没有配置计费功能,只做认证。。。。。。。。。。
交换机配置dot1x认证后,802.1x客户端登录,RADIUS服务器回送AccessAccept允许入网命令,但是该端口依然无法入网。交换机配置大致如下:
domain default enable ***.***
dot1x
dot1x authentication-method eap
radius scheme radius1
server-type standard
primary authentication 192.168.1.92
key authentication testing123
timer response-timeout 5
retry 5
user-name-format without-domain
nas-ip 192.168.1.250
domain ***.***
scheme radius-scheme radius1
authentication radius-scheme radius1
端口配置如下:
inter Eth1/0/12
dot1x port-method portbased
dot1x
开启调试模式,查看radius packet.内容如下:
Warning: The current active Ip address of Radius Host[0.0.0.0] is wrong
Send accounting failed. But for essential accounting-mode, notify
radius packet 调式信息如下:
*0.3233616 H3C RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=EAP auth request Index = 19, ulParam3=2181204244] *0.3233724 H3C RDS/8/DEBUG:- 1 -Send attribute list: *0.3233773 H3C RDS/8/DEBUG:- 1 - [1 User-name ] [18] [48A0000000000002] [79 EAP-Message ] [23] [020100150134384130303030303030303030303032] [80 Message-Autheticator ] [18] [00000000000000000000000000000000] [4 NAS-IP-Address ] [6 ] [192.168.1.250] [32 NAS-Identifier ] [14] [000fe2216cc5] [5 NAS-Port ] [6 ] [268484609] *0.3234290 H3C RDS/8/DEBUG:- 1 - [61 NAS-Port-Type ] [6 ] [15] [6 Service-Type ] [6 ] [2] [7 Framed-Protocol ] [6 ] [1] [31 Caller-ID ] [16] [333465362D643733632D33383964] *0.3234573 H3C RDS/8/DEBUG:- 1 -Send: IP=[192.168.1.92], UserIndex=[19], ID=[38], RetryTimes=[0], Code=[1], Length=[139] *0.3234724 H3C RDS/8/DEBUG:- 1 -Send Raw Packet is: *0.3234773 H3C RDS/8/DEBUG:- 1 - 01 26 00 8b 0b 5c 00 00 d5 44 00 00 73 6c 00 00 e3 08 00 00 01 12 34 38 41 30 30 30 30 30 30 30 30 30 30 30 30 32 4f 17 02 01 00 15 01 34 38 41 30 30 30 30 30 30 30 30 30 30 30 30 32 50 12 3f 2b fb 43 3b ce d9 92 ea 38 bf 18 3e 8a c6 0b 04 06 c0 a8 01 fa 20 0e 30 30 30 66 65 32 32 31 36 63 63 35 05 06 10 00 c0 01 3d 06 00 00 00 0f 06 06 00 00 00 02 07 06 00 00 00 01 1f 10 33 34 65 36 2d 64 37 33 63 2d 33 38 39 64 *0.3235373 H3C RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=PKT response Index = 62, ulParam3=2181379444] *0.3235490 H3C RDS/8/DEBUG:- 1 -Receive Raw Packet is: *0.3235556 H3C RDS/8/DEBUG:- 1 - 0b 26 00 3e ef f9 5b de b5 6e b8 23 d6 76 ea fc 8f e7 fe f7 50 12 71 7f 66 a7 7a df 16 5a eb 45 13 6b 18 fe 76 d0 4f 18 01 02 00 16 04 10 30 31 32 33 30 31 32 33 34 35 36 37 38 39 31 32 *0.3235858 H3C RDS/8/DEBUG:- 1 -Receive:IP=[192.168.1.92],Code=[11],Length=[62] *0.3235956 H3C RDS/8/DEBUG:- 1 - [80 Message-Autheticator ] [18] [717F66A77ADF165AEB45136B18FE76D0] [79 EAP-Message ] [24] [01020016041030313233303132333435363738393132] *0.3236198 H3C RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=EAP auth request Index = 19, ulParam3=2181212500] *0.3236307 H3C RDS/8/DEBUG:- 1 -Send attribute list: *0.3236356 H3C RDS/8/DEBUG:- 1 - [1 User-name ] [18] [48A0000000000002] [79 EAP-Message ] [25] [020200170410F3AAD199A0643FC9D8FCB2177BED534E7A] [80 Message-Autheticator ] [18] [00000000000000000000000000000000] [4 NAS-IP-Address ] [6 ] [192.168.1.250] [32 NAS-Identifier ] [14] [000fe2216cc5] [5 NAS-Port ] [6 ] [268484609] *0.3236873 H3C RDS/8/DEBUG:- 1 - [61 NAS-Port-Type ] [6 ] [15] [6 Service-Type ] [6 ] [2] [7 Framed-Protocol ] [6 ] [1] [31 Caller-ID ] [16] [333465362D643733632D33383964] *0.3237156 H3C RDS/8/DEBUG:- 1 -Send: IP=[192.168.1.92], UserIndex=[19], ID=[39], RetryTimes=[0], Code=[1], Length=[141] *0.3237307 H3C RDS/8/DEBUG:- 1 -Send Raw Packet is: *0.3237357 H3C RDS/8/DEBUG:- 1 - 01 27 00 8d 74 4a 00 00 47 02 00 00 8a 43 00 00 ed 79 00 00 01 12 34 38 41 30 30 30 30 30 30 30 30 30 30 30 30 32 4f 19 02 02 00 17 04 10 f3 aa d1 99 a0 64 3f c9 d8 fc b2 17 7b ed 53 4e 7a 50 12 36 6a 64 06 3c 57 2d 9d ab 79 27 15 60 4b ed 00 04 06 c0 a8 01 fa 20 0e 30 30 30 66 65 32 32 31 36 63 63 35 05 06 10 00 c0 01 3d 06 00 00 00 0f 06 06 00 00 00 02 07 06 00 00 00 01 1f 10 33 34 65 36 2d 64 37 33 63 2d 33 38 39 64 *0.3237956 H3C RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=PKT response Index = 44, ulParam3=2181377620] *0.3238089 H3C RDS/8/DEBUG:- 1 -Receive Raw Packet is: *0.3238156 H3C RDS/8/DEBUG:- 1 - 02 27 00 2c 97 a7 ca 05 9b 75 6d 93 c6 5b 7e b0 f7 db 4b 7e 50 12 b1 0a 93 fc 6a 55 c9 4b 94 f0 cf 41 f7 27 05 aa 4f 06 03 03 00 04 *0.3238373 H3C RDS/8/DEBUG:- 1 -Receive:IP=[192.168.1.92],Code=[2],Length=[44] *0.3238474 H3C RDS/8/DEBUG:- 1 - [80 Message-Autheticator ] [18] [B10A93FC6A55C94B94F0CF41F72705AA] [79 EAP-Message ] [6 ] [03030004] *0.3238673 H3C RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=Account request Index = 19, ulParam3=0] *0.3238773 H3C RDS/8/DEBUG:- 1 -Send attribute list: *0.3238823 H3C RDS/8/DEBUG:- 1 - [1 User-name ] [18] [48A0000000000002] [32 NAS-Identifier ] [14] [000fe2216cc5] [5 NAS-Port ] [6 ] [268484609] [61 NAS-Port-Type ] [6 ] [15] [31 Caller-ID ] [16] [333465362D643733632D33383964] [40 Acct-Status-Type ] [6 ] [1] *0.3239273 H3C RDS/8/DEBUG:- 1 - [45 Acct-Authentic ] [6 ] [1] [44 Acct-Session-Id ] [16] [11000302004814] [4 NAS-IP-Address ] [6 ] [192.168.1.250] [55 Event-Timestamp ] [6 ] [954636534] *0.3239573 H3C RDS/8/DEBUG:- 1 -Warning: The current active Ip address of Radius Host [0.0.0.0] is wrong *0.3239690 H3C RDS/8/DEBUG:- 1 -Send accounting failed. But for essential accounting-mode, notify ACM accounting failed.
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论