
10.1 AAA Troubleshooting
10.1.1 RADIUS Authentication Fails
Common Causes
This fault is commonly caused by one of the following:
l
The user name or password is incorrect. For example, the user name does not exist, or the
user name format (with or without the domain name) is different from the format configured
on the Remote Authentication Dial In User Service (RADIUS) server.
l
The RADIUS configuration on the AR2200-S is incorrect, including the authentication
mode and the RADIUS server template.
l
The port number and shared key configured on the AR2200-S are different from those on
the RADIUS server.
l
The number of online users reaches the maximum value.
Troubleshooting Flowchart
A user fails to pass the Authentication Dial In User Service (RADIUS) authentication.
The troubleshooting roadmap is as follows:
l
Check whether the link between the AR2200-S and the RADIUS server is working.
l
Check whether the number of authenticated users has reached the maximum.
l
Check the RADIUS configuration on the AR2200-S, including the domain name, domain
status, RADIUS server template, authentication mode, and accounting mode.
l
Check whether the user name, password, and user access type configured on the RADIUS
server are correct and whether the router IP address, port number, shared key, and domain
name carry method and resolution method configured on the RADIUS server are the same
as those configured on the AR2200-S.
shows the troubleshooting flowchart.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
267