我在使用咱么一款比较老的交换机做MAC地址认证实验,如下是交换机版本信息:
[H3C]display version
H3C Comware Platform Software
Comware Software, Version 3.10, Release 2108P04
Copyright (c) 2004-2009 Hangzhou H3C Technologies Co., Ltd. All rights reserved.
H3C S3100-26TP-SI uptime is 0 week, 0 day, 0 hour, 14 minutes
H3C S3100-26TP-SI with 1 Processor
64M bytes SDRAM
8M bytes Flash Memory
Config Register points to FLASH
在该交换机以太网接口1/0/12接口连接一台PC,并开启MAC地址认证。
[H3C]display domain test
The contents of Domain test:
State = Active
Scheme = Local
Authentication : RADIUS Scheme = freeradius
Access-limit = Disable
Vlan-assignment-mode = Integer
Domain User Template:
Idle-cut = Disable
Self-service = Disable
Messenger Time = Disable
[H3C]display radius scheme freeradius
SchemeName =freeradius Index=1 Type=standard
Primary Auth IP =192.168.1.111 Port=1812
Primary Acct IP =0.0.0.0 Port=1813
Second Auth IP =0.0.0.0 Port=1812
Second Acct IP =0.0.0.0 Port=1813
Auth Server Encryption Key= testing123
Acct Server Encryption Key= Not configured
Accounting method = required
Accounting-On packet disable, send times = 15 , interval = 3s
TimeOutValue(in second)=3 RetryTimes=5 RealtimeACCT(in minute)=12
Permitted send realtime PKT failed counts =5
Retry sending times of noresponse acct-stop-PKT =500
nas-ip:Source-IP-address =0.0.0.0
Quiet-interval(min) =5
Username format =without-domain
Data flow unit =Byte
Packet unit =1
calling_station_id format =XXXX-XXXX-XXXX in lowercase
unit 1 :
Primary Auth State=active, Second Auth State=block
Primary Acc State=block , Second Acc State=block
开启了全局MAC地址认证和接口MAC地址认证,freeRADIUS能够返回认证成功,但是交换机始终不能认证通过。


请问这是产品不支持FreeRADIUS吗?
(0)
你把交换机account去掉试试
应该和account没关系,可能是交换机比较老,所以在domain下添加 scheme radius-scheme freeradius命令就可以了
应该和account没关系,可能是交换机比较老,所以在domain下添加 scheme radius-scheme freeradius命令就可以了
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明