Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

radius out-of-service message

This thread has been viewed 8 times
  • 1.  radius out-of-service message

    Posted Jun 27, 2014 06:20 AM

    We have a customer with laptops running 802.1x to NPS via a 3600 controller.

    They cant get on to the system and when i run the show auth-trace-buf command i am getting a radius server "out-of-service"

    message as though the NPS box has been placed into a "dead server" list.

    I know the NPS box is working.

    Pete

     


    #3600


  • 2.  RE: radius out-of-service message

    EMPLOYEE
    Posted Jun 27, 2014 06:50 AM

    What verson of ArubaOS?  How many radius servers are in the server group?  Are there any messages on the NPS server?

     



  • 3.  RE: radius out-of-service message

    Posted Jun 27, 2014 06:55 AM

     

    hello

    no message on the NPS box but we know it's working ok.

     



  • 4.  RE: radius out-of-service message

    EMPLOYEE
    Posted Jun 27, 2014 06:58 AM
    Try forcing it in service with the aaa inservice command


  • 5.  RE: radius out-of-service message

    EMPLOYEE
    Posted Jun 27, 2014 06:51 AM
    Are there any other devices using this NPS server? Are those working correctly?

    Can you run a AAA test from the diagnostics page and see if you get an accept, reject or timeout?


  • 6.  RE: radius out-of-service message

    Posted Jun 27, 2014 06:54 AM

     

    We have tested the NPS box from another NAS and is working ok.

    The message we are getting is a server timeout message.

    Any ideas?

     



  • 7.  RE: radius out-of-service message

    Posted Jun 27, 2014 07:14 AM
    Can you Ping the server ?

    What ports did you define for authentication ?



  • 8.  RE: radius out-of-service message

    Posted Jun 27, 2014 03:18 PM
    is there is any firewall between the controller and RADIUS server !


  • 9.  RE: radius out-of-service message
    Best Answer

    Posted Jun 30, 2014 04:49 AM

    Big Thank you to everyone who replied.

    We found the issue in the end.

    What had happened there was an RF rogue client who had statically configured the IP address of the NPS box!!!

    All radius requests were going to this client.

    As a result the lack of response meant the controller was put into a "dead server" group.

    When we tracked down the client all was well.

    Chap called Manish from Aruba TAC was excellent in helping out.

    CHEERS

    Pete

     

     

     



  • 10.  RE: radius out-of-service message

    Posted Jun 30, 2014 05:29 AM

    quick question as a result of what happened.

    Is there a way of enforcing DHCP on an SSID so that nobody with a static IP address can get in?

    cheers

    Pete

     



  • 11.  RE: radius out-of-service message

    Posted Jun 30, 2014 05:40 AM

    hello everybody,

    just found the tick box for enforce dhcp in the AAA profile.

    cheers

    Pete

     



  • 12.  RE: radius out-of-service message

    Posted Jun 30, 2014 07:54 AM

    Good Subject to discuss and we are happy to see your problem Solved :)