Troubleshooting
Unusual Network Activity
The switch does not receive a response to RADIUS authentication
requests.
In this case, the switch will attempt authentication using the
secondary method configured for the type of access you are using (console,
Telnet, or SSH).
There can be several reasons for not receiving a response to an authentication
request. Do the following:
■
Use
ping
to ensure that the switch has access to the configured RADIUS
servers.
■
Verify that the switch is using the correct encryption key (RADIUS secret
key) for each server.
■
Verify that the switch has the correct IP address for each RADIUS server.
■
Ensure that the
radius-server timeout
period is long enough for network
conditions.
The switch does not authenticate a client even though the RADIUS
server is properly configured and providing a response to the
authentication request.
If the RADIUS server configuration for authenti
cating the client includes a VLAN assignment, ensure that the VLAN exists as
a static VLAN on the switch. Refer to “How 802.1X Authentication Affects
VLAN Operation” in the
Access Security Guide
for your switch.
During RADIUS-authenticated client sessions, access to a VLAN on the
port used for the client sessions is lost.
If the affected VLAN is config
ured as untagged on the port, it may be temporarily blocked on that port during
an 802.1X session. This is because the switch has temporarily assigned another
VLAN as untagged on the port to support the client access, as specified in the
response from the RADIUS server. Refer to “How 802.1X Authentication
Affects VLAN Operation” in the
Access Security Guide
for your switch.
The switch appears to be properly configured as a supplicant, but
cannot gain access to the intended authenticator port on the switch
to which it is connected.
If
aaa authentication port-access
is configured for
Local, ensure that you have entered the local
login
(operator-level) username
and password of the authenticator switch into the
identity
and
secret
parame
ters of the supplicant configuration. If instead, you enter the enable (manager
level) username and password, access will be denied.
C-11
Содержание PROCURVE 2520
Страница 2: ......
Страница 3: ...HP ProCurve 2520 Switches November 2009 S 14 03 Management and Configuration Guide ...
Страница 60: ...Using the Menu Interface Where To Go From Here 3 16 ...
Страница 82: ...Using the Command Line Interface CLI CLI Editing Shortcuts 4 22 ...
Страница 104: ...Using the ProCurve Web Browser Interface Status Reporting Features Figure 5 14 Example of Alert Log Detail View 5 22 ...
Страница 146: ...Switch Memory and Configuration Automatic Configuration Update with DHCP Option 66 6 40 ...
Страница 164: ...Interface Access and System Information System Information 7 18 ...
Страница 184: ...Configuring IP Addressing IP Preserve Retaining VLAN 1 IP Addressing Across Configuration File Downloads 8 20 ...
Страница 292: ...Port Trunking Outbound Traffic Distribution Across Trunked Links 12 30 ...
Страница 374: ...Configuring for Network Management Applications LLDP Link Layer Discovery Protocol 13 82 ...
Страница 434: ...Monitoring and Analyzing Switch Operation Locating a Device B 30 ...
Страница 514: ...Troubleshooting DNS Resolver C 80 ...
Страница 524: ...Daylight Savings Time on ProCurve Switches E 4 ...
Страница 525: ...F Power Saving Features Contents Configuring Power Saving for LEDs F 2 Show Savepower Status F 2 F 1 ...
Страница 542: ...16 Index ...
Страница 543: ......