HP Procurve 2650 Management And Configuration Manual page 472

Hide thumbs Also See for Procurve 2650:
Table of Contents

Advertisement

Troubleshooting
Unusual Network Activity
C-10
Ensure that the
I
radius-server timeout
conditions.
The switch does not authenticate a client even though the RADIUS
server is properly configured and providing a response to the
authentication request. If the RADIUS server configuration for authenti-
cating the client includes a VLAN assignment, ensure that the VLAN exists as
a static VLAN on the switch. See "How 802.1x Authentication Affects VLAN
Operation" in the Access Security Guide for your switch.
During RADIUS-authenticated client sessions, access to a VLAN on the
port used for the client sessions is lost. If the affected VLAN is config-
ured as untagged on the port, it may be temporarily blocked on that port during
an 802.1x session. This is because the switch has temporarily assigned another
VLAN as untagged on the port to support the client access, as specified in the
response from the RADIUS server. See "How 802.1x Authentication Affects
VLAN Operation" in the Access Security Guide for your switch.
The switch appears to be properly configured as a supplicant, but
cannot gain access to the intended authenticator port on the switch
to which it is connected. If
Local, ensure that you have entered the local login (operator-level)
username and password of the authenticator switch into the
secret
parameters of the supplicant configuration. If instead, you enter
the enable (manager-level) username and password, access will be
denied. The supplicant statistics listing shows multiple ports with the
same authenticator MAC address. The link to the authenticator may have
been moved from one port to another without the supplicant statistics having
been cleared from the first port. Refer to the "Note on Supplicant Statistics"
in the Access Security Guide for your switch.
The
show port-access authenticator < port-list >
ports remain open after they have been configured with
. 802.1x is not active on the switch. After you execute
unauthorized
access authenticator active
listed as
.
Closed
period is long enough for network
aaa authentication port-access
command shows one or more
, all ports configured with
is configured for
identity
control
aaa port-
should be
control unauthorized
and

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 6108

Table of Contents