Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Users unable to authenticate using RADIUS server?

This thread has been viewed 1 times
  • 1.  Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 06:52 AM

    Hi

     

    We have a partner that uses our WiFi, they have X2 SSID's setup for X2 seperate RADIUS servers using 802.1X.

    They have made a change which stopped users authenticated to either RADIUS server? They rolled back the change and can acces one server using one SSID but not the other?

     

    Logs say - Dropping the radius server packet

                     Authentication Server Out of Service

                     Request timeout

    I can ping both RADIUS servers from the controller, they say they cant see any logs on one the servers from the controller?



  • 2.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 06:58 AM

    I beleive they added a request forwarder from one RADIUS server to the other older leagcy NPS. 

    They say they have rolled back this as it caused a problem, however one of the SSID's are no longer sending RADIUS request?

     

    I have no visability of their server or network!



  • 3.  RE: Users unable to authenticate using RADIUS server?

    EMPLOYEE
    Posted Feb 12, 2016 07:05 AM

    They need to look at the Radius Server and see if  it is getting radius requests from an unknown radius client.  They would have to correct the radius client address on the radius server...



  • 4.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 07:09 AM

    Hi

     

    They say they are not receiving any RADIUS requests, they can only see when I ping?

     

    How can I test traffic is reaching them?



  • 5.  RE: Users unable to authenticate using RADIUS server?

    EMPLOYEE
    Posted Feb 12, 2016 07:11 AM

    You could install wireshark on the radius server and do a packet capture to see if any radius traffic is being received.



  • 6.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 07:23 AM

    Hi

     

    They won't do that as they say they cant see traffic on their firewall which is connected to our controller?



  • 7.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 07:35 AM

    Debug logs show authentication timeout messages, RADIUS Server is up, back in service and down for 10 mins?



  • 8.  RE: Users unable to authenticate using RADIUS server?

    EMPLOYEE
    Posted Feb 12, 2016 07:53 AM

    They should reenter the radius server key on both ends to make sure it is working.  Without having access to their system it is difficult to troubleshoot, because it could be anything?  Is there a firewall between the radius server and the controller?



  • 9.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 08:51 AM

    Yes they have a firewall connected to our controller, so they say they cant see any traffic going to their RADIUS server?

     

    I can only see failed messages on the controller!

    Yes it is very difficult to troubleshoot, the problem only occured when tehy mad a change to add a forwarder now roled back only working on one SSID and RADIUS?



  • 10.  RE: Users unable to authenticate using RADIUS server?

    EMPLOYEE
    Posted Feb 12, 2016 09:29 AM

    Did they change anything on the controller?  Type "show audit-trail" to see what was changed...

     



  • 11.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 10:47 AM

    Hi

     

    No they dont have access to the contoller only I do and I have not made any changes?



  • 12.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 11:08 AM

    They are asking for us to prove traffic is going from the controller to their firewall! This works on their 2nd SSID and RADIUS server?

    Could this forwarder be having an impact still trying to send to the other server?

    Logs on the controller do show fails to the original server?



  • 13.  RE: Users unable to authenticate using RADIUS server?

    Posted Feb 12, 2016 11:40 AM

    Hi 

     

    Users are now suddenly connecting to both RADIUS servers ok? Could there be an issue with load?

    Other users could be logging off the WiFi on other SSID's being Fri afternoon and now the users are connecting using RADIUS?

     

    Is there a way to do a health check to look into this?

    Still not sure why working ok one one SSID not the other? now ok on both?

     

    Need to see what happens on Monday morning? Could a reboot help or do you think this is not a controller issue?



  • 14.  RE: Users unable to authenticate using RADIUS server?

    EMPLOYEE
    Posted Feb 12, 2016 02:59 PM

    The best way to see the radius server status is by typing "show aaa authentication-server statistics" to see if servers have been up/down or not responding to packets.