交换机是S5560,客户端是win10+iNode7.3,交换机可以读取user信息,但验证失败,提示ErrCode=8。
配置如下:
[Core_SW]dis cur
#
dot1x
#
interface GigabitEthernet1/0/3
port access vlan 20
stp edged-port
dot1x
#
domain system
authentication lan-access local
authorization lan-access local
accounting lan-access local
#
domain default enable system
#
local-user test class network
password cipher $c$3$rPs7cArO5ZceaH2FVzU6PbNWJB+Hh3gpRls=
service-type lan-access
authorization-attribute user-role network-operator
#
=====================================================
debugging dot1x all,全部的debug信息显示如下:
*Dec 13 14:44:09:881 2019 Core_SW DOT1X/7/PACKET:
Transmitted a packet on interface GE1/0/3.
---Verbose information of the packet---
Destination Mac Address: f439-0924-0aa9
Source Mac Address: 9ce8-95d1-a74c
VLAN ID: 20
Mac Frame Type: 888e
Protocol Version ID: 1
Packet Type: 0
Packet Length: 22
-----Packet Body-----
Code: 1
Identifier: 2
Length: 5632
*Dec 13 14:44:09:896 2019 Core_SW DOT1X/7/PACKET:
Received a packet on interface GE1/0/3.
---Verbose information of the packet---
Destination Mac Address: 9ce8-95d1-a74c
Source Mac Address: f439-0924-0aa9
Mac Frame Type: 888e
Protocol Version ID: 1
Packet Type: 0
Packet Length: 26
-----Packet Body-----
Code: 2
Identifier: 2
Length: 26
*Dec 13 14:44:09:896 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] BE is in Response state.
*Dec 13 14:44:09:897 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] Created server timeout timer successfully.
*Dec 13 14:44:09:905 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] User sent authentication request.
%Dec 13 14:44:09:908 2019 Core_SW DOT1X/6/DOT1X_LOGIN_FAILURE: -IfName=GigabitEthernet1/0/3-MACAddr=f439-0924-0aa9-VLANID=20-Username=test-ErrCode=8; User failed 802.1X authentication.
*Dec 13 14:44:09:910 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:20:GE1/0/3] AAA processed authentication request and returned Failure code 26.
*Dec 13 14:44:09:911 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] BE is in Fail state.
*Dec 13 14:44:09:913 2019 Core_SW DOT1X/7/PACKET:
Transmitted a packet on interface GE1/0/3.
---Verbose information of the packet---
Destination Mac Address: f439-0924-0aa9
Source Mac Address: 9ce8-95d1-a74c
VLAN ID: 20
Mac Frame Type: 888e
Protocol Version ID: 1
Packet Type: 0
Packet Length: 4
-----Packet Body-----
Code: 4
Identifier: 2
Length: 1024
*Dec 13 14:44:09:914 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] PAE is in Aborting state.
*Dec 13 14:44:09:914 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] BE is in Initialize state.
*Dec 13 14:44:09:914 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] PAE is in Disconnect state.
*Dec 13 14:44:09:915 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] BE is in Idle state.
*Dec 13 14:44:09:915 2019 Core_SW DOT1X/7/EVENT: PORT_SM[GE1/0/3] received event Set the port authorization status to unauthorized..
*Dec 13 14:44:09:917 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] Processing the event of AuthenFail.
*Dec 13 14:44:09:917 2019 Core_SW DOT1X/7/EVENT: [f439-0924-0aa9:VLAN20:GE1/0/3] Notified PortSec of AuthenFail result: 2
##########
dot1x authentication-method {pap | chap | eap} 都试过了。
麻烦各位老大帮忙看看还是哪些地方没有设置,非常感谢!
(0)
最佳答案
 
	 
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论