224
C
HAPTER
11: 802.1X C
ONFIGURATION
AAA and RADIUS
Protocol Fault Diagnosis
and Troubleshooting
The RADIUS protocol of the TCP/IP protocol suite is located on the application
layer. It mainly specifies how to exchange user information between NAS and
RADIUS server of ISP. So it is likely to be invalid.
Fault One: User Authentication/Authorization Always Fails
Troubleshooting:
■
The username may not be in the
userid@isp-name
format or NAS has not
been configured with a default ISP domain. Use the username in proper format
and configure the default ISP domain on NAS.
■
The user may have not been configured in the RADIUS server database. Check
the database and make sure that the configuration information of the user
does exist in the database.
■
The user may have input a wrong password. So make sure that the user inputs
the correct password.
■
The encryption keys of RADIUS server and NAS may be different. Check
carefully and make sure that they are identical.
■
There might be some communication fault between NAS and RADIUS server,
which can be discovered through pinging RADIUS from NAS. So ensure there is
normal communication between NAS and RADIUS.
Fault Two: RADIUS Packet Cannot be Transmitted to RADIUS Server
Troubleshooting:
■
The communication lines (on physical layer or link layer) connecting NAS and
the RADIUS server may not work well. So ensure the lines work well.
■
The IP address of the corresponding RADIUS server may not have been set on
NAS. Set a proper IP address for RADIUS server.
■
UDP ports of authentication/authorization and accounting services may not be
set properly. So make sure they are consistent with the ports provided by
RADIUS server.
Fault Three: After Being Authenticated and Authorized, the User Cannot
Send Charging Bill to the RADIUS Server
Troubleshooting:
■
The accounting port number may be set improperly. Please set a proper
number.
■
The accounting service and authentication/authorization service are provided
on different servers, but NAS requires the services to be provided on one server
(by specifying the same IP address). So make sure the settings of the servers are
consistent with the actual conditions.
Содержание Switch 4500 26-Port
Страница 16: ...14 ABOUT THIS GUIDE...
Страница 58: ...56 CHAPTER 2 PORT OPERATION...
Страница 104: ...102 CHAPTER 5 NETWORK PROTOCOL OPERATION...
Страница 130: ...128 CHAPTER 6 IP ROUTING PROTOCOL OPERATION...
Страница 154: ...152 CHAPTER 7 ACL CONFIGURATION...
Страница 228: ...226 CHAPTER 11 802 1X CONFIGURATION...
Страница 250: ...248 CHAPTER 14 DEVICE MANAGEMENT...
Страница 280: ...278 CHAPTER 15 SYSTEM MAINTENANCE AND DEBUGGING...
Страница 312: ...310 CHAPTER 18 NTP CONFIGURATION...
Страница 340: ...338 CHAPTER 19 SSH TERMINAL SERVICES...
Страница 350: ...348 CHAPTER 20 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 388: ...386 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP...