3650 Radius Configuration

Have a new 3650 configured from scratch, I'm trying to get ssh/radius authentication setup.  I went through a guide to setup on switch, I have several others that are working so i know the server is setup correctly, but when i try to use it on the switch, SSh works, and i can log in with local creds, but AD creds don't work. Thinking I'm missing something.  was hoping someone could take a look over my config and see if anything stands out.. Thanks
3650_scrub.txt
LVL 1
leadthewayAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

arnoldCommented:
Your issue is likely the encoding of the ad credentials you are using user@addomain
addomain\user?

Check what radius sees as far as a request.
Check your check items to see whether they pass.

If you have a test radius server to which you can have this switch send its radius packets without impacting the environment and without being inundated with other radius packets........... drop it into debug mode so you can see what comes in, what you sent and where the breakdown is.

Did you on the switch perform a test radius query?


potentially realm, or user from realm separation is where the issue is. DO you have other switches  in the environment to which you can compare this one?
0
leadthewayAuthor Commented:
i have 15 other switches setup the same way that work.  attached is code of one that works see if anything jumps out

usually we just enter ad username/pass.  Don't need upn
3650_scrub.txt
0
arnoldCommented:
What happens on the switch when you test radius auth. Double check whether the sw new switch is setup as a client on radius?
0
Cloud Class® Course: Microsoft Exchange Server

The MCTS: Microsoft Exchange Server 2010 certification validates your skills in supporting the maintenance and administration of the Exchange servers in an enterprise environment. Learn everything you need to know with this course.

arnoldCommented:
Which port is your radius server on, the one that works does not specify auth/acct ports while the instigator does not points to the newer 1812/1813 ports. Suggesting perhaps that the default might be running on 1645/1646 ....
Remove on the new the added auth-port 1812 acct-port 1813 and see
Radius-server.....

Your http authentication on the new is set to local only ....

Still double check that this switch is configured as a client on the radius box.
0
leadthewayAuthor Commented:
the switch is set as client, see attached, also see attached for the port config
Capture.PNG
Capture3.PNG
0
arnoldCommented:
Compare the two switches records in the client.
While radius is listening on all ports, the path via firewall might not be setup. The new specifies 1812/1813 explicitly which is not what the working one has.
Remove the auth/acct port reference on the new and see if the functionality gets fixed at which point you'll have confirmation that ports 1812 and 1813 are not setup on firewalls to allow passage to the radius server.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
leadthewayAuthor Commented:
how do i remove it, i tried to do a no statement to that line but it didn't work
0
arnoldCommented:
Try switching them to 1645/1646 respectively and see if that gets it to work.
0
leadthewayAuthor Commented:
2nd_Floor_IDF_3650(config-radius-server)#address ipv4 192.168.9.9 auth
2nd_Floor_IDF_3650(config-radius-server)#$4 192.168.9.9 auth-port 1645 ac
2nd_Floor_IDF_3650(config-radius-server)#$9.9 auth-port 1645 acct-port 1646
%Server already exists with same address port combination.
0
leadthewayAuthor Commented:
ok i got it fixed...not sure what was wrong, basically i just backed all the radius config out and mimic'd a working switch config.  Thanks for the help
0
arnoldCommented:
Great to hear. You might want to take the time and make sure that your radius paths include both 1645/1812 and 1646/1813 including the local server firewall if any.

...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Switches / Hubs

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.