Solved

Cisco 3548 XL

Posted on 2013-01-06
13
495 Views
Last Modified: 2013-03-01
Hi,

I have setup Radius Authentication but when I try to encrypt the password it fails to
Authenticate,

With the following.

radius-server host 10.42.7.110 auth-port 1645 acct-port 1646 key thispassword

The user account logons without any problems.

But when I encrypt the password.

radius-server host 10.42.7.110 auth-port 1645 acct-port 1646 key 7 *****

It fails to authenticate.

Am I missing something or is there any easier way ?  Its only the 3548-XL I have this problem on.

Thanks in advance,
0
Comment
Question by:Mongo Peck
  • 6
  • 4
  • 2
  • +1
13 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 38749325
Can you point out where you can use a encrypted key for RADIUS?  I have alway just specified "key value"  and I checked a few places and don't seem to see anything that says you can do "key 7 encryptedvalue".
0
 
LVL 5

Expert Comment

by:Leeeee
ID: 38749331
It seems like the following may be your issue. When you specify an encrypted key with '7', you need to paste a encrypted key, not the plain text key that you're expecting to be encrypted because you use a 7.

What you're looking for and what will work, is pasting the key with the following syntax:

radius-server host 10.42.7.110 auth-port 1645 acct-port 1646 key 0 ciscokey (plain text)

Service password-encryption (this will disguise the key in the config with random hash)

Now the key will be encrypted in the config.

If you have a legit encrypted key that looks like , 07AfeR20AbC, then you would use the 7 and paste the encrypted key. Hope this helps you.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 38749355
Yes,  Leeeee is correct.  If radius-server key supports accepts encrypted keys, then the value after the 7 must be the encrypted value.  

However, that would only be used if you don't know what the clear text value is and you have saved the encrypted value.  IOS will store any key values encrypted once you specify service password-encryption.
0
 

Author Comment

by:Mongo Peck
ID: 38749455
Hi,

When using the key 7 I am using an encrypted value which instantly stops radius
from working.  

When I use Service password-encryption the AAA password remains plain text in the
config.

Its only the 3458-XL thats having a problem all other 2900's etc take the config without
any errors,  This switch also doesn't support ssh.

This is the version c3500XL-c3h2s-mz.120-5.WC5.bin
0
 
LVL 57

Expert Comment

by:giltjr
ID: 38749505
The most recent level of code for the 3548XL is c3500xl-c3h2s-mz.120-5.WC17.bin.
0
 

Author Comment

by:Mongo Peck
ID: 38749523
The most recent level of code for the 3548XL is c3500xl-c3h2s-mz.120-5.WC17.bin

Cause the switch to randomly to reboot.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Author Comment

by:Mongo Peck
ID: 38749544
When I use Service password-encryption the AAA password remains plain text in the
config.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 38750613
We have 2 3548's left.  One is running c3550-ipservicesk9-mz.122-25.SEC.bin and the other  c3500xl-c3h2s-mz.120-5.WC17.bin.

Both show the passwords encrypted.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 38751332
Whoa, the one running c3550-ipservicesk9-mz.122-25.SEC.bin is surely not a c3548-XL... :)
0
 
LVL 57

Accepted Solution

by:
giltjr earned 500 total points
ID: 38751367
Opps, my fault, its not.  We apparently replaced the 3548 with a 3550 and somebody didn't update the doc.  Didn't even thing about it when I did the show ver.

So our ONLY 3548 left is running  c3500xl-c3h2s-mz.120-5.WC17.bin.
0
 

Author Comment

by:Mongo Peck
ID: 38753922
Is there some 3548 hardware versions that cannot support later IOS.
These switches run c3500xl-c3h2s-mz.120-5.WC5.bin without any problems.

As soon as I replace this with c3500xl-c3h2s-mz.120-5.WC17.bin they randomly crash
constantly.
0
 
LVL 17

Expert Comment

by:TimotiSt
ID: 38754194
I do remember something faint about different memory size (4M/8M?), but that may have been the 2900XL series...

Check the MD5 of your .WC17 image, make sure it's not corrupt? Possibly format the flash of the switch before uploading new image?
0
 
LVL 57

Expert Comment

by:giltjr
ID: 38754517
Just checked and 12.0(5)WC17 is supposed to be able to run on 3500 XL switches with 8MB of DRAM, which is the minimum that a 3548XL is supposed to have.  Ours has 16MB.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
USB Hub for apple devices 5 35
policy routing to fw2 18 52
Connecting to CISCO 4402 WLC 3 11
CISCO Smartnet agreement 5 8
I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now