catalysts + freeradius -> acs only ?

Oct 09, 2006 3 Replies

Hi



I have problem with some catalysts eg 2948 with working with freeradius. Clients on w2k sp4 or wxp prof. logging (user and pass) and authenticate on freeradius. Freeradius tell to the catalyst that user is ok and ...nothing. Catalyst don't do anything. The port on catalyst is still unauthorized. I use freeradius-1.1.3, on w2k sp4 i use peap, mschap v2, i don't have any idea. Maybe there are some problems between cisco and freeradius ? maybe i have to use acs or ms ias ? but i would like freeradius because is for free ;)


thanks pilsner


so the user telnets to the switch.. are they prompted for username and password? they enter correct details then what? any messages at all?

check event log on the freeradius box and check shared radius key is correct, turn radius debuging on on the switch and console in and watch the messages when you try and authenticate.

Flamer.

not exactly. Clients use 802.1x and radius to get attempt to network, they authenticate, freeradius send message to the switch that the user is ok and switch do nothing so user they haven't network. I try this on dell switch, poweronnect, but there was the same problem.

thanks pilsner

Ok but the users are trying to authenticate on the switch itself right? not to the domain?? what do the logs say? do you want to post the switch config where it relates to aaa and radius?

Flamer.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required