Security

last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Testing RADIUS servers from the CLI

This thread has been viewed 28 times
  • 1.  Testing RADIUS servers from the CLI

    Posted Jan 16, 2019 12:07 PM

    I'm trying to use the aaa test-server command to troubleshoot some RADIUS auth issues I'm running into, but I keep getting a parse error on the 'server name' parameter. No matter what I put there it says parse error and points to the first character of the server name.

     

    I am using the 'Name' property of the server that shows up in the 'show radius' command. The Server Name property shows Not Configured on everything server though, could that be related? Not sure what I need to do to test it...

     

     

    Maybe someone could help with my actual RADIUS issue if I can't get the command to work. I had it working by configuring my NPS server directly on the SSID in question, but I am trying to load balance NPS behind a KEMP loadmaster. When I switched the IP from the NPS server itself, to the virtual server on the KEMP, it stopped working. It isn't even sending the requests through to the NPS server.

     

    I know the KEMP virtual server is working though because other devices are using it just fine. It's just my IAP-105's that won't work through it which is what lead me to trying the test command.

     

    Anyone have any ideas?

     

     



  • 2.  RE: Testing RADIUS servers from the CLI

    EMPLOYEE
    Posted Jan 16, 2019 12:45 PM

    Can you please print out your exact command and the error you are witnessing?



  • 3.  RE: Testing RADIUS servers from the CLI

    Posted Jan 16, 2019 12:50 PM

    I have a screenshot below, KEMP-NPS is the load balanced virtual server that I have configured
    2019-01-16_11-48-22.png



  • 4.  RE: Testing RADIUS servers from the CLI

    EMPLOYEE
    Posted Jan 16, 2019 12:53 PM

    What version of ArubaOS is this?

    Are you running this from the VMC or the VMM?



  • 5.  RE: Testing RADIUS servers from the CLI

    Posted Jan 16, 2019 01:11 PM

    ArubaOS (MODEL: 105), Version 6.4.4.8-4.2.4.11

     

    These are instant APs so I just SSH'd into the virtual controller, we do not have a mobility controller.



  • 6.  RE: Testing RADIUS servers from the CLI



  • 7.  RE: Testing RADIUS servers from the CLI
    Best Answer

    Posted Jan 17, 2019 09:33 AM

    Looks like it was a formatting issue, I formatted it like your link and it did not give me the parse error, but it also displayed no output. It just goes back to a prompt line immediately.

     

    However, I figured out the issue. It was related to our load balancer. I have it configured improperly for Transparency. All is good now!