+ Post New Thread
Results 1 to 8 of 8
Wireless Networks Thread, Procurve Macbased Authentication in Technical; Hi there, hopefulle somebody here can give me some hints I have several 2600 and 5300 switches configured with 802.1x, ...
  1. #1

    Join Date
    Jan 2009
    Posts
    5
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Procurve Macbased Authentication

    Hi there,

    hopefulle somebody here can give me some hints
    I have several 2600 and 5300 switches configured with 802.1x, which works fine.
    Problem: MAC-based authentication. My switches just won't talk with my RADIUS (MS IAS) server...

    This thread gave me some pointers but nothing worked so far:
    http://www.edugeek.net/forums/networ...tches-11x.html

    My setup:

    2600 and 5300 Switches
    Radius configured and working (802.1x with same RADIUS works)
    IAS-Policy with correct group and NAS-type
    EAP-Method MD5-Challenge, CHAP is enabled
    aaa authentication port-access eap-radius is enabled
    message authenticator is disabled
    Tried different delimiter settings
    Accounts for Clients have reversible encryption enabled and user/pw is mac-address

    I expected to see activated ports with *show port-access mac-based clients* but the list is empty altough several ports are active.

    Log only shows "Port blocked by AAA"...
    Last edited by Scratch; 5th January 2009 at 03:27 PM. Reason: Additional Info

  2. #2

    Join Date
    Jan 2009
    Posts
    5
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    nobody got a clue?

  3. #3

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    17,529
    Thank Post
    513
    Thanked 2,406 Times in 1,862 Posts
    Blog Entries
    24
    Rep Power
    822
    This is the config on my HP 5406zl switch:

    Code:
    max-vlans 64 
    module 1 type J8706A 
    module 2 type J8705A 
    module 3 type J8702A 
    module 4 type J8702A 
    ip default-gateway 10.5.143.254 
    ip routing 
    ip udp-bcast-forward 
    vlan 1 
       name "Servers" 
       untagged A12-A24,B1-B11,B13-B19,B21-B24,C1-C21,C24,D2-D3,D5-D14,D16-D24 
       ip forward-protocol udp 10.5.140.127 5151 
       ip forward-protocol udp 10.5.140.255 5151 
       ip forward-protocol udp 10.5.141.63 5151 
       ip forward-protocol udp 10.5.141.127 5151 
       ip forward-protocol udp 10.5.141.191 5151 
       ip forward-protocol udp 10.5.141.255 5151 
       ip forward-protocol udp 10.5.142.127 5151 
       ip address 10.5.143.1 255.255.255.0 
       tagged A1-A11,C22 
       no untagged B12,B20,C23,D1,D4,D15 
       exit
    aaa accounting update periodic 15 
    aaa accounting network start-stop radius 
    aaa accounting exec start-stop radius 
    aaa accounting system start-stop radius 
    radius-server dead-time 5 
    radius-server key juniper12a 
    radius-server host 10.5.143.14 
    primary-vlan 666 
    aaa port-access mac-based C1,C5,C9,C11-C20,D2,D5-D10,D12-D14,D16,D18-D24
    aaa port-access mac-based C1 unauth-vid 666
    aaa port-access mac-based C5 unauth-vid 666
    Well, the pertinent bit anyway. The vlan part is repeated for the different VLANs and the aaa parts are repeated for different groups of ports.

  4. #4
    DMcCoy's Avatar
    Join Date
    Oct 2005
    Location
    Isle of Wight
    Posts
    3,421
    Thank Post
    10
    Thanked 486 Times in 426 Posts
    Rep Power
    110
    Have you altered the Framed-MTU option in the IAS policy? Newer Procurve firmware versions don't work with the default value anymore. I have set Framed-MTU in all of my policies to 1400

  5. #5

    Join Date
    Jan 2009
    Posts
    5
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Thank you for your replies.

    @DmcCoy: Tested it, had no effekt.

    RAS-Policy Settings are:
    Framed-Protocol: PPP
    Service-Type: Framed

  6. #6

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    17,529
    Thank Post
    513
    Thanked 2,406 Times in 1,862 Posts
    Blog Entries
    24
    Rep Power
    822
    Just a quick question, did you have reversible encryption enabled before or after creating the password for clients?

  7. #7

    Join Date
    Jan 2009
    Posts
    5
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    activated reversible encryption and then set the password.

  8. #8

    Join Date
    Jan 2009
    Posts
    5
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    /bump

SHARE:
+ Post New Thread

Similar Threads

  1. Procurve VLAN help
    By meastaugh1 in forum Wireless Networks
    Replies: 8
    Last Post: 4th September 2008, 08:29 PM
  2. HP Procurve VALNS Help !
    By ICTNUT in forum Wireless Networks
    Replies: 22
    Last Post: 30th July 2008, 01:15 PM
  3. Help... I need a Procurve Pro!
    By Ric_ in forum Wireless Networks
    Replies: 20
    Last Post: 2nd July 2008, 10:14 PM
  4. HP Procurve switches
    By edie209 in forum Hardware
    Replies: 16
    Last Post: 4th October 2006, 05:58 PM
  5. HP Procurve 4108GL
    By wesleyw in forum Hardware
    Replies: 16
    Last Post: 5th July 2006, 01:58 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •