Jump to content

Recommended Posts

Posted

Hi All,

 

We had our Unifi system linked to Smoothwall and it's been working great for a few years now, until today. I'm found some logs on the Unifi system telling me it's getting a RADUIS reject message back from the Smoothwall, however I can't find any RADIUS logs on the Smoothwall itself. Can anyway tell me where these would live? I'm sure I've found them in the past.

 

Thanks,

Rob

Posted
System Logs > Authentication

 

Yer that's what I thought. Doesn't show anything linked with our Unifi system requesting Authentication. So I can see from the Unifi it sends the RADIUS request, but gets a rejected response back. Smoothwall doesn't show any logs in the Authentication log which link to this.

 

I've tested with NTRadPing on my PC, changing the address on the Smoothwall for the RADIUS client. I get the same reject response from the Smoothwall. If I don't have the IP set in the Smoothwall I get a timeout (As expected). So I know the Smoothwall is responding with the reject, I just don't know why.

Posted

Theres no detailed logging of the RADIUS messages available in the UI but you can run a debug command and check the output there on the console.

 

Log on to the console and run the command:

 

radiusdebug --run

 

You can pipe this to a text file if you find the info is passing by too fast.

 

Once you have the debug info, stop this by using ctrl+c and then restart the radius service from the UI by just editing and saving one of the RADIOUS client entries in services - authentication - BYOD.

  • Thanks 1
Posted
Theres no detailed logging of the RADIUS messages available in the UI but you can run a debug command and check the output there on the console.

 

Log on to the console and run the command:

 

radiusdebug --run

 

Is there similar for digging into Kerberos auth?

 

Verbose auth logging shows “Error” receiving reply when seeking group memberships, and browser demands you feed it more credentials.

 

I want to see what my AD is saying to Smoothwall to make it ask for credentials.

Posted

We do have a verbose logging option for the auth engine - needs to be enabled in the services - authentication - settings menu, however it does not specifically show the inner workings of an NTLM or Kerberos transaction, just the replies the auth system receives regarding user info.

 

Is this happening for all systems or just for some?

 

Also, I'd recommend you take a look at our iDex solution for domain user identification instead - so many applications use HTTPS these days and close to none of them support NTLM or Kerberos - you can get rid of a lot of headache by moving to iDex.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...