Case Study: STA Authentication Fails Due to Incomplete Configuration of the Authentication Scheme Profile on the AC
Symptom
When external Portal authentication and AD authentication are configured on the AC, STAs fail Portal authentication.
Relevant Alarms and Logs
None
Cause Analysis
No authentication mode is configured in the authentication scheme profile on the AC.
Procedure
- Use the trace function to check the STA authentication process.
[AC] trace object mac-address sta-mac [AC] trace object ip-address sta-ip [AC] trace enable
Based on the error message, it is suspected that the authentication scheme profile is incorrectly configured.
[BTRACE][AAA][sta-mac]:User authentication domain name is [BTRACE][AAA][sta-mac]:The authentication place is Local. [BTRACE][AAA][sta-mac]:No such local user exist, send to the next authen place. [BTRACE][AAA][sta-mac]:No such local user exist. [BTRACE][AAA][sta-mac]: [AAA ERROR]authen finish,the authen fail code is:3,reason is:Failed to send authen-req
- Run the display current-configuration command on the AC to check the authentication mode configuration. No configuration is found in the authentication scheme profile.
- Set the authentication mode to AD authentication in the authentication scheme profile.
<AC> system-view [AC] aaa [AC-aaa] authentication-scheme xxx [AC-aaa-authen-xxx] authentication-mode ad