1.检查radius模板配置是否正确:
[NM-WH-WD-XXZX-H5700-L3-GigabitEthernet0/0/3]test-aaa test test radius-template 802.1x
Info: Account test succeed.
test-aaa测试时succeed,说明对接参数没有问题;
2.在认证的时候开启trace信息,trace终端的mac地址,关键信息如下:
[BTRACE][2017/05/26 17:01:08][RADIUS][74d4-XXXX-922e]:Receive authentication request message from AAA module.
[BTRACE][2017/05/26 17:01:08][RADIUS][74d4-XXXX-922e]:
Send a authentication request packet to radius server( server ip = 192.168.253.100).
[BTRACE][2017/05/26 17:01:08][RADIUS][74d4-XXXX-922e]:
Server Template: 0
Server IP : 192.168.253.100
Protocol: Standard
Code : 1
Len : 285
ID : 53
[User-Name ] [6 ] [test]
[NAS-Port ] [6 ] [12428]
[Service-Type ] [6 ] [2]
[Framed-Protocol ] [6 ] [4294967295]
[Calling-Station-Id ] [19] [37 34 2D 44 34 2D 33 35 2D 43 37 2D 39 32 2D 32 45 ]
[NAS-Identifier ] [24] [NM-WH-WD-XXZX-H5700-L3]
[NAS-Port-Type ] [6 ] [15]
[NAS-Port-Id ] [36] [slot=0;subslot=0;port=3;vlanid=140]
[State ] [32] [27SessionID=acs/283426346/316;]
[EAP-Message ] [8 ] [02 7c 00 06 03 19 ]
[Message-Authenticator ] [18] [47 c7 38 62 86 13 8c b9 4f 89 41 23 76 40 ac 9f ]
[Login-IP-Host ] [6 ] [0]
[BTRACE][2017/05/26 17:01:08][EAPoL][74d4-XXXX-922e]:Receive a DHCP packet from user.
[BTRACE][2017/05/26 17:01:08][EAPoL][74d4-XXXX-922e]:User(MAC:74d4-XXXX-922e) existed in temp user table.
[BTRACE][2017/05/26 17:01:09][RADIUS][74d4-XXXX-922e]:
[NAS-IP-Address ] [6 ] [192.168.253.254]
[Framed-Mtu ] [6 ] [1500]
[HW-NAS-Startup-Time-Stamp ] [6 ] [1494605777]
[HW-IP-Host-Address ] [35] [255.255.255.255 74:XX:XX:c7:92:2e]
[HW-Connect-ID ] [6 ] [135]
[HW-Version ] [14] [Huawei S5700]
[HW-Product-ID ] [7 ] [S5700]
[HW-Access-Type ] [6 ] [0]
[BTRACE][2017/05/26 17:01:10][RADIUS][74d4-XXXX-922e]:
Received a authentication reject packet from radius server(server ip = 192.168.253.100).//radius服务器回了一个reject报文;
在认证的时候在PC和radius服务器同时开启报文头分析,关键报文如下:
![]()
![]()
终端使用的是EAP-PEAP认证,服务器使用的EAP-MD5认证,二者不匹配