Troubleshooting Aaa And Radius - 3Com Switch 7700 Configuration Manual

Switch
Hide thumbs Also See for Switch 7700:
Table of Contents

Advertisement

Troubleshooting AAA
and RADIUS
The RADIUS protocol of TCP/IP protocol suite is located on the application layer. It
basically specifies how to exchange user information between NAS and RADIUS
server of ISP. So it is likely to be invalid.
Tasks for Troubleshooting AAA and Radius are described in the following sections:
User authentication/authorization always fails
RADIUS packet cannot be transmitted to RADIUS server.
After being authenticated and authorized, the user cannot send charging bill
to the RADIUS server.
User authentication/authorization always fails
1 The username may not be in the userid@isp-name format or NAS has not been
configured with a default ISP domain. Please use the username in proper format
and configure the default ISP domain on NAS.
2 The user may not have been configured in the RADIUS server database. Check the
database and make sure that the configuration information of the user does exist
in the database.
3 The user may have input a wrong password. Make sure that the supplicant inputs
the correct password.
4 The encryption keys of RADIUS server and NAS may be different. Check carefully
and make sure that they are identical.
5 There might be some communication fault between NAS and RADIUS server,
which can be discovered through pinging RADIUS from NAS. Ensure the normal
communication between NAS and RADIUS.
RADIUS packet cannot be transmitted to RADIUS server.
1 The communication lines (on physical layer or link layer) connecting NAS and
RADIUS server may not work well.
2 The IP address of the corresponding RADIUS server may not have been set on NAS.
Set a proper IP address for RADIUS server.
3 UDP ports of authentication/authorization and accounting services may not be set
properly. Make sure they are consistent with the ports provided by RADIUS server.
After being authenticated and authorized, the user cannot send charging
bill to the RADIUS server.
1 The accounting port number may be set improperly. Set a proper number.
2 The accounting service and authentication/authorization service are provided on
different servers, but NAS requires the services to be provided on one server (by
specifying the same IP address). Make sure the settings of servers are consistent
with the actual conditions.
Configuring the AAA and RADIUS Protocols
311

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents