Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

Troubleshooting
Research
Professional Opinions
Ask a Question
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

troubleshooting Question

Problem with 802.1X and 3Com 5500G

Avatar of markholmes24
markholmes24 asked on
NetworkingNetworking Hardware-OtherSwitches / Hubs
3 Comments1 Solution2199 ViewsLast Modified:
I'm trying to set up a 3Com 5500G to authenticate connections via RADIUS.

I have configured it to use mac authentication, so when a machine is plugged in the port sends the connected NICS MAC address as username and password, to a RADIUS server (I'm using IAS in Windows 2008 - now called something different)

The RADIUS server authenticates against AD, if there is an account found for the connecting machine it allows connection and then should return a VLAN to the switch to put the port into based on AD Group membership.

If auth fails, the switch puts the port into a Guest VLAN.

When I test this, the log on the server shows RADIUS authenticates the connection and records a sucessfull logon, but this is immediately followed by a logoff event

The switch logs an authentication failure - see below

It looks to me like the RADIUS server is returning a NULL response to the switch?  Why could this be?

*0.427711560 5500G-EI MACAUTH/8/EVENT:- 1 -Port:0,MAC authentication new mac is: 001c-2315-56ca, vlan:1.r
*0.427711682 5500G-EI MACAUTH/8/EVENT:- 1 -Port:0,MAC authenticaiton: excute MAC_AddressLearn...a
*0.427711802 5500G-EI MACAUTH/8/EVENT:- 1 -Port:0,new mac address 001c-2315-56ca , vlan 1.d
*0.427711912 5500G-EI MACAUTH/8/EVENT:- 1 -Auth:1058,Processing  InitTrans!i
*0.427712002 5500G-EI MACAUTH/8/EVENT:- 1 -Auth:1058,Processing node CONNECTING...u
*0.427712103 5500G-EI RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=Normal auth request Index = 1058, ulParam3=2214909604]s
*0.427712246 5500G-EI RDS/8/DEBUG:- 1 -Send attribute list:
*0.427712312 5500G-EI RDS/8/DEBUG:- 1 -
[1  User-name                   ] [28] [001c231556ca@netauth.local]
[2  Password                    ] [18] [FFEEF390AC4963F6684FC39313DB8AEA]
[4  NAS-IP-Address              ] [6 ] [192.168.99.50]
[32 NAS-Identifier              ] [14] [001ec178cc82]
[5  NAS-Port                    ] [6 ] [16781313]
[61 NAS-Port-Type               ] [6 ] [15]schem
*0.427712802 5500G-EI RDS/8/DEBUG:- 1 -
[6  Service-Type                ] [6 ] [2]
[7  Framed-Protocol             ] [6 ] [1]
[31 Caller-ID                   ] [16] [303031632D323331352D35366361]e
*0.427713054 5500G-EI RDS/8/DEBUG:- 1 -Send: IP=[192.168.99.1], UserIndex=[1058], ID=[247], RetryTimes=[0], Code=[1], Length=[126]
*0.427713223 5500G-EI RDS/8/DEBUG:- 1 -Send Raw Packet is:
*0.427713293 5500G-EI RDS/8/DEBUG:- 1 -
 01 f7 00 7e 00 00 18 de 00 00 17 69 00 00 41 69
 00 00 66 d4 01 1c 30 30 31 63 32 33 31 35 35 36
 63 61 40 6e 65 74 61 75 74 68 2e 6c 6f 63 61 6c
 02 12 ff ee f3 90 ac 49 63 f6 68 4f c3 93 13 db
 8a ea 04 06 c0 a8 63 32 20 0e 30 30 31 65 63 31
 37 38 63 63 38 32 05 06 01 00 10 01 3d 06 00 00
 00 0f 06 06 00 00 00 02 07 06 00 00 00 01 1f 10
 30 30 31 63 2d 32 33 31 35 2d 35 36 63 61
 
*0.427713842 5500G-EI RDS/8/DEBUG:- 1 -Recv MSG,[MsgType=PKT response Index = 20, ulParam3=2215056340]
*0.427713972 5500G-EI RDS/8/DEBUG:- 1 -Receive Raw Packet is:
*0.427714042 5500G-EI RDS/8/DEBUG:- 1 -
 03 f7 00 14 bb 5e e0 f0 a1 2c d5 4d 95 aa 42 e0
 6c 51 8a a4
 
*0.427714172 5500G-EI RDS/8/DEBUG:- 1 -Receive:IP=[192.168.99.1],Code=[3],Length=[20]
*0.427714281 5500G-EI RDS/8/DEBUG:- 1 -NULL
*0.427714322 5500G-EI RDS/8/DEBUG:- 1 -RejectMsg=[Rejected by RADIUS server without any message ]
*0.427714443 5500G-EI MACAUTH/8/EVENT:- 1 -Auth:0,
 MacGuestVlanId = 0, MacGuestVlanCfg = 0, MacAuthCount = 1
*0.427714582 5500G-EI MACAUTH/8/EVENT:- 1 -Auth:1058,Processing CONNECTING Trans!
*0.427714692 5500G-EI MACAUTH/8/EVENT:- 1 -Auth:1058,Processing node FAILURE...


 
ASKER CERTIFIED SOLUTION
Avatar of markholmes24
markholmes24

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Commented:
This problem has been solved!
Unlock 1 Answer and 3 Comments.
See Answers