No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

An ME60 Is Configured with Non-Operating Authentication, But MAC Addresses Are Displayed as User Names on

Publication Date:  2019-07-28 Views:  98 Downloads:  0

Issue Description

An ME60 is successfully configured with non-operating authentication, specifically, MAC address-prioritized portal authentication. However, MAC addresses, instead of the user names of terminals, are displayed on ASG5000s.

Networking: Terminal----ME60----Agile Controller-Campus---ASG5500

Handling Process

When non-operating authentication is performed, ASGs record the user names of terminals based on the accounting packets sent by devices. Therefore, packet header obtaining on ME60s needs to be analyzed to confirm the user names of accounting packets.

In case of MAC address-prioritized portal authentication, MAC authentication packets are sent in priority. Therefore, MAC addresses of terminals are displayed as user names.

Check the packets replied to the ME60 by the RADIUS server. It is found that the Accept packet contains the user name conversion attribute.

Check the accounting packets sent by the ME60 to the RADIUS server. It is found that a MAC address is still displayed as the user name. The ME60 does not respond to the user name conversion attribute delivered by the RADIUS server.

 

Root Cause

The ME60 fails to respond to the user name conversion attribute delivered by the RADIUS server.

Solution

Run the radius-attribute apply user-name match user-type ipoe command in the RADIUS profile on the ME60 to replace the user names delivered by the RADIUS server with the user names generated by the ME60.

END