无
某局点使用了我司S5850-54QS作为汇聚交换机,出于安全性考虑只开启了SSH登入,并且是结合IMC做的认证,配置完成之后,发现终端无法SSH设备,但是如果使用本地用户认证是可以登入成功的,所以SSH的配置应该没问题,怀疑是IMC侧问题导致。
通过本地用户登入正常,结合IMC登入不正常,怀疑是AAA或者IMC侧问题导致,让客户在SSH登入的时候,收集debug信息反馈。
关键debug信息:
*Aug 14 09:55:02:837 2020 ShaoXingZH-S5850-IRF RADIUS/7/PACKET:
04 ac 00 b6 0e de 1e 79 b9 59 e7 89 ce d5 b0 4f
12 6b a2 e3 01 0e 68 75 61 77 65 69 40 74 6a 62
68 62 20 16 53 68 61 6f 58 69 6e 67 5a 48 2d 53
35 38 35 30 2d 49 52 46 08 06 14 65 9e 87 1f 10
32 30 2e 31 30 31 2e 31 35 38 2e 31 33 35 3d 06
00 00 00 05 2c 28 30 30 30 30 30 30 30 31 32 30
32 30 30 38 31 34 30 31 35 35 30 32 30 30 30 30
30 30 30 31 30 38 31 32 34 30 34 31 04 06 0a f0
00 01 28 06 00 00 00 01 29 06 00 00 00 00 37 06
5f 35 ee f6 1a 16 00 00 63 a2 ff 10 48 33 43 20
53 35 38 35 30 2d 35 34 51 53 1a 0c 00 00 63 a2
3b 06 4d 1e 6e 87
*Aug 14 09:55:02:837 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Sent request packet and create request context successfully.
*Aug 14 09:55:02:837 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Added request context to global table successfully.
*Aug 14 09:55:02:838 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Processing AAA request data.
*Aug 14 09:55:06:822 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Response timed out.
*Aug 14 09:55:06:822 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Found request context, dstIP: x.x.x.x; dstPort: 1813; VPN instance: --(public); socketfd: 50; pktID:172.
*Aug 14 09:55:06:822 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Retransmitting request packet, currentTries: 2, maxTries: 2.
*Aug 14 09:55:09:822 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Response timed out.
*Aug 14 09:55:09:827 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Found request context, dstIP: ; dstPort: 1813; VPN instance: --(public); socketfd: 50; pktID:172.
*Aug 14 09:55:09:828 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Reached the maximum retries.
*Aug 14 09:55:09:828 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Set status of server to block successfully. serverIP: serverPort: 1813.
*Aug 14 09:55:09:828 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Got next server failed.
*Aug 14 09:55:09:828 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Received status of server changing event.
*Aug 14 09:55:09:828 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Sent reply error message to PAM.
*Aug 14 09:55:09:829 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: PAM_RADIUS: Fetched accounting-start reply-data successfully, resultCode: 3
*Aug 14 09:55:09:829 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: PAM_RADIUS: Received accounting-start reply message, resultCode: 3
*Aug 14 09:55:09:829 2020 ShaoXingZH-S5850-IRF RADIUS/7/EVENT: Sent reply message successfully.
%Aug 14 09:55:09:834 2020 ShaoXingZH-S5850-IRF LOGIN/5/LOGIN_FAILED: failed to log in from
通过debug信息发现认证是成功的,但是计费失败了,怀疑是计费有问题,查看设备配置,发现没有配置radius 计费密钥,最终导致计费失败。
radius scheme bhbank
primary authentication x.x.x.x
primary accounting x.x.x.x
key authentication cipher $c$3$dXeI4iaA0YIRLjC1Fwb5xC7Uj/GRjmGRJD/q0jI=
nas-ip interface Vlan-interface10
设备上再加上radius 计费密钥的配置之后,问题解决。
key accounting simple xxx
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作