SecBlade FW Enhanced Module和无线AC都遇到这个问题,通过普通用户可以登录网页,通过RADIUS认证就不行了。
通过 https://www.h3c.com/cn/Service/Document_Software/Document_Center/Home/Security/00-Public/Configure/Radius_Attribute_List/H3C_RADIUS_V7-5273/#_Toc145427820 查询到 Login-Service = 54为HTTPS,从debug也可以看出从RADIUS服务器得到了属性,但网页就是无法登录,可能“The login-service type that server assigned does not match with the access type.”就是问题,不知道RADIUS下发什么属性可以让用户登录网页,试过Login-Service=SSH可以让用户从SSH登录的。
Decoded reply packet successfully.
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/PACKET: -COntext=1;
Login-Service=54
Service-Type=Login-User
Login-Service=Terminal
Login-Service=SSH
H3c-Exec-Privilege=3
H3c-User-Roles="shell:roles="network-admin""
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/PACKET: -COntext=1;
02 3e 00 5b 71 b6 a1 84 e0 f9 b7 40 90 88 10 cd
c7 64 2f 55 0f 06 00 00 00 36 06 06 00 00 00 01
0f 06 00 00 00 34 0f 06 00 00 00 32 1a 0c 00 00
63 a2 1d 06 00 00 00 03 1a 23 00 00 63 a2 9b 1d
73 68 65 6c 6c 3a 72 6f 6c 65 73 3d 22 6e 65 74
77 6f 72 6b 2d 61 64 6d 69 6e 22
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/ERROR: -COntext=1;
The login-service type that server assigned does not match with the access type.
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
Sent reply message successfully.
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
PAM_RADIUS: Processing RADIUS authentication.
*Jan 25 13:23:42:742 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
PAM_RADIUS: Fetched authentication reply-data successfully, resultCode: 1
%Jan 25 13:23:42:743 2024 h3c_fw WEB/5/LOGIN_FAILED: -COntext=1; h3c-administrator@home.lan 从 x.x.x.x 登录失败.
配置信息:
radius scheme freeradius
primary authentication x.x.x.x
primary accounting x.x.x.x
accounting-on enable
key authentication cipher $c$3$XOOT/JeB3PGLkhBRol5pEdYPvd0V0PJB2jrqOFV88GrN4cp8fYRDjSaHCOOHKulq0w==
key accounting cipher $c$3$oleEMd/bnexygvv8ajyqBCRUkJUbioNqg7kJDy0SmkF2eQixgz8pVEeUr9qAslTiPw==
timer response-timeout 5
user-name-format without-domain
nas-ip x.x.x.x
data-flow-format data kilo-byte
#
domain home.lan
authentication login radius-scheme freeradius local
authorization login radius-scheme freeradius local
accounting login radius-scheme freeradius local
authentication super radius-scheme freeradius
#
(0)
您好,我记得不支持,只能使用http
(0)
ip http enable后,浏览器通过http打开网页,然后把RADIUS属性改成了53(HTTP)试了还是不行。 Decoded reply packet successfully. *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/PACKET: -COntext=1; Service-Type=Login-User Login-Service=Terminal Login-Service=SSH Login-Service=53 H3c-Exec-Privilege=3 H3c-User-Roles="shell:roles="network-admin"" *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/PACKET: -COntext=1; 02 bc 00 5b 6b 75 86 c1 ee da cb b3 b0 65 2f e2 3f 13 eb bf 06 06 00 00 00 01 0f 06 00 00 00 34 0f 06 00 00 00 32 0f 06 00 00 00 35 1a 0c 00 00 63 a2 1d 06 00 00 00 03 1a 23 00 00 63 a2 9b 1d 73 68 65 6c 6c 3a 72 6f 6c 65 73 3d 22 6e 65 74 77 6f 72 6b 2d 61 64 6d 69 6e 22 *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/ERROR: -COntext=1; The login-service type that server assigned does not match with the access type. *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1; Sent reply message successfully. *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1; PAM_RADIUS: Processing RADIUS authentication. *Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1; PAM_RADIUS: Fetched authentication reply-data successfully, resultCode: 1 %Jan 25 14:24:28:246 2024 h3c_fw WEB/5/LOGIN_FAILED: -COntext=1; h3c-administrator@hajyw.lan 从 x.x.x.x 登录失败.
ip http enable后,浏览器通过http打开网页,然后把RADIUS属性改成了53(HTTP)试了还是不行。
Decoded reply packet successfully.
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/PACKET: -COntext=1;
Service-Type=Login-User
Login-Service=Terminal
Login-Service=SSH
Login-Service=53
H3c-Exec-Privilege=3
H3c-User-Roles="shell:roles="network-admin""
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/PACKET: -COntext=1;
02 bc 00 5b 6b 75 86 c1 ee da cb b3 b0 65 2f e2
3f 13 eb bf 06 06 00 00 00 01 0f 06 00 00 00 34
0f 06 00 00 00 32 0f 06 00 00 00 35 1a 0c 00 00
63 a2 1d 06 00 00 00 03 1a 23 00 00 63 a2 9b 1d
73 68 65 6c 6c 3a 72 6f 6c 65 73 3d 22 6e 65 74
77 6f 72 6b 2d 61 64 6d 69 6e 22
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/ERROR: -COntext=1;
The login-service type that server assigned does not match with the access type.
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
Sent reply message successfully.
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
PAM_RADIUS: Processing RADIUS authentication.
*Jan 25 14:24:28:245 2024 h3c_fw RADIUS/7/EVENT: -COntext=1;
PAM_RADIUS: Fetched authentication reply-data successfully, resultCode: 1
%Jan 25 14:24:28:246 2024 h3c_fw WEB/5/LOGIN_FAILED: -COntext=1; h3c-administrator@hajyw.lan 从 x.x.x.x 登录失败.
不是要实现Portal,是登录防火墙/无线AC设备的管理网页,RADIUS对接了LDAP,这样以后一个地方改密码就行了,不需要每个设备都改一次密码。
SSH已经可以了,就是HTTPS网页登录不了管理页面。
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明