshoot issues, if the client fails MAC authentication:
Check Authentication Process Logs on the AP
Check the authentication logs to view and identify errors in the authentication process between the client
and the AP.
Run the
show ap debug auth-trace-buff <MAC address>
command to view the authentication process
logs between the client and the AP. Use the MAC address of the client to filter packets specific to a client.
Any error in the authentication process will be displayed in the output.
Wireless Client Fails to Reach Captive Portal
Authentication Page
The following procedure describes how to troubleshoot issues, if the client fails to reach the captive portal
authentication page:
1.
Identify the Captive Portal Mode of the SSID
2.
Debug ECP Mode Behavior on Client PC
Identify the Captive Portal Mode of the SSID
There are two modes of captive portal authentication provided by the AP:
n
ECP tiny proxy mode
— the captive portal page is provided by the AP and the AP mediates
authentication between the client and the captive portal server.
n
ECP redirect mode
— the AP redirects the client to the captive portal server for authentication.
Run the
show external-captive-portal
command in the CLI to view the captive portal mode of the SSID.
(Instant AP0# show external-captive-portal
External Captive Portal
-----------------------