对接的radius是华为nce campus,认证radius已经显示认证成功,抓包也看到有Access-accept的报文。但是交换机侧仍然认证失败,终端无法联网。
(0)
是否回应code2,参考:https://zhiliao.h3c.com/Theme/details/78995
(0)
是code2,但是那个连接没看懂,需要怎么处理呢?
抓包看到nce campus返回的是code2,交换机debug也看到code2,然后需要怎么处理呢?
抓包只有access-request和access-accept报文,是不是还需要有accounting报文交互后才可以访问网络?
sysname H3C # domain default enable system # ipv6 # telnet server enable # mac-authentication mac-authentication domain system # password-recovery enable # vlan 1 # vlan 26 # radius scheme system primary authentication NCE-Campus-IP key cipher $c$3$rkPmrgpX+399aao+IAWA/0ULZPvztyfYYWXl primary accounting NCE-Campus-IP 1812 key cipher $c$3$kyQhdQpz7bwlN2y7rjJpTAqOBg2oRAWeQOv5 user-name-format without-domain # domain system authentication default radius-scheme system accounting default radius-scheme system access-limit disable state active idle-cut disable self-service-url disable # user-group system group-attribute allow-guest # interface NULL0 # interface Vlan-interface1 ip address 192.168.0.222 255.255.255.0 # interface Ethernet1/0/1 port access vlan 26 mac-authentication # interface Ethernet1/0/2 ---- More ---- #
[H3C]dis radius schemesys system SchemeName : system Index : 0 Type : standard Primary Auth Server: IP: NCE-Campus-IP Port: 1812 State: active Encryption Key : ****** Probe username : N/A Probe interval : N/A Primary Acct Server: IP: NCE-Campus-IP Port: 1812 State: active Encryption Key : ****** Auth Server Encryption Key : N/A Acct Server Encryption Key : N/A Accounting-On packet disable, send times : 50 , interval : 3s Interval for timeout(second) : 3 Retransmission times for timeout : 3 Interval for realtime accounting(minute) : 12 Retransmission times of realtime-accounting packet : 5 Retransmission times of stop-accounting packet : 500 Quiet-interval(min) : 5 Username format : without-domain Data flow unit : Byte Packet unit : one
<H3C>debugging radius *Apr 26 12:42:28:030 2000 H3C MACAUTH/7/EVENT: Port:Ethernet1/0/1,new mac address f8e4-3ba4-ea6f *Apr 26 12:42:28:032 2000 H3C MACAUTH/7/EVENT: Port:Ethernet1/0/1, Need not delay. *Apr 26 12:42:28:032 2000 H3C MACAUTH/7/EVENT: Auth:35,Processing node CONNECTING... *Apr 26 12:42:28:038 2000 H3C RDS/7/DEBUG: Recv MSG,[MsgType=Auth request Index = 35, ulParam3=2219856400] *Apr 26 12:42:28:039 2000 H3C RDS/7/DEBUG: Send attribute list: *Apr 26 12:42:28:040 2000 H3C RDS/7/DEBUG: [1 User-name ] [14] [f8e43ba4ea6f] [2 Password ] [18] [BC4257EE9E4D8CE43932D771AE104E35] [4 NAS-IP-Address ] [6 ] [192.168.0.222] [32 NAS-Identifier ] [5 ] [H3C] [5 NAS-Port ] [6 ] [16781338] [87 NAS_Port_Id ] [35] [slot=1;subslot=0;port=1;vlanid=26] *Apr 26 12:42:28:041 2000 H3C RDS/7/DEBUG: [61 NAS-Port-Type ] [6 ] [15] [6 Service-Type ] [6 ] [10] [7 Framed-Protocol ] [6 ] [1] [31 Caller-ID ] [19] [46382D45342D33422D41342D45412D3646] [44 Acct-Session-Id ] [18] [1000326124221010] *Apr 26 12:42:28:042 2000 H3C RDS/7/DEBUG: Event: Send Packet,oem(0), send count(0), primary state(0). *Apr 26 12:42:28:043 2000 H3C RDS/7/DEBUG: Event: Restart select server. *Apr 26 12:42:28:044 2000 H3C RDS/7/DEBUG: Event: Begin to switch RADIUS server when sending 0 packet. *Apr 26 12:42:28:045 2000 H3C RDS/7/DEBUG: Event: Modify NAS-IP to 192.168.0.222. *Apr 26 12:42:28:046 2000 H3C RDS/7/DEBUG: Send: IP=[NCE-Campus-IP], UserIndex=[35], ID=[32], RetryTimes=[0], Code=[1], Length=[159] *Apr 26 12:42:28:046 2000 H3C RDS/7/DEBUG: Event: Set socket VPN attribute, VPN index=0, Result=0! *Apr 26 12:42:28:047 2000 H3C RDS/7/DEBUG: Send Raw Packet is: *Apr 26 12:42:28:048 2000 H3C RDS/7/DEBUG: 01 20 00 9f 58 25 27 e4 42 d9 94 d1 de 0b 08 28 7e 2f 55 20 01 0e 66 38 65 34 33 62 61 34 65 61 36 66 02 12 bc 42 57 ee 9e 4d 8c e4 39 32 d7 71 ae 10 4e 35 04 06 c0 a8 00 de 20 05 48 33 43 05 06 01 00 10 1a 57 23 73 6c 6f 74 3d 31 3b 73 75 62 73 6c 6f 74 3d 30 3b 70 6f 72 74 3d 31 3b 76 6c 61 6e 69 64 3d 32 36 3d 06 00 00 00 0f 06 06 00 00 00 0a 07 06 00 00 00 01 1f 13 46 38 2d 45 34 2d 33 42 2d 41 34 2d 45 41 2d 36 46 2c 12 31 30 30 30 33 32 36 31 32 34 32 32 31 30 31 30 *Apr 26 12:42:28:174 2000 H3C RDS/7/DEBUG: Recv MSG,[MsgType=PKT response Index = 20, ulParam3=2220247904] *Apr 26 12:42:28:174 2000 H3C RDS/7/DEBUG: Receive Raw Packet is: *Apr 26 12:42:28:175 2000 H3C RDS/7/DEBUG: 02 20 00 14 c3 79 b7 72 00 d3 1f e1 a6 75 aa a4 bd d7 76 e9 *Apr 26 12:42:28:176 2000 H3C RDS/7/DEBUG: Receive:IP=[NCE-Campus-IP],Code=[2],Length=[20] *Apr 26 12:42:28:177 2000 H3C RDS/7/DEBUG: NULL *Apr 26 12:42:28:182 2000 H3C MACAUTH/7/EVENT: Auth:35,Processing node connecting trans... *Apr 26 12:42:28:183 2000 H3C MACAUTH/7/EVENT: Port:Ethernet1/0/1,Auth:35,PORTSEC HandleAccessUserEvent return 2 *Apr 26 12:42:28:184 2000 H3C MACAUTH/7/EVENT: Auth:35,Processing node RELEASE...p
发现accounting port配置错了,回去我再试试
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
发现accounting port配置错了,回去我再试试