Mypower
S4100
Troubleshooting
Maipu Confidential & Proprietary Information
Page
82
of
124
Fault 2: User gets offline immediately after login
Possible Reasons
Judging Methods and Solutions
1.
The default role is not
configured on the ps,
but the client PC NIC
is configured with two
IP addresses which
are in two different
network segments.
Check whether the PS is configured with default role. If not, add
default role and set the network segment to contain the IP
address of the PC NIC, or remove the non-authentication IP
address on the client PC.
2.
After the user logs in,
match the check rule
bound with the PS
and enters the default
vlan (for the TC user)
Check the host rule characteristics bound with the user role on
the PS and the implemented action. If the characteristics are
matched, check the PC security or change the host rule.
3.
The ARP cheat exists
in the network
The client PC is infected and sends ARP cheat packets or the
network connected with authentication port has ARP cheat,
imitating multiple IP addresses to send ARP requests. As a
result, the users get offline. Eliminate the ARP cheat to solve the
problem.
4.
The default role
network segment and
the client non-
authentication IP
address are not in the
same network
segment
Set the address of the PC NIC in the client to the IP address in
the user role network segment. If you set the second IP
address, ensure that the IP address is in the network segment
where the default role is bound.
Fault 3: User cannot obtain the IP address in the process of login
Possible Reasons
Judging Methods and Solutions
The public rule of the
device on the PS does not
allow dhcp application
Check whether the DHCP permission rules exist on the ps device
public rules. If not, add the rule.
Fault 4: User cannot ping any address in the process of login or after login
Possible Reasons
Judging Methods and Solutions
In the PS device public
rules, there is not rules
allowing ICMP; or in the
device rule there is not rule
allowing icmp. At the same
time, the role default action
is Deny.
The public rule takes effect when the tac is enabled at the port.
The device rule takes effect after the user logs in. After
successful login, the default action of the role is set to Deny. As
a result, the unmatched rules are all denied. Check the setting
of the PS and change it to the proper value.
Fault 5: After the authentication failed, the user cannot the security
resources including virus server
Possible Reasons
Judging Methods and Solutions