• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

H3C S5500V2-34S-EI 启用dot1x认证后,仅有个别端口可以认证,其他端口认证失败

3天前提问
  • 0关注
  • 0收藏,70浏览
粉丝:0人 关注:0人

问题描述:

H3C S5500V2-34S-EI(Version 7.1.070, Release 1119P03) 启用dot1x认证后,仅有个别端口可以认证,其他端口认证失败,端口配置都一样,而且该交换机一重启,原来不能认证的端口现在可以了,但其他端口又不能认证了

组网及组网描述:

H3C S5500V2-34S-EI交换机 胖挂radius,下接pc,接口启用了dot1x配置
接口配置如下

interface GigabitEthernet1/0/9(该口下的pc认证无反应)

 port link-mode bridge

 description S1224-8

 port access vlan 11

 stp edged-port

 dot1x mandatory-domain 1x-domain

 undo dot1x multicast-trigger

 dot1x unicast-trigger

 dot1x guest-vlan 11

 dot1x auth-fail vlan 13

 mac-authentication domain gz_radius

 mac-authentication timer auth-delay 15

 undo mac-authentication offline-detect enable

 port-security port-mode userlogin-secure-or-mac-ext

 

interface GigabitEthernet1/0/11(该口的pc认证正常)

 port link-mode bridge

 description S1224-4

 port access vlan 12

 stp edged-port

 undo dot1x handshake

 dot1x mandatory-domain 1x-domain

 undo dot1x multicast-trigger

 dot1x unicast-trigger

 dot1x guest-vlan 11

 dot1x auth-fail vlan 13

 mac-authentication domain gz_radius

 mac-authentication timer auth-delay 15

 undo mac-authentication offline-detect enable

 port-security port-mode userlogin-secure-or-mac-ext

 

 GigabitEthernet1/0/11  is link-up

   Online 802.1X users: 1

          MAC address       Auth state

          e0d5-5e6b-819b    Authenticated  

 

2 个回答
粉丝:0人 关注:0人

 确保所有相关端口的802.1X配置一致,包括接口下的dot1x命令和相关的AAA配置。检查交换机是否达到了资源或会话限制,某些设备在并发认证会话上可能有硬件限制。
在交换机上启用调试模式,观察802.1X认证过程中的日志信息:
display logbuffer
debugging dot1x all  

所有配置一致,同一个vlan,在该交换机接口上抓包显示,只有start报文,没回给pc 这是9口本机(745d-229d-84b9)点击客户端认证后交换机的提示的debugg信息 *Nov 17 10:09:43:241 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:446 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:743 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Aborting state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Initialize state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Disconnect state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:107 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: Interface GigabitEthernet1/0/2 received Set the port authorization status to unauthorized event. *Nov 17 10:09:48:508 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:48:804 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:49:065 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:54:080 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 undo de all All possible debugging has been turned off. <Hx-A7_2F_H3C> 日志信息如下172.20.32.3是本机ip地址,目前本机接的9口 Current messages: 303 %Nov 17 09:58:49:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally. %Nov 17 09:57:56:433 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse %Nov 17 09:57:45:073 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse %Nov 17 09:57:15:828 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer %Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C CFGMAN/5/CFGMAN_EXIT_FROM_CONFIGURE: -Line=vty0-IPAddr=172.20.32.3-User=admin; Exit from the system view or a feature view to the user view. %Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui %Nov 17 09:56:59:601 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-AccessVLANID=11-AuthorizatiOnVLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726; User passed 802.1X authentication and came online. %Nov 17 09:56:47:093 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui %Nov 17 09:56:46:019 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command exi in view GigabitEthernet1/0/9 failed to be matched. %Nov 17 09:49:53:830 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 11 %Nov 17 09:49:27:392 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:49:25:508 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo dot1x handshake %Nov 17 09:48:47:430 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:45:700 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 12 %Nov 17 09:48:40:669 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:39:064 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/9 %Nov 17 09:48:02:284 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:00:008 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/15 %Nov 17 09:47:40:362 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:47:39:309 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int GigabitEthernet 1/0/9 %Nov 17 09:45:24:350 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions %Nov 17 09:45:17:315 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 12 %Nov 17 09:45:12:834 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 11 %Nov 17 09:44:55:163 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 in view system failed to be matched. %Nov 17 09:43:18:324 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command conf t in view system failed to be matched. %Nov 17 09:43:15:360 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is sys %Nov 17 09:43:10:945 2024 Hx-A7_2F_H3C LLDP/6/LLDP_CREATE_NEIGHBOR: Nearest bridge agent neighbor created on port GigabitEthernet1/0/2 (IfIndex 2), neighbor"s chassis ID is 244b-fe07-746f, port ID is 244b-fe07-746f. %Nov 17 09:42:34:429 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions %Nov 17 09:42:27:122 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 172.20.32.3. %Nov 17 09:41:52:849 2024 Hx-A7_2F_H3C IFNET/5/LINK_UPDOWN: Line protocol state on the interface GigabitEthernet1/0/9 changed to up. %Nov 17 09:41:52:847 2024 Hx-A7_2F_H3C IFNET/3/PHY_UPDOWN: Physical state on the interface GigabitEthernet1/0/9 changed to up. %Nov 17 09:38:07:466 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 192.168.2.6. %Nov 17 09:37:33:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally. %Nov 17 09:36:07:405 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 192.168.2.6. %Nov 17 09:36:01:421 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 172.20.32.3. %Nov 17 09:35:56:309 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/15-MACAddr=745d-229d-84b9-AccessVLANID=12-AuthorizatiOnVLANID=12-Username=term_a59f574f-931a-4f75-be5a-bde7663d9c6c; User passed 802.1X authentication and came online.

zhiliao_4jaxxE 发表时间:2天前 更多>>

您好已回复帮看下

zhiliao_4jaxxE 发表时间:3天前

检查下接口和全局下有没有都使能1x认证

zhiliao_EN9WDl 发表时间:3天前

这是全局的配置: clock protocol none # telnet server enable # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # dot1x authentication-method eap dot1x timer tx-period 10 dot1x access-user log enable abnormal-logoff failed-login normal-logoff successful-login 接口的配置如下,在单独配置dot1x并回车时报错 [Hx-A7_2F_H3C-GigabitEthernet1/0/9]dis thi # interface GigabitEthernet1/0/9 port link-mode bridge description S1224-8 port access vlan 11 stp edged-port undo dot1x handshake dot1x mandatory-domain 1x-domain undo dot1x multicast-trigger dot1x unicast-trigger dot1x guest-vlan 11 dot1x auth-fail vlan 13 mac-authentication domain gz_radius mac-authentication timer auth-delay 15 undo mac-authentication offline-detect enable port-security port-mode userlogin-secure-or-mac-ext # return [Hx-A7_2F_H3C-GigabitEthernet1/0/9]dot1x Can't enable 802.1X for port security is enabled. [Hx-A7_2F_H3C-GigabitEthernet1/0/9] [Hx-A7_2F_H3C-GigabitEthernet1/0/19]dis thi # interface GigabitEthernet1/0/19 port link-mode bridge port access vlan 13 stp edged-port # return [Hx-A7_2F_H3C-GigabitEthernet1/0/19]dot1x Can't enable 802.1X for port security is enabled. [Hx-A7_2F_H3C-GigabitEthernet1/0/19]

zhiliao_4jaxxE 发表时间:2天前

所有配置一致,同一个vlan,在该交换机接口上抓包显示,只有start报文,没回给pc 这是9口本机(745d-229d-84b9)点击客户端认证后交换机的提示的debugg信息 *Nov 17 10:09:43:241 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:446 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:743 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Aborting state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Initialize state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Disconnect state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:107 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: Interface GigabitEthernet1/0/2 received Set the port authorization status to unauthorized event. *Nov 17 10:09:48:508 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:48:804 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:49:065 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:54:080 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 undo de all All possible debugging has been turned off. <Hx-A7_2F_H3C> 日志信息如下172.20.32.3是本机ip地址,目前本机接的9口 Current messages: 303 %Nov 17 09:58:49:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally. %Nov 17 09:57:56:433 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse %Nov 17 09:57:45:073 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse %Nov 17 09:57:15:828 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer %Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C CFGMAN/5/CFGMAN_EXIT_FROM_CONFIGURE: -Line=vty0-IPAddr=172.20.32.3-User=admin; Exit from the system view or a feature view to the user view. %Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui %Nov 17 09:56:59:601 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-AccessVLANID=11-AuthorizatiOnVLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726; User passed 802.1X authentication and came online. %Nov 17 09:56:47:093 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui %Nov 17 09:56:46:019 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command exi in view GigabitEthernet1/0/9 failed to be matched. %Nov 17 09:49:53:830 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 11 %Nov 17 09:49:27:392 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:49:25:508 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo dot1x handshake %Nov 17 09:48:47:430 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:45:700 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 12 %Nov 17 09:48:40:669 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:39:064 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/9 %Nov 17 09:48:02:284 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:48:00:008 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/15 %Nov 17 09:47:40:362 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi %Nov 17 09:47:39:309 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int GigabitEthernet 1/0/9 %Nov 17 09:45:24:350 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions %Nov 17 09:45:17:315 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 12 %Nov 17 09:45:12:834 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 11 %Nov 17 09:44:55:163 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 in view system failed to be matched. %Nov 17 09:43:18:324 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command conf t in view system failed to be matched. %Nov 17 09:43:15:360 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is sys %Nov 17 09:43:10:945 2024 Hx-A7_2F_H3C LLDP/6/LLDP_CREATE_NEIGHBOR: Nearest bridge agent neighbor created on port GigabitEthernet1/0/2 (IfIndex 2), neighbor"s chassis ID is 244b-fe07-746f, port ID is 244b-fe07-746f. %Nov 17 09:42:34:429 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions %Nov 17 09:42:27:122 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 172.20.32.3. %Nov 17 09:41:52:849 2024 Hx-A7_2F_H3C IFNET/5/LINK_UPDOWN: Line protocol state on the interface GigabitEthernet1/0/9 changed to up. %Nov 17 09:41:52:847 2024 Hx-A7_2F_H3C IFNET/3/PHY_UPDOWN: Physical state on the interface GigabitEthernet1/0/9 changed to up. %Nov 17 09:38:07:466 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 192.168.2.6. %Nov 17 09:37:33:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally. %Nov 17 09:36:07:405 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 192.168.2.6. %Nov 17 09:36:01:421 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 172.20.32.3. %Nov 17 09:35:56:309 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/15-MACAddr=745d-229d-84b9-AccessVLANID=12-AuthorizatiOnVLANID=12-Username=term_a59f574f-931a-4f75-be5a-bde7663d9c6c; User passed 802.1X authentication and came online.

zhiliao_4jaxxE 发表时间:2天前
zhiliao_4jaxxE 知了小白
粉丝:0人 关注:0人

所有配置一致,同一个vlan,在该交换机接口上抓包显示,只有start报文,没回给pc


这是9口本机(745d-229d-84b9)点击客户端认证后交换机的提示的debugg信息 *Nov 17 10:09:43:241 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:446 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:43:743 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Aborting state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Initialize state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: PAE is in Disconnect state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:106 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: BE is in Idle state: UserMAC=9897-cc6c-ca02, VLANID=11, Interface=GigabitEthernet1/0/2. *Nov 17 10:09:45:107 2024 Hx-A7_2F_H3C DOT1X/7/EVENT: Interface GigabitEthernet1/0/2 received Set the port authorization status to unauthorized event. *Nov 17 10:09:48:508 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:48:804 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:49:065 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 *Nov 17 10:09:54:080 2024 Hx-A7_2F_H3C DOT1X/7/PACKET: Received a packet on interface GigabitEthernet1/0/9. Destination Mac Address=0180-c200-0003 Source Mac Address=745d-229d-84b9 Mac Frame Type=888e Protocol Version ID=1 Packet Type=1 Packet Length=0 undo de all All possible debugging has been turned off. <Hx-A7_2F_H3C>




日志信息如下172.20.32.3是本机ip地址,目前本机接的9口

Current messages: 303
%Nov 17 09:58:49:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally.
%Nov 17 09:57:56:433 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse
%Nov 17 09:57:45:073 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer reverse
%Nov 17 09:57:15:828 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis logbuffer
%Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C CFGMAN/5/CFGMAN_EXIT_FROM_CONFIGURE: -Line=vty0-IPAddr=172.20.32.3-User=admin; Exit from the system view or a feature view to the user view.
%Nov 17 09:57:05:819 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui
%Nov 17 09:56:59:601 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-AccessVLANID=11-AuthorizatiOnVLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726; User passed 802.1X authentication and came online.
%Nov 17 09:56:47:093 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is qui
%Nov 17 09:56:46:019 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command exi in view GigabitEthernet1/0/9 failed to be matched.
%Nov 17 09:49:53:830 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 11
%Nov 17 09:49:27:392 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi
%Nov 17 09:49:25:508 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo dot1x handshake
%Nov 17 09:48:47:430 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi
%Nov 17 09:48:45:700 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is port acc vlan 12
%Nov 17 09:48:40:669 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi
%Nov 17 09:48:39:064 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/9
%Nov 17 09:48:02:284 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi
%Nov 17 09:48:00:008 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int gi1/0/15
%Nov 17 09:47:40:362 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis thi
%Nov 17 09:47:39:309 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is int GigabitEthernet 1/0/9
%Nov 17 09:45:24:350 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions
%Nov 17 09:45:17:315 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 12
%Nov 17 09:45:12:834 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 vlan 11
%Nov 17 09:44:55:163 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command undo mac-address dynamic 745d-229d-84b9 int GigabitEthernet 1/0/15 in view system failed to be matched.
%Nov 17 09:43:18:324 2024 Hx-A7_2F_H3C SHELL/4/SHELL_CMD_MATCHFAIL: -User=admin-IPAddr=172.20.32.3; Command conf t in view system failed to be matched.
%Nov 17 09:43:15:360 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is sys
%Nov 17 09:43:10:945 2024 Hx-A7_2F_H3C LLDP/6/LLDP_CREATE_NEIGHBOR: Nearest bridge agent neighbor created on port GigabitEthernet1/0/2 (IfIndex 2), neighbor"s chassis ID is 244b-fe07-746f, port ID is 244b-fe07-746f.

%Nov 17 09:42:34:429 2024 Hx-A7_2F_H3C SHELL/6/SHELL_CMD: -Line=vty0-IPAddr=172.20.32.3-User=admin; Command is dis dot1x sessions
%Nov 17 09:42:27:122 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 172.20.32.3.
%Nov 17 09:41:52:849 2024 Hx-A7_2F_H3C IFNET/5/LINK_UPDOWN: Line protocol state on the interface GigabitEthernet1/0/9 changed to up.
%Nov 17 09:41:52:847 2024 Hx-A7_2F_H3C IFNET/3/PHY_UPDOWN: Physical state on the interface GigabitEthernet1/0/9 changed to up.
%Nov 17 09:38:07:466 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 192.168.2.6.
%Nov 17 09:37:33:106 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGOFF_ABNORMAL: -IfName=GigabitEthernet1/0/2-MACAddr=244b-fe07-746f-VLANID=11-Username=term_c60d6d57-e17d-4361-9825-b86b6660a726-ErrCode=9; 802.1X user was logged off abnormally.
%Nov 17 09:36:07:405 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGIN: admin logged in from 192.168.2.6.
%Nov 17 09:36:01:421 2024 Hx-A7_2F_H3C SHELL/5/SHELL_LOGOUT: admin logged out from 172.20.32.3.
%Nov 17 09:35:56:309 2024 Hx-A7_2F_H3C DOT1X/6/DOT1X_LOGIN_SUCC: -IfName=GigabitEthernet1/0/15-MACAddr=745d-229d-84b9-AccessVLANID=12-AuthorizatiOnVLANID=12-Username=term_a59f574f-931a-4f75-be5a-bde7663d9c6c; User passed 802.1X authentication and came online.


编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明