Login to a Nortel BayStack 470 switch with radius

Hi,

We have a Nortel BayStack 470 switch configured with Radius authentication. We also have a Cisco ACS version 3.3 server which works as a Radius & TACACS+ server. Now when we press + to log in to the switch, it asks for a username and password. However, when we type in the correct username and password it says "Access Denied from RADIUS".

I also tried a WinRadius server and it didn't work.

Does anybody know how to get into this switch??

Thanks. Deepu.

Reply to
deepuab
Loading thread data ...

You can click "Ctrl + C" to interrupt booting and get into a boot mode. At this mode, press "i" to initialize config and log flash. It's kind of a procedure of password recovery but you will lose any configuraiton and log at this switch.

snipped-for-privacy@gmail.com wrote:

Reply to
yilin.wang

Is there any way to do this without losing the config of this switch, as I am not aware of the existing configuration of this switch?

Thanks, Deepu.

Reply to
deepuab

Unfortuately, this is the only one way to recover password by yourself.

Unless, you send this switch to Nortel and ask the tenical support recover password without losing configuration. There is no well-known backdoor at Nortel switches using new firmwares.

Reply to
Dophi

Is there any compatibility problem between the Nortel BayStack 470 switch and the Cisco ACS server v3.3. It appears that the Cisco ACS server supports login from Nortel devices using Radius. When I check the logs of the Cisco ACS server (Radius) it states that the user has authenticated sucessfully, but the Nortel BayStack 470 gives "Access Denied from RADIUS" message?

Reply to
deepuab

Maybe you can use a packet analyzing software to capture packets of the communicaiton between ACS and 470. BayStack 470 is compatible with other RADIUS servers as long as they follow RFC definitions even RFC

2138.

As I know, BayStack supports two different kinds of accounts associated with RADIUS. One is read-only account and another is read-write. The access level of account depends on the return attribute of RADIUS.

something back to BayStack 470 but 470 doesn't understand it. Maybe you can verify the setting of ACS. For read-write access, set the service type field value to "Administrative".

If everything still doesn't work, how about try to use Device Manager? It is a management software provided by Nortel and it uses SNMP to manage switches. If u can get access from this, you also can change everything you want. :)

I hope this information can help you.

Regards

Reply to
Dophi

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.