Hello,
I'm configuring several 2626 (H.10.45) and 5308xl (E.11.03)switches for mac-based authentication and would be very happy about some hints :)
Scenario:
Multiple thinclients and printers should be authenticated via MAC.
There are several clients and printers on each switch.
Problem:
Thinclients work, Printers don't (mostly HP LJ 1000 - 4000 Series). There's one exception: a
Samsung ML-2550, altough the same model on a differnt switch doesn't work, haven't found any differences yet. As long as a MAC is supplied the client shouldn't matter, or I'm wrong?
Activated Ports with printers connected are shown under *show port-access mac-based* but both "Authenticated Clients" and "Unauthenticated Clients" are 0. Thinclients have "Authenticated Clients" 1.
I have no clue why :(
There are no authentication attempts on IAS-Servers (MS IAS), thinclients are sucessfully logged. Apparently the switches don't send requests for printers.
Summary:
MAC-based authentication works for thinclients, not for printers on the same switch.
Thinclients authenticate sucessfully.
Printers go immediatly offline if authentication is actived - with no requests to IAS send.
Both use the same IAS-policies.
My only hints so far are:
Logging:
"18:02:44 ports: port H1 is Blocked by AAA"
"18:02:47 ports: port H1 is Blocked by STP"
show port-acces mac-based:
Port Access MAC-Based Status
Authenticated Unauthenticated Current RADIUS ACL
Port Clients Clients VLAN ID Applied?
----- ------------- --------------- -------- -----------
H1 0 0 1 No
I've read this guide, but it hasn't given me any pointers:
http://cdn.procurve.com/training/Manuals/2900-ASG-Jan08-3-WebMacAuth.pdfHopefully somebody has experience with this behavior :)
Kind regards,
Gernot