802.1x Configuration + Wired Authentication
Posted: 15 Jul 2021 07:35
Dear Experts
I am stuck in a scenario and need the support.
I want to authenticate my wired users via radius server (my radius server would be my Domain controller).
I'm using windows server 2016 Datacenter and NPAS & ADCS roles are installed on the server. My authenticator in this scenario is Alcatel switch OS6350 ( radius client).
I want my Active directory to authenticate the users via Alcatel Switch.
Below are the commands that i have configured on my switch.
1. vlan port mobile 1/1
2. vlan port 1/1 802.1x enable
3. aaa radius-server radiusservername host 192.168.101.1 key radiuskey
4. aaa authentication 802.1x radiusservername
Can any one explain the actual commands that supposed to be configure on radius client switch.
When i use :-show aaa authentication 802.1x)
I get some results like this:- 1st authentication server = myradiusservername
On this commands :- show radius-server "my radius server name"
I'm getting below results.
Server name = "my radius server name"
Server type = RADIUS,
IP Address 1 = 192.168.x.x,
Retry number = 3,
Time out (sec) = 2,
Authentication port = 1812,
Accounting port = 1813,
Nas port = default,
Nas port id = disable,
Nas port type = ethernet,
Mac Addr Format Status = disable,
Mac Address Format = uppercase,
Unique Acct Session Id = disable,
Health Check Status = DISABLED,
Server oper status = UNKNOWN,
Primary oper status = UNKNOWN,
Primary Server,
Server uptime = -,
Server downtime = -,
No of server up-down = 0,
No of server down-up = 0,
Polling interval = 50,
User name = alcatel,
Failover Status = DISABLED
Please identify, is there any problem in my switch configuration because user is unable to get authentication.
When i connect my user on a port where i have enabled 802.1x, machine gets an error on network adapter as "Authentication failed".
If connected machine is AD member the it gets such message. If the connected device is not the AD member then it get's the IP Address from the server but it does not has internet access.
I am stuck in a scenario and need the support.
I want to authenticate my wired users via radius server (my radius server would be my Domain controller).
I'm using windows server 2016 Datacenter and NPAS & ADCS roles are installed on the server. My authenticator in this scenario is Alcatel switch OS6350 ( radius client).
I want my Active directory to authenticate the users via Alcatel Switch.
Below are the commands that i have configured on my switch.
1. vlan port mobile 1/1
2. vlan port 1/1 802.1x enable
3. aaa radius-server radiusservername host 192.168.101.1 key radiuskey
4. aaa authentication 802.1x radiusservername
Can any one explain the actual commands that supposed to be configure on radius client switch.
When i use :-show aaa authentication 802.1x)
I get some results like this:- 1st authentication server = myradiusservername
On this commands :- show radius-server "my radius server name"
I'm getting below results.
Server name = "my radius server name"
Server type = RADIUS,
IP Address 1 = 192.168.x.x,
Retry number = 3,
Time out (sec) = 2,
Authentication port = 1812,
Accounting port = 1813,
Nas port = default,
Nas port id = disable,
Nas port type = ethernet,
Mac Addr Format Status = disable,
Mac Address Format = uppercase,
Unique Acct Session Id = disable,
Health Check Status = DISABLED,
Server oper status = UNKNOWN,
Primary oper status = UNKNOWN,
Primary Server,
Server uptime = -,
Server downtime = -,
No of server up-down = 0,
No of server down-up = 0,
Polling interval = 50,
User name = alcatel,
Failover Status = DISABLED
Please identify, is there any problem in my switch configuration because user is unable to get authentication.
When i connect my user on a port where i have enabled 802.1x, machine gets an error on network adapter as "Authentication failed".
If connected machine is AD member the it gets such message. If the connected device is not the AD member then it get's the IP Address from the server but it does not has internet access.