Nortel Networks Nortel 450 switch / EAPOL / Microsoft IAS / 802.1x / PEAP etc

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Nortel 450 switch / EAPOL / Microsoft IAS / 802.1x / PEAP etc Skinftz 12-12-06
Posted by Skinftz on December 12, 2006, 11:44 am
Please log in for more thread options
Has anyone managed to get Nortel 450 switches to work with EAPOL with
Microsoft IAS using 802.1x?

I have Windows XP SP2 clients, Server 2003 Release2 server running IAS.
I have set up the return attributes as described in the documentation,
namely:

VLAN Membership attributes:
-- Tunnel-Pvt-Group-ID RADIUS Standard String Value= Number of
VLAN
-- Tunnel-Type RADIUS Standard Virtual LANs (VLAN)
-- Tunnel-Medium-Type RADIUS Standard 802 (Includes all 802
media... )
-- Nortel-Port-Priority Nortel Networks 4

(I have also tried the vendor specific attribute but IAS in Server 2003
knows about some nortel attributes)

The client is setup with a secret and 'Requests must contain the
Message Authenticator attribute' is ticked.

The policy conditions are 'NAS-Port-Type matches "Ethernet" AND
Windows-Groups matches "<DOMAIN>\<some group name>"

The computer and user accounts have dialin 'controlled through RAS
policy'.

. The 450 switch is running firmware 4.5.4.06. The switch is not in a
stack.

I have tried using MD5 (yes I turned on 'use reversible encryption'),
'Smartcard or other Certificate', and PEAP.

In all of my tests for both the machine and the user account the port
is authorised and access is granted. Events are logged to this effect,
and if I look in the JDM at the switch I see the port is authorised,
and I also see the VLAN change to whatever I tell IAS to return.
Everything *looks* fine, however the clients will not work - I do not
get DHCP, and if I set a static IP address on the client and try to
ping something, I get nothing. If I set a static IP on the client and
run Ethereal on a client and monitor the EAP process, I see an EAP
success. I then see 'IGMP V2 Membership Report's the source of which
are other machines in the VLAN that I'm supposed to be in, and I see
Nortel SONMP traffic. If I run the 'dhcploc' utility and manually
request an IP over DHCP, I see the requests but no responses.

I have IAS set up and working just fine for wireless clients using some
Nortel 2380 wireless switches, but the 450's simply Do Not Work.

I have tried two different clients and have updated all drivers where
possible. The newest client was a Dell D600 with the Broadcom driver
dated 2006. All yield the same results.

Does *anyone* have this working?


Posted by Skinftz on December 12, 2006, 12:01 pm
Please log in for more thread options

Skinftz wrote:

> Has anyone managed to get Nortel 450 switches to work with EAPOL with
> Microsoft IAS using 802.1x?

I just worked out what was wrong - turns out spanning tree MUST be
enabled on the ports that are using EAPOL!

AAARRRGGGHHH!!!!!!! WOULD IT HAVE KILLED YOU NORTEL TO MENTION THIS IN
THE DOCUMENTATION??????!!!!!

*ahem*.

:)


Similar ThreadsPosted
Nortel 450 switch / EAPOL / Microsoft IAS / 802.1x / PEAP etc December 12, 2006, 11:44 am
EAPOL in wired network. June 19, 2005, 8:19 am
I am BUYING Cisco, Lucent, Nortel, Microsoft & more. I also buy Extreme, Foundry, Brocade and more. September 20, 2008, 3:04 pm
WTB: I NEED TO BUY LIST OF TELECOM, NETWORKING, SOFTWARE, CISCO, MICROSOFT, NORTEL, LUCENT, ALCATEL & MORE April 10, 2008, 8:05 pm
WTB: I NEED TO BUY LIST OF TELECOM, NETWORKING, SOFTWARE, CISCO, MICROSOFT, NORTEL, LUCENT, ALCATEL & MORE April 18, 2008, 8:35 pm
WTB: I NEED TO BUY LIST OF TELECOM, NETWORKING, SOFTWARE, CISCO, MICROSOFT, NORTEL, LUCENT, ALCATEL & MORE May 6, 2008, 2:04 am
WE BUY Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe and more.. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you have. March 31, 2007, 8:36 am
WTB: (USED or NEW) Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe & more. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you have. PLEASE September 30, 2007, 11:19 am
WTB: We BUY USED - Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe & more. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you have. PLEASE October 27, 2007, 7:38 am
WTB: WE BUY USED, REFURB & NEW Nortel, Cisco, Juniper, Alcatel, Lucent, Foundry, Extreme, F5 Big IP, Tellabs, Microsoft, Adobe & more. We buy Telecom, Networking and Software. Look below at my current want to buys and email me with any offers that you ha August 19, 2007, 7:18 pm
Nortel 4550T PRW switch January 16, 2008, 3:43 pm
Re: Nortel 460-24T PWR, how to make it just into a non addressed switch? August 18, 2007, 11:24 pm
Login to a Nortel BayStack 470 switch with radius March 20, 2006, 3:34 am
nortel Baystack 5520-24T ethernet switch December 14, 2005, 12:49 pm
I am looking to buy Cisco, Lucent, Nortel, Alcatel, Juniper Networks, Bintec, Siemens, Foundry, Networks, Extreme Networks, Fore/Marconi, Tellabs Lucent/Avaya/Ascend, Xylogics, Brocade, Intel, Motorola, Nokia VPN/Firewall, Netscreen, Microsoft Adobe, February 24, 2008, 8:22 am