3 Troubleshooting Functional Failures During Operation
60
No.
Items to check and commands
Action
8
If authentication linked with the NAP
quarantine system cannot be
performed in port-based
authentication (static) mode, check
the setting of the authentication
IPv4 access list.
Make sure access permission for the quarantine server is set
in the authentication IPv4 access list.
Correct the configuration so that the
Filter-ID
value
specified for the
RADIUS
attribute of the RADIUS server
matches the authentication IPv4 access list name for the
Switch.
#1
Check the following configuration command settings:
1.
When both the
switchport mac vlan
and
no switchport mac auto-vlan
are
not set
- The VLAN ID for the RADIUS server has been set by
vlan mac-based
.
- The VLAN ID of the authenticating port does not match
switchport mac
dot1q vlan
.
2.
When both the
switchport mac vlan
and
no
switchport mac auto-vlan
are
set
- The VLAN ID of the authenticating port matches
switchport mac vlan
.
#2
Be careful of the following when using a VLAN name configured using the
name
configuration command as a VLAN after RADIUS authentication.
Specify a unique VLAN name. If the same VLAN name is used for two or more
VLANs, the smallest VLAN ID is allocated as the post-authentication VLAN in
RADIUS authentication mode.
Do not specify a number at the beginning of the VLAN name. A number at the
beginning will be recognized as the VLAN ID, which might result in an
authentication failure.
If communication is not possible on a port or VLAN that uses IEEE 802.1X, isolate the
cause of the problem according to the failure analysis method described in the table below.
If neither is the case, see
3.5 Layer 2 network communication failures
.
Table 3-22
Communication failure analysis method for IEEE 802.1X
No.
Items to check and commands
Action
1
Check whether the authenticated
terminal has moved to an
unauthenticated port in the same
VLAN.
If the terminal authenticated on the Switch has moved to an
unauthenticated port, communication is disabled until the
authentication information is cleared. Use the
clear
dot1x
auth-state
operation command to clear the authentication
status of the terminal.
Содержание AX2500S
Страница 1: ...AX2500S Troubleshooting Guide AX25S T001X 60...
Страница 6: ......
Страница 34: ...1 Overview 8...
Страница 40: ...2 Troubleshooting Switch Failures 14...
Страница 106: ...3 Troubleshooting Functional Failures During Operation 80 config...
Страница 116: ...3 Troubleshooting Functional Failures During Operation 90...
Страница 121: ...95 5 Line Testing 5 1 Testing a line...
Страница 126: ...5 Line Testing 100...
Страница 127: ...101 Appendix A Detailed Display Contents of the show tech support Command...