Hi Everton,
Your router is sending access-requests to the wrong Radius IP address
10.180.50.74.
It was supposed to send them to 10.10.50.74, all right?
Try to create an interface loopback with the IP address configured in your
Radius' client file and configure 'ip radius source-interface loopbackX'. Make
sure routing is ok.
It's worth also comparing configuration before and after the reload, if you
could.
Regards,
Leonardo Gama.
________________________________
De: [EMAIL PROTECTED] em nome de Everton Diniz
Enviada: seg 16/6/2008 12:46
Para: cisco-nsp
Assunto: [c-nsp] User not authenticating by radius
Hi all,
After a reboot on router, the radius do not auth users. The config is
not change.
This the config and debug output.
RT_2811#sh run | i aaa|radius
aaa new-model
aaa authentication login default group radius local
aaa authentication enable default group radius enable
aaa authorization exec default group radius none
aaa authorization network default group radius none
aaa accounting exec default start-stop group radius
aaa session-id common
radius-server host 10.10.50.74 auth-port 1812 acct-port 1813
radius-server key 7 shared
000334: Jun 16 12:31:23: RADIUS/ENCODE(00000018): ask "Username: "
000335: Jun 16 12:31:23: RADIUS/ENCODE(00000018): send packet; GET_USER
000338: Jun 16 12:37:24: RADIUS/ENCODE(0000001A): ask "Username: "
000339: Jun 16 12:37:24: RADIUS/ENCODE(0000001A): send packet; GET_USER
000340: Jun 16 12:37:27: RADIUS/ENCODE(0000001A): ask "Password: "
000341: Jun 16 12:37:27: RADIUS/ENCODE(0000001A): send packet; GET_PASSWORD
000342: Jun 16 12:37:29: RADIUS/ENCODE(0000001A):Orig. component type = EXEC
000343: Jun 16 12:37:29: RADIUS: AAA Unsupported Attr: interface
[156] 6
000344: Jun 16 12:37:29: RADIUS: 74 74 79 33
[tty3]
000345: Jun 16 12:37:29: RADIUS(0000001A): Storing nasport 322 in rad_db
000346: Jun 16 12:37:29: RADIUS/ENCODE(0000001A): dropping service
type, "radius-server attribute 6 on-for-login-auth" is off
000347: Jun 16 12:37:29: RADIUS(0000001A): Config NAS IP: 0.0.0.0
000348: Jun 16 12:37:29: RADIUS/ENCODE(0000001A): acct_session_id: 25
000349: Jun 16 12:37:29: RADIUS(0000001A): sending
000350: Jun 16 12:37:29: RADIUS/ENCODE: Best Local IP-Address
10.180.50.1 for Radius-Server 10.180.50.74
000351: Jun 16 12:37:29: RADIUS(0000001A): Send Access-Request to
10.180.50.74:1812 id 1645/36, len 83
000352: Jun 16 12:37:29: RADIUS: authenticator 9C 90 BC 71 C7 35 FE
E3 - E5 17 32 00 D2 DE 4A 88
000353: Jun 16 12:37:29: RADIUS: User-Name [1] 13 "cpm.everton"
000354: Jun 16 12:37:29: RADIUS: User-Password [2] 18 *
000355: Jun 16 12:37:29: RADIUS: NAS-Port [5] 6 322
000356: Jun 16 12:37:29: RADIUS: NAS-Port-Type [61] 6
Virtual [5]
000357: Jun 16 12:37:29: RADIUS: Calling-Station-Id [31] 14 "10.251.0.130"
000358: Jun 16 12:37:29: RADIUS: NAS-IP-Address [4] 6
10.180.50.1
000359: Jun 16 12:37:35: RADIUS: no sg in radius-timers: ctx
0x44540118 sg 0x0000
000360: Jun 16 12:37:35: RADIUS: Retransmit to
(10.180.50.74:1812,1813) for id 1645/36
000361: Jun 16 12:37:40: RADIUS: no sg in radius-timers: ctx
0x44540118 sg 0x0000
000362: Jun 16 12:37:40: RADIUS: Retransmit to
(10.180.50.74:1812,1813) for id 1645/36
000363: Jun 16 12:37:45: RADIUS: no sg in radius-timers: ctx
0x44540118 sg 0x0000
000364: Jun 16 12:37:45: RADIUS: Retransmit to
(10.180.50.74:1812,1813) for id 1645/36
000365: Jun 16 12:37:51: RADIUS: no sg in radius-timers: ctx
0x44540118 sg 0x0000
000366: Jun 16 12:37:51: RADIUS: No response from
(10.180.50.74:1812,1813) for id 1645/36
000367: Jun 16 12:37:51: RADIUS/DECODE: parse response no app start; FAIL
000368: Jun 16 12:37:51: RADIUS/DECODE: parse response; FAIL
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/