• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

WX2540X-LI Portal 认证失败

1天前提问
  • 0关注
  • 0收藏,41浏览
粉丝:0人 关注:0人

问题描述:

搭建FreeRadius 服务器读取AD域账号做portal认证失败。

1.在FreeRadius 服务器上使用radtest 命令,可以验证AD域账号信息。
2.在AC上运行dis radius scheme ,Radius 处于Active状态,


3.运行dis radius statistics,请求数有变化,
4.连接Wifi 信号可以正常跳转到验证页面,输入账号密码,显示认证失败。
求大佬指导下,怎么排错。

2 个回答
粉丝:101人 关注:8人

认证服务器上提示失败原因是什么?

radiusd服务器的log中没找到有验证的信息

zhiliao_UTbSgH 发表时间:1天前

感觉就像AC没有真正和Radius服务器建立连接。

zhiliao_UTbSgH 发表时间:1天前

debug看下吧

zhiliao_sEUyB 发表时间:1天前

应该使用哪个debug命令

zhiliao_UTbSgH 发表时间:1天前

radius和portal认证的

zhiliao_sEUyB 发表时间:1天前

我截取了一部分日志在下面,帮忙看一下。

zhiliao_UTbSgH 发表时间:1天前
zhiliao_UTbSgH 知了小白
粉丝:0人 关注:0人

*Jul 18 16:07:28:896 2024 WX2540X-LI PORTAL/7/RULE:

 [Outbound] permit the packet on the outbound {MatchRes = [Rule1-Permit]}.

 L3 Interface = WLAN-BSS1/0/349, L2 Interface = WLAN-BSS1/0/349, VLAN = 98, DstMac = 64d6-9ae8-e7fc,

 SrcIP = 172.16.1.20, DstIP = 192.168.98.25

 Protocol = 6, SrcPort = 80, DstPort = 10788, VPN Instance = 0

 

*Jul 18 16:07:28:905 2024 WX2540X-LI PORTAL/7/EVENT: Received a new user request connection

*Jul 18 16:07:28:905 2024 WX2540X-LI PORTAL/7/EVENT: Received HTTP POST method packet.

*Jul 18 16:07:28:905 2024 WX2540X-LI PORTAL/7/EVENT: Request for /portal/logon.cgi.

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Success to get ssid by user mac, ssid:H3C-G-EAA9D0, user MAC:64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option info from IPCIM, user IP=192.168.98.25, user MAC=64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option55 from DHCP option55:1,3,6,15,31,33,43,44,46,47,119,121,249,252,len:14, user IP-192.168.98.25, user MAC=64-D6-9A-E8-E7-FC

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option info from IPCIM, user IP=192.168.98.25, user MAC=64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option55 from DHCP option55:1,3,6,15,31,33,43,44,46,47,119,121,249,252,len:14, user IP-192.168.98.25, user MAC=64-D6-9A-E8-E7-FC

*Jul 18 16:07:28:906 2024 WX2540X-LI PORTAL/7/EVENT: Extend-auth: A New Connection has been added to hash. User IP=192.168.98.25.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get ap mac by user mac, ap mac: 14-84-77-9B-C5-60, user MAC: 64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get ssid by user mac, ssid:H3C-G-EAA9D0, user MAC:64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option info from IPCIM, user IP=192.168.98.25, user MAC=64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option55 from DHCP option55:1,3,6,15,31,33,43,44,46,47,119,121,249,252,len:14, user IP-192.168.98.25, user MAC=64-D6-9A-E8-E7-FC

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option info from IPCIM, user IP=192.168.98.25, user MAC=64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option12 from DHCP option12:65,65,48,49,50,51,48,54,48,48,48,51,45,76,80,len:15, user IP-192.168.98.25, user MAC=64-D6-9A-E8-E7-FC

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option info from IPCIM, user IP=192.168.98.25, user MAC=64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: Success to get option60 from DHCP option60:77,83,70,84,32,53,46,48,len:8, user IP-192.168.98.25, user MAC=64-D6-9A-E8-E7-FC

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/EVENT: User-SM[192.168.98.25]: Notified Auth-SM to process the REQ_AUTH packet.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/FSM: Auth-SM: Started to run.

*Jul 18 16:07:28:907 2024 WX2540X-LI PORTAL/7/FSM: Auth-SM [192.168.98.25]: Entered state Authenticating.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

PAM_RADIUS: Processing RADIUS authentication.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

PAM_RADIUS: Sent authentication request successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI PORTAL/7/EVENT: User-SM[192.168.98.25]: AAA processed authentication request and returned processing.

*Jul 18 16:07:28:908 2024 WX2540X-LI PORTAL/7/EVENT: Success to get ap mac by user mac, ap mac: 14-84-77-9B-C5-60, user MAC: 64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:908 2024 WX2540X-LI PORTAL/7/EVENT: Success to get ssid by user mac, ssid:H3C-G-EAA9D0, user MAC:64-D6-9A-E8-E7-FC.

*Jul 18 16:07:28:908 2024 WX2540X-LI PORTAL/7/FSM: User-SM[192.168.98.25]: Begin to run.

*Jul 18 16:07:28:908 2024 WX2540X-LI PORTAL/7/FSM: User-SM [192.168.98.25]: State changed from Initial to Authenticating.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Processing AAA request data.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Got request data successfully, primitive: authentication.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Getting RADIUS server info.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Got RADIUS server info successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Created request context successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Created request packet successfully, dstIP: 192.168.98.12, dstPort: 1812, VPN instance: --(public), socketFd: 111, pktID: 87.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Added packet socketfd to epoll successfully, socketFd: 111.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Mapped PAM item to RADIUS attribute successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Got RADIUS username format successfully, format: 1.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Added attribute user-name successfully, user-name: x00054@system.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Filled RADIUS attributes in packet successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Composed request packet successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/EVENT:

Created response timeout timer successfully.

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/PACKET:

    User-Name="x00054@system"

    User-Password=******

    Service-Type=Framed-User

    Framed-Protocol=255

    NAS-Identifier="WX2540X-LI"

    NAS-Port=16777314

    NAS-Port-Type=Wireless-802.11

    NAS-Port-

    Calling-Station-

    Called-Station-

    Acct-Session-

    H3c-User-Vlan-Id=98

    Framed-IP-Address=192.168.98.25

    H3c-Ip-Host-Addr="192.168.98.25 64:d6:9a:e8:e7:fc"

    H3c_DHCP_OPTION55=0x0103060f1f212b2c2e2f7779f9fc

    H3C-DHCP-Option=0x370e0103060f1f212b2c2e2f7779f9fc

    H3C-DHCP-Option=0x0c0f4141303132333036303030332d4c50

    H3C-DHCP-Option=0x3c084d53465420352e30

    H3C-MAC-Proxy-Authenticator=******

*Jul 18 16:07:28:908 2024 WX2540X-LI RADIUS/7/PACKET:

    NAS-IP-Address=192.168.98.24

    H3c-Product-

    H3c-Nas-Startup-Timestamp=1700903682

*Jul 18 16:07:28:909 2024 WX2540X-LI RADIUS/7/EVENT:

Sent request packet successfully, dst-IP: 192.168.98.12, code: 1, length: 408.

*Jul 18 16:07:28:909 2024 WX2540X-LI RADIUS/7/PACKET:

 01 57 01 98 e5 3e fa ea 56 72 fa 8b 09 51 a9 b6

 1d 35 30 4f 01 0f 78 30 30 30 35 34 40 73 79 73

 74 65 6d 02 12 57 30 ff 8a 85 be ad 3b c9 24 84

 98 ba af 65 80 06 06 00 00 00 02 07 06 00 00 00

 ff 20 0c 57 58 32 35 14 30 58 2d 4c 49 05 06 01

 00 00 62 3d 06 00 00 00 13 57 12 30 31 30 30 30

 30 30 30 30 30 30 30 30 30 39 38 1f 13 36 34 2d

 44 36 2d 39 41 2d 45 38 2d 45 37 2d 46 43 1e 20

 31 34 2d 38 34 2d 37 37 2d 39 4d 2d 43 35 2d 36

 30 3a 48 33 43 2d 47 2d 45 41 41 39 44 30 2c 28

 30 30 30 30 30 30 30 37 32 30 32 34 30 37 31 38

 30 38 30 37 32 38 30 30 30 30 30 30 65 37 30 38

 31 32 39 32 30 36 1a 0c 00 00 63 a2 85 06 00 00

 00 62 08 06 c0 a8 62 19 1a 27 00 00 63 a2 3c 21

 31 39 32 2e 31 36 38 2e 39 38 2e 32 35 20 36 34

*Jul 18 16:07:28:909 2024 WX2540X-LI RADIUS/7/PACKET:

 3a 64 36 3a 39 61 3a 65 38 3a 65 37 3a 66 63 1a

 16 00 00 63 a2 d0 10 01 03 06 0f 1f 21 2b 2c 2e

 2f 77 79 f9 fc 1a 18 00 00 63 a2 da 12 37 0e 01

 03 06 0f 1f 21 2b 2c 2e 2f 77 79 f9 fc 1a 19 00

 00 63 a2 da 13 0c 0f 41 41 30 31 32 33 30 36 30

 30 30 33 2d 4c 50 1a 12 00 00 63 a2 da 0c 3c 08

 4d 53 46 54 20 35 2e 30 1a 18 00 00 63 a2 96 12

 57 01 a3 8d 81 be c6 56 85 6d 84 98 ba af 65 80

 04 06 c0 a8 62 18 1a 16 00 00 63 a2 ff 10 48 33

 43 20 57 58 32 35 34 30 58 2d 4c 49 1a 0c 00 00

 63 a2 3b 06 65 61 bb 02

*Jul 18 16:07:28:909 2024 WX2540X-LI RADIUS/7/EVENT:

Sent request packet and create request context successfully.

*Jul 18 16:07:28:909 2024 WX2540X-LI RADIUS/7/EVENT:

Added request context to global table successfully.

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/RULE:

 [Inbound] execute full rule match, { MatchRes = [Rule3-Redirect] }

 L3 Interface = WLAN-BSS1/0/349, L2 Interface = WLAN-BSS1/0/349, VLAN = 98, SrcMac = 64d6-9ae8-e7fc,

 SrcIP = 192.168.98.25, DstIP = 104.46.162.227

 Protocol = 6, SrcPort = 10789, DstPort = 443, VPN Instance = 0

 

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/HTTP_REDIRECT-EVENT:  Receive the packet(flag:0x2,datalen:0,srcIP:192.168.98.25,dstIP:104.46.162.227,seq:0x236593d7,ack:0x0,dataLen:0, sport:10789, dport:443)

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/HTTP_REDIRECT-EVENT:  create the redirect node successfully.

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/HTTP_REDIRECT-EVENT: Append tcp reply mbuf, mss=1200 len=24 seq=4a9f8 ack=236593d8.

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/HTTP_REDIRECT-EVENT: Compose tcp cheat pkt(flag:0x2) successfully.

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/HTTP_REDIRECT-EVENT: Reply tcp cheat pkt(flag:0x2) successfully.

*Jul 18 16:07:29:388 2024 WX2540X-LI PORTAL/7/RULE:

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明