• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

10510+radius 认证失败

2021-06-13提问
  • 1关注
  • 1收藏,2339浏览
粉丝:0人 关注:0人

问题描述:

登录设备使用radius服务器验证失败,debugg输出如下信息,请大佬帮忙看下怎么个排查思路?

For radius

 

When customer try to login switch via radius  then we receive below debug messages

 

<KHI-CE-H3C-S10510X-B1>

<KHI-CE-H3C-S10510X-B1>%Jun 12 20:30:27:031 2021 KHI-CE-H3C-S10510X-B1 SNMP/6/SNMP_NOTIFY: -MDC=1; Notification hh3cPeriodicalTrap(1.3.6.1.4.1.25506.2.38.1.6.3.0.1).

*Jun 12 20:30:31:837 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; PAM_RADIUS: Processing RADIUS authentication.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; PAM_RADIUS: Sent authentication request successfully.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Processing AAA request data.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Got request data successfully, primitive: authentication.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Getting RADIUS server info.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Got RADIUS server info successfully.

*Jun 12 20:30:31:838 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Created request context successfully.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Created request packet successfully, dstIP: 10.31.229.12, dstPort: 1812, VPN instance: --(public), socketFd: 28, pktID: 89.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Added packet socketfd to epoll successfully, socketFd: 28.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Mapped PAM item to RADIUS attribute successfully.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Got RADIUS username format successfully, format: 2.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Added attribute user-name successfully, user-name: asif.m.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Filled RADIUS attributes in packet successfully.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Composed request packet successfully.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Created response timeout timer successfully.

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/PACKET: -MDC=1;

    User-Name="asif.m"

    NAS-Identifier="KHI-CE-H3C-S10510X-B1"

    Framed-IP-Address=10.31.225.29

    Calling-Station-

    H3C-NAS-Port-Name="LoopBack1"

    NAS-Port-Type=Virtual

    User-Password=**

    Acct-Session-

    Service-Type=Login-User

    NAS-IP-Address=10.31.18.79

    H3c-Product-

    H3c-Nas-Startup-Timestamp=1623412476

*Jun 12 20:30:31:840 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Sent request packet successfully.

*Jun 12 20:30:31:841 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/PACKET: -MDC=1;

01 59 00 c3 23 14 44 7b 9f a7 d1 4a 6c 1a e4 7f

5d b2 e8 47 01 08 61 73 69 66 2e 6d 20 17 4b 48

49 2d 43 45 2d 48 33 43 2d 53 31 30 35 31 30 58

2d 42 31 08 06 0a 1f e1 1d 1f 0e 31 30 2e 33 31

2e 32 32 35 2e 32 39 1a 11 00 00 63 a2 e6 0b 4c

6f 6f 70 42 61 63 6b 31 3d 06 00 00 00 05 02 12

e4 6d 47 26 ce 8b 84 3a a8 93 ad c5 e2 67 77 34

2c 28 30 30 30 30 30 30 30 31 32 30 32 31 30 36

31 32 31 35 33 30 33 31 30 30 30 30 30 30 30 32

38 30 31 30 35 31 30 35 06 06 00 00 00 01 04 06

0a 1f 12 4f 1a 13 00 00 63 a2 ff 0d 48 33 43 20

53 31 30 35 31 30 58 1a 0c 00 00 63 a2 3b 06 60

c3 4e fc

*Jun 12 20:30:31:841 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Sent request packet and create request context successfully.

*Jun 12 20:30:31:841 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Added request context to global table successfully.

*Jun 12 20:30:31:841 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Processing AAA request data.

*Jun 12 20:30:31:879 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Reply SocketFd recieved EPOLLIN event.

*Jun 12 20:30:31:879 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Received reply packet succuessfully.

*Jun 12 20:30:31:879 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Found request context, dstIP: 10.31.229.12, dstPort: 1812, VPN instance: --(public), socketFd: 28, pktID: 89.

*Jun 12 20:30:31:879 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/ERROR: -MDC=1; Reply packet: Invalid packet authenticator.

*Jun 12 20:30:31:879 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/ERROR: -MDC=1; The reply packet is invalid.

*Jun 12 20:30:35:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Response timed out.

*Jun 12 20:30:35:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Found request context, dstIP: 10.31.229.12; dstPort: 1812; VPN instance: --(public); socketfd: 28; pktID:89.

*Jun 12 20:30:35:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Retransmitting request packet, currentTries: 2, maxTries: 3.

*Jun 12 20:30:38:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Response timed out.

*Jun 12 20:30:38:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Found request context, dstIP: 10.31.229.12; dstPort: 1812; VPN instance: --(public); socketfd: 28; pktID:89.

*Jun 12 20:30:38:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Retransmitting request packet, currentTries: 3, maxTries: 3.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Response timed out.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Found request context, dstIP: 10.31.229.12; dstPort: 1812; VPN instance: --(public); socketfd: 28; pktID:89.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Reached the maximum retries.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Set status of server to block successfully. serverIP: 10.31.229.12, serverPort: 1812.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Got next server failed.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Sent reply error message to PAM.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Received status of server changing event.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; Sent reply message successfully.

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; PAM_RADIUS: Fetched authentication reply-data successfully, resultCode: 3

*Jun 12 20:30:41:150 2021 KHI-CE-H3C-S10510X-B1 RADIUS/7/EVENT: -MDC=1; PAM_RADIUS: Received authentication reply message, resultCode: 3

 

<KHI-CE-H3C-S10510X-B1>

组网及组网描述:

2 个回答
粉丝:14人 关注:0人

交换机向服务器发送了radius请求报文,没有收到服务器回应,建议排查下radius服务器

暂无评论

粉丝:133人 关注:6人

您好,请知:
radius认证失败,以下是排查要点,请参考:
1.检查交换机到radius服务器路由是否可达。
2.检查交换机到radius服务器的指向、密钥和domain的调用。
3.检查radius服务器的配置。

暂无评论

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明