Solved

No radius logs ACS 5.2

Posted on 2014-02-17
5
467 Views
Last Modified: 2014-02-20
Hello all!

I have a testbed set up for 802.1x authentication between an ACS 5.2 server with the radius
protocol enabled..."Identity stores", "Resource network devices" and "Shared secret key".
The 3750 has the  "bare bones" configs...AAA new model, shared key and the radius server
IP address.
The switch interface is configured for monitor mode..."authentication open".
I am able to ping the ACS from the switch, but when I connect a PC to the switch port
it shuts down!!  Also, there are no radius logs ont the ACS to evaluate the issue.

It seems to be ovious that the switch and ACS are not communicating.
What do I need to do get the ACS radius server to generate radius logs?
I will work on the authentication issue later down the road.  For now I just want the switch
and the ACS 5.2 server to communicate.

Thanks in advance!

Ray
0
Comment
Question by:Rayneedssomehelp
  • 3
  • 2
5 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39866836
Can you post a switch config?
0
 

Author Comment

by:Rayneedssomehelp
ID: 39867326
Hello,

The configs on the switch were configured by one of the techs here.  There is a lot of junk
on it that does not need to be on it, such as the load balancing configs.  I did not want to make any changes to the configs until I checked with the experts first.


As I stated, right now I am more concerned with just getting the ACS radius server
to communicate with the switch, so that I can view the radius logs.

I do understand that in order for the authentication to be successful I need the ACS
configured properly also.  That being said, I would like to take one step at a time
to try and resolve our issues with the deployment.  First:ACS\switch radius communcation!
Second:Authentication.




aaa new-model
!
!
aaa group server radius radus-pri
!
aaa group server radius radius-log
 server xxx.xxx.xxx.xxx
 server xxx.xxx.xxx.xxx
!
aaa group server radius radius-pri
 server xxx.xxx.xxx.xxx
!
aaa group server radius raqdius-sec
 server xxx.xxx.xxx.xxx

aaa authentication login default group tacacs+ local
aaa authentication login list-name group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authentication dot1x default group radius-pri group radius-sec
aaa authorization network default group radius-pri group radius-sec
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
!
dot1x system-auth-control


interface GigabitEthernet3/0/11
 switchport access vlan xxx
 switchport mode access
 switchport nonegotiate
 authentication open
 dot1x pae authenticator
 spanning-tree portfast


Thanks,

Ray
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39867392
That's a good plan - you can't test authentication if the ACS/switch link doesn't work.

So, you're missing some configuration...

radius-server host 1.2.3.4 auth-port 1645 acct-port 1646 key <SHAREDSECRET>

Open in new window


...one per RADIUS server.
0
 

Author Comment

by:Rayneedssomehelp
ID: 39868252
Gentlemen,

I am trying to clean up the 802.1X\radius configs on the switch.
for example,  we are only using one ACS server as a testbed. Those configs for primary
and secondary radius servers may be causing some problems.

I add the radius-server host 1.2.3.4 auth-port 1645 acct-port 1646 key <SHAREDSECRET>
command.  At first I received an error message about using the name in place of the IP
address in the syntax...although it appeared to accept the command regardless.

Anyway, I still don't see any radius logs on the ACS.


Ray
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39868438
At the switch, try this command...

test aaa group radius server x.x.x.x <user> <pass> legacy

Open in new window

0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Most computer users do not realize how important their passwords are. Here’s the straight scoop on why you need a good password and how to create super strong passwords that are easy to remember and hard to crack. Thieves Are Trying to Steal Yo…
This subject  of securing wireless devices conjures up visions of your PC or mobile phone connecting to the Internet through some hotspot at Starbucks. But it is so much more than that. Let’s look at the facts: devices#sthash.eoFY7dic.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now