Solved

No radius logs ACS 5.2

Posted on 2014-02-17
5
465 Views
Last Modified: 2014-02-20
Hello all!

I have a testbed set up for 802.1x authentication between an ACS 5.2 server with the radius
protocol enabled..."Identity stores", "Resource network devices" and "Shared secret key".
The 3750 has the  "bare bones" configs...AAA new model, shared key and the radius server
IP address.
The switch interface is configured for monitor mode..."authentication open".
I am able to ping the ACS from the switch, but when I connect a PC to the switch port
it shuts down!!  Also, there are no radius logs ont the ACS to evaluate the issue.

It seems to be ovious that the switch and ACS are not communicating.
What do I need to do get the ACS radius server to generate radius logs?
I will work on the authentication issue later down the road.  For now I just want the switch
and the ACS 5.2 server to communicate.

Thanks in advance!

Ray
0
Comment
Question by:Rayneedssomehelp
  • 3
  • 2
5 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39866836
Can you post a switch config?
0
 

Author Comment

by:Rayneedssomehelp
ID: 39867326
Hello,

The configs on the switch were configured by one of the techs here.  There is a lot of junk
on it that does not need to be on it, such as the load balancing configs.  I did not want to make any changes to the configs until I checked with the experts first.


As I stated, right now I am more concerned with just getting the ACS radius server
to communicate with the switch, so that I can view the radius logs.

I do understand that in order for the authentication to be successful I need the ACS
configured properly also.  That being said, I would like to take one step at a time
to try and resolve our issues with the deployment.  First:ACS\switch radius communcation!
Second:Authentication.




aaa new-model
!
!
aaa group server radius radus-pri
!
aaa group server radius radius-log
 server xxx.xxx.xxx.xxx
 server xxx.xxx.xxx.xxx
!
aaa group server radius radius-pri
 server xxx.xxx.xxx.xxx
!
aaa group server radius raqdius-sec
 server xxx.xxx.xxx.xxx

aaa authentication login default group tacacs+ local
aaa authentication login list-name group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authentication dot1x default group radius-pri group radius-sec
aaa authorization network default group radius-pri group radius-sec
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
!
dot1x system-auth-control


interface GigabitEthernet3/0/11
 switchport access vlan xxx
 switchport mode access
 switchport nonegotiate
 authentication open
 dot1x pae authenticator
 spanning-tree portfast


Thanks,

Ray
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 39867392
That's a good plan - you can't test authentication if the ACS/switch link doesn't work.

So, you're missing some configuration...

radius-server host 1.2.3.4 auth-port 1645 acct-port 1646 key <SHAREDSECRET>

Open in new window


...one per RADIUS server.
0
 

Author Comment

by:Rayneedssomehelp
ID: 39868252
Gentlemen,

I am trying to clean up the 802.1X\radius configs on the switch.
for example,  we are only using one ACS server as a testbed. Those configs for primary
and secondary radius servers may be causing some problems.

I add the radius-server host 1.2.3.4 auth-port 1645 acct-port 1646 key <SHAREDSECRET>
command.  At first I received an error message about using the name in place of the IP
address in the syntax...although it appeared to accept the command regardless.

Anyway, I still don't see any radius logs on the ACS.


Ray
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39868438
At the switch, try this command...

test aaa group radius server x.x.x.x <user> <pass> legacy

Open in new window

0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Read about achieving the basic levels of HRIS security in the workplace.
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
Learn how to create flexible layouts using relative units in CSS.  New relative units added in CSS3 include vw(viewports width), vh(viewports height), vmin(minimum of viewports height and width), and vmax (maximum of viewports height and width).

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now