I have the problem with telnet access through radius server(Cisco ACS 4.2).
Error, that I get back from the switch:
"Authentication failure : Server configuration error, contact your administrator"
I've read the knowledge base solutions:
https://service.esd.alcatel-lucent.com/ ... umber=5925
https://service.esd.alcatel-lucent.com/ ... umber=5763
but it didnt help me.
All switches(6800,6850,7800,7700 Software Versions 6.3.1.999.R01, 5.4.1.444.R01) return the same error
Switch configuration:
aaa radius-server "RADIUS" host x.x.x.x key xxx auth-port 1645 acct-port 1646
aaa authentication telnet "RADIUS" "local"
ACS configuration:
UDV with VSAs installed
(VSA 9=Alcatel-Asa-Access
VSA 39=Alcatel-Acce-Priv-F-R1
VSA 40=Alcatel-Acce-Priv-F-R2
VSA 41=Alcatel-Acce-Priv-F-W1
VSA 42=Alcatel-Acce-Priv-F-W2)
Radius Alcatel Attributes:
[800\009] Alcatel-Asa-Access all
[800\039] Alcatel-Acce-Priv-F-R1 4294967295
[800\040] Alcatel-Acce-Priv-F-R2 4294967295
[800\041] Alcatel-Acce-Priv-F-W1 4294967295
[800\042] Alcatel-Acce-Priv-F-W2 4294967295
Any ideas?
Thanx
Switch access authentication problems
-
benny
-
yanchick
I tried to change authentication and accounting ports - unfortunately I got the same.
About logs... then I enter wrong name or pass Alcatel return Rejected and ACS reports in Failed attemps:
Mesage type - "Authen failed"
User-Name -
Network Access Profile Name-
Authen-Failure-Code - "ACS user unknown" or "ACS password invalid"
NAS-Port -1001 (it depens on value 0,8 or 4294967295 in attributes column- Alcatel-Acce-Priv-F-R1 and other )
NAS-IP-Address - x.x.x.x
Access Device - Device name
Then I enter right name and pass - nothing in Log (Radius accounting report is empty)
Waiting for reply. Thanx
About logs... then I enter wrong name or pass Alcatel return Rejected and ACS reports in Failed attemps:
Mesage type - "Authen failed"
User-Name -
Network Access Profile Name-
Authen-Failure-Code - "ACS user unknown" or "ACS password invalid"
NAS-Port -1001 (it depens on value 0,8 or 4294967295 in attributes column- Alcatel-Acce-Priv-F-R1 and other )
NAS-IP-Address - x.x.x.x
Access Device - Device name
Then I enter right name and pass - nothing in Log (Radius accounting report is empty)
Waiting for reply. Thanx
-
yanchick
I found the same problem in the old forum
http://old.alcatelunleashed.com/viewtop ... 98&start=0
But I cant read the solution in alcatel knowledge base, because it was deleted. (https://service.esd.alcatel-lucent.com/ ... umber=2272)
http://old.alcatelunleashed.com/viewtop ... 98&start=0
But I cant read the solution in alcatel knowledge base, because it was deleted. (https://service.esd.alcatel-lucent.com/ ... umber=2272)
-
yanchick
-
yanchick
