Re: MAC authentication succeeds, port stays unauthorized (allied telesis)

2013-06-11 Thread Stijn D'haese
On Fri, 07 Jun 2013 17:40:04 +0200, David Mitton da...@mitton.com wrote: Best to check the error log on the NAS. When the link goes up the following debug message appear on the NAS: 2013 Jun 10 15:22:56 system.information awplus pcfg: Egress Broadcast(1):Milticast(1):Unicast(1) port1.0.5 2013

MAC authentication succeeds, port stays unauthorized (allied telesis)

2013-06-07 Thread Stijn D'haese
Hi, I'm trying to do MAC based authentication on our switches, but for some strange reason the port doesn't want to authenticate, even though the radius server sends an Access-Accept package to the port. I did a capture on the port and the Access-Accept package is received by the port, but

Re: MAC authentication succeeds, port stays unauthorized (allied telesis)

2013-06-07 Thread Alan DeKok
Stijn D'haese wrote: Any ideas where I need to start looking? The RADIUS server sent the right answer. The NAS ignored it. Blame the NAS. Alan DeKok. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MAC authentication succeeds, port stays unauthorized (allied telesis)

2013-06-07 Thread David Mitton
The NAS device is the final arbiter of allowing access. Even if the authentication succeeds, there may be other things about the connection and the NAS policies that are not met by the port user. Best to check the error log on the NAS. Dave. Quoting Stijn D'haese maill...@stijn-dhaese.be: