Operation Manual - Security
Quidway S3500 Series Ethernet Switches
Chapter 3 AAA and RADIUS Protocol Configuration
Huawei Technologies Proprietary
3-25
3.6 AAA and RADIUS Protocol Fault Diagnosis and
Troubleshooting
RADIUS protocol of TCP/IP protocol suite is located on the application layer. It mainly
specifies how to exchange user information between NAS and RADIUS server of ISP.
So it is very likely to be invalid.
z
Fault one: User authentication/authorization always fails
Troubleshooting:
1) The username may not be in the userid@isp-name format or NAS has not been
configured with a default ISP domain. Please use the username in proper format
and configure the default ISP domain on NAS.
2) The user may have not been configured in the RADIUS server database. Check
the database and make sure that the configuration information of the user does
exist in the database.
3) The user may have input a wrong password. So please make sure that the
supplicant inputs the correct password.
4) The encryption keys of RADIUS server and NAS may be different. Please check
carefully and make sure that they are identical.
5) There might be some communication fault between NAS and RADIUS server,
which can be discovered through pinging RADIUS from NAS. So please ensure
the normal communication between NAS and RADIUS.
z
Fault two: RADIUS packet cannot be transmitted to RADIUS server.
Troubleshooting:
1) The communication lines (on physical layer or link layer) connecting NAS and
RADIUS server may not work well. So please ensure the lines work well.
2) The IP address of the corresponding RADIUS server may not have been set on
NAS. Please set a proper IP address for RADIUS server.
3) UDP ports of authentication/authorization and accounting services may not be set
properly. So make sure they are consistent with the ports provided by RADIUS
server.
z
Fault three: After being authenticated and authorized, the user cannot send
charging bill to the RADIUS server.
Troubleshooting:
1) The accounting port number may be set improperly. Please set a proper number.
2) The accounting service and authentication/authorization service are provided on
different servers, but NAS requires the services to be provided on one server (by
specifying the same IP address). So please make sure the settings of servers are
consistent with the actual conditions.
Содержание Quidway S3500 Series
Страница 42: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Port ...
Страница 64: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual VLAN ...
Страница 159: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Routing Protocol ...
Страница 266: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Multicast ...
Страница 323: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual QoS ACL ...
Страница 402: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Integrated Management ...
Страница 431: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual STP ...
Страница 466: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Security ...
Страница 537: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Reliability ...
Страница 551: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual System Management ...
Страница 654: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Auto Detecting ...
Страница 667: ...Huawei Technologies Proprietary HUAWEI Quidway S3500 Series Ethernet Switches Operation Manual Appendix ...