mrbios Posted July 12, 2021 Posted July 12, 2021 I'm trying to get radius working nicely with smoothwall but i keep getting errors on the functionality tests. I've set it up so that my NPS server is doing authentication and the smoothwall is doing accounting, and then should be forwarding accounting back to the NPS server. However under the smoothwall functionality tests i keep getting the error "The system attempted to forward the RADIUS request to the upstream server, but it did not respond or the configured shared secret is incorrect." I'm certain it's not the shared secret, i've redone that twice. I'm running wireshark on the NPS server and i can see the occasional accounting packet going from my smoothwall to my NPS server, but they only ever appear to come from a singular access point (Under NAS-IP-Address attribute, the source is the smoothwall as expected) The other errors I'm seeing in the functionality tests: No Framed-IP-Address attribute was received with an accounting request, but DHCP is not installed. This configuration is not supported. Calling-Station-Id attribute is missing from the RADIUS packet. This configuration is not supported. NAS-IP-Address attribute is missing from the RADIUS packet. Wireless roaming may cause problems with unsynchronized logins and blocked users. Any suggestions? I don't really know what I'm doing on the Aerohive side of things so maybe i've not done something right there. It's actually ExtremeIQ or whatever Aerohive is rebranded to now.
foofighterjim Posted July 12, 2021 Posted July 12, 2021 I may be misunderstanding the setup, but with Aerohive, authentication happens at the AP, so each AP needs to be added as an authorised RADIUS Client.
mrbios Posted July 12, 2021 Author Posted July 12, 2021 I may be misunderstanding the setup, but with Aerohive, authentication happens at the AP, so each AP needs to be added as an authorised RADIUS Client. Yea the APs are setup in their own vlan so on RAIDUS the full cidr of their management vlan is setup as the client. Authentication is working fine, and i can see accounting is being received by my smoothwall, but forwarding that accounting back from the smoothwall to the NPS server doesn't appear to work.
slugshead Posted July 12, 2021 Posted July 12, 2021 Here's my settings - Works nicely and everything is logged as you would expect with no errors Smoothwall > Authentication > BYOD Authorized RADIUS Clients Wi-Fi Controller - I'm using Ruckus so I've just got the controller there. Sounds like you may have to add each AP. Forward RADIUS Accounting to NPS Server. NPS > Radius Clients and Servers > Radius Clients Wi-Fi Controller Smoothwall Wi-Fi AAA Servers 3 DCs as Active Directory sources Smoothwall RADIUS Accounting NPS as RADIUS Doesn't read right when you think about it logically but it works perfectly. Shared secret needs to be put in all places too
mrbios Posted July 12, 2021 Author Posted July 12, 2021 (edited) That sounds exactly how i've got mine setup with the only change being that rather than an individual controller IP, I've got the full CIDR set as the authorised radius client range on the smoothwall. I've just done a complete config update and put the latest firmware on a bunch of APs and I'm still only seeing radius accounting packets coming through to the NPS server from smoothwall on occasion and always relating to the same individual AP, not all the others. I'll try adding in a bunch of APs individually as authorised radius clients on the smoothwall rather than the range and see how that goes. EDIT: Interesting, every time i add an AP, i get an accounting packet, but all are identified as that same AP I added first. Edited July 12, 2021 by mrbios
slugshead Posted July 12, 2021 Posted July 12, 2021 Just came across this and thought it sounded familiar, came back to post this to you https://docs.microsoft.com/en-us/answers/questions/97643/windows-server-2019-solved.html sc sidtype IAS unrestricted 1
mrbios Posted July 12, 2021 Author Posted July 12, 2021 Just tried that but doesn't appear to have made a difference unfortunately, enabled firewall logs as well and i've got the following 2021-07-12 16:54:37 ALLOW UDP 172.18.66.100 172.18.66.39 1814 1813 0 - - - - - - - RECEIVE 66.100 is my smoothwall, 66.39 is my NPS server. So I'm definitely getting something through, albeit wireshark shows that 4 times while the firewall log only sees it once throughout the period i had logs enabled. The more i investigate the more i feel like smoothwall is at fault.
mrbios Posted July 13, 2021 Author Posted July 13, 2021 (edited) I restarted my smoothwall box last night. Interestingly, wireshark is still seeing the one occasional packet received, but from what i suspect was the very first device to connect and report via radius. I think smoothwall struggles to report back properly using multiple radius clients rather than a single IP address from a controller. EDIT: I've just gone through and added all 49 access points individually, rather than the range they're in. Now ideally i want to restart the radius server service, but i've no idea how i do that without restarting the whole smoothwall? EDIT2: Nevermind, worked that one out, restarted the freeradius service but no change. Edited July 13, 2021 by mrbios
slugshead Posted August 23, 2021 Posted August 23, 2021 Got something to add to this if you're still puzzled. I updated our Smoothwall to Leeds 49. RADIUS totally died and nothing could connect to our BYOD. Rolled back to 48 and everything worked as normal again
mrbios Posted August 23, 2021 Author Posted August 23, 2021 Interesting, I'm still on 48, got a smoothwall support call tomorrow morning about this. Maybe i should update to 49 overnight and see what happens
mrbios Posted August 24, 2021 Author Posted August 24, 2021 So after some diagnostics with Smoothwall support, and looking at more in depth logs, it looks as though the fault with this isn't with smoothwall. Smoothwall is sending the accounting packets, NPS is receiving them, but isn't sending an acknowledgment back. Not that surprised really. Might try setting up either a Server 2022 or even a 2012R2 server just to test and see if it's a 2019 specific issue (as i know it did have some strange NPS issues in the early days)
tom_newton Posted August 24, 2021 Posted August 24, 2021 There's definitely a radius wrinkle in L49 (fixed in 50). You 100% sure it's not a unidirectional routing issue if there's a packet going one way but not tother?
mrbios Posted August 24, 2021 Author Posted August 24, 2021 The support guy ruled out routing, he did do a bit of testing on that, but everything seemed fine from a routing perspective.
AndyB4rks Posted September 1, 2021 Posted September 1, 2021 We have been having a similar issue to what you describe but with unifi and accounting packets We are also on Leeds 49 and NPS 2019. Let me know if you tried server 2022 as that was my next step in trying to fix it.
moneill Posted January 12, 2024 Posted January 12, 2024 anyone get anywhere with this? i'm having similar issues haha
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now