Case Study: STA Authentication Fails Because the Shared Key Configured on the RADIUS Server Is Different from That Configured on the AC
Symptom
802.1X authentication is configured on an AC, but wireless STAs fail to pass 802.1X authentication.
Relevant Alarms and Logs
None
Cause Analysis
The shared key configured on the RADIUS server is different from that configured on the AC.
Procedure
- Reproduce the fault and use the trace and station-trace functions to check the authentication packet exchange process.
[AC] trace object mac-address sta-mac [AC] trace enable [AC-diagnose] station-trace sta-mac sta-mac
The command output prompts you to check the shared-key configuration.
[BTRACE][2020/07/02 10:34:00][512][RADIUS][x-x-x]: Send a authentication request packet to radius server( server ip = y.y.y.y). [BTRACE][2020/07/02 10:34:00][512][RADIUS][x-x-x]: Receive a illegal packet(Authenticator error), please check share key config.
- Reconfigure the shared key on the AC to be the same as that on the RADIUS server. The fault is rectified.
<AC> system-view [AC] radius-server template test [AC-radius-test] radius-server shared-key cipher Example@2012