S5700-52P-LI-ACV200R007C00SPC500用户终端802.1X认证失败

问题描述

S5700-52P-LIV200R007C00SPC500为XXX设备终端用户802.1X认证失败
关键配置:
#
domain default_admin
#
dot1x enable
dot1x authentication-method eap
#
radius-server template dms
radius-server shared-key cipher %#%#c{/`1HR<lCta>W~]`il9A6\lA"q}~2f/UL:R]du*%#%#
radius-server authentication x.x.x.4 1812 source ip-address x.x.x.46 weight 80
radius-server accounting x.x.x.4 1813 source ip-address x.x.x.46 weight 80
#
aaa
authentication-scheme default
authentication-scheme dms
authentication-mode radius
authentication-scheme local
authentication-scheme none
authentication-mode none
authorization-scheme default
accounting-scheme default
accounting-scheme dms
accounting-scheme local
domain default
authentication-scheme dms
accounting-scheme dms
radius-server dms
domain default_admin
#
interface GigabitEthernet0/0/1
port link-type hybrid
port hybrid pvid vlan 27
port hybrid untagged vlan 17 27
stp edged-port enable
dot1x enable
authentication guest-vlan 17
dot1x authentication-method eap
#

处理过程

故障复现获取诊断信息
[S5700]info-center enable
[S5700]quit
<S5700>debugging radius all
<S5700>debugging aaa all
<S5700>debugging cm all
<S5700>debugging dot1x packet
<S5700>>terminal debugging
<S5700>terminal monitor

故障信息:
Mar 31 2017 15:16:50.170.16-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:
AAA_MAIN initiate EapRelayAuthenReq event to AAA_AUTHEN module.
CID:246 Result:0 Info:182695068
Mar 31 2017 15:16:50.170.17-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:AAA EAP Relay Authen Req 1
Mar 31 2017 15:16:50.170.18-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:User authentication domain name is default_admin //用户进入认证域default_admin
Mar 31 2017 15:16:50.170.19-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:AAA get user group author info. (RadiusAuthenFlag=0)
Mar 31 2017 15:16:50.170.20-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:AAA get service scheme author info. (RadiusAuthenFlag=0)
Mar 31 2017 15:16:50.170.21-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:Author of DaaTariffLevel.(DaaEnableFlag=0, UpStat=0, DownStat=0, Acct=0)
Mar 31 2017 15:16:50.170.22-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:
AAA send AAA_SRV_MSG_AUTHEN_ACK message to UCM module.

Mar 31 2017 15:16:50.170.23-05:13 BOCS-XA-SOFT-E10N-SW02 AAA/7/DEBUG:
Result:1 DomainIndex:1 ServiceScheme:65535
AuthedPalace:0 VLAN:4294967295 IsCallBackVerify:0 IsCallbackUser:0
IfSessionTimeout:0 IfRemanentVolume:0 IfIdleCut:0
SessionTimeout:4294967295 RemanentVolume:4294967295 IdleTimeout:4294967295
EAPSessionTimeout:4294967295 EAPPasswordRetry:4294967295
RTAcctInterval:4294967295 Priority:[255,255]
AdminLevel:255 NextHop:4294967295
EapSize:4 ReplyMessage:Authentication fail
TunnelType:0 MediumType:0 PrivateGroupID:

根因

[S5700]domain default_admin //将域default_admin设置默认域
终端认证的用户名不带域名时将进入默认域进行认证,default_admin为默认管理域未绑定radius模式的认证模板与radius服务器所以认证失败

 

解决方案

[S5700]undo domain default_admin //将设备的默认域恢复为default

阅读剩余
THE END