ZXR102900ESeriesCongurationGuide
authenticationfunctionontheaccesslayerdeviceofsixbuildingsofstudentareainthe
speciedtime.ThecongurationofZXR102900Eisasfollows:
ThetwodevicesconnectedwiththetwoportsinthesameVLANcannotpingeachother.
setport1-24securityenable
confignas
radiusisptestdefaultispenable
radiusisptestsharedsecretamtium
/*ThesharingkeynegotiatedwithcompanyB*/
radiusisptestaddaccounting10.150.12.101
/*CompanyBauthenticationandaccountingserveraddress*/
radiusisptestaddauthentication10.150.12.101
/*CompanyBauthenticationandaccountingserveraddress*/
radiusisptestclient172.16.0.181
/*ConfigureISPnameandtheIPaddressofaccessswitch*/
aaa-controlport1-24dot1xenable
aaa-controlport1-24accountingenable
aaa-controlport1-24port-modeauto
Whenthecongurationiscompleted,somehostsofB1,B2andB3threebuildinghave
“authenticationtimeout”problem.
FaultAnalysisandLocation
Whenthestudentaccountnumberandpasswordarechecked,theinternalnetwork
authenticationstillcannotbepassed.Aftercheckingalltherelatedcongurationof
ZXR102900Eindetail,theproblemstillexists.Also,changeonenewZXR102900E,the
problemstillexists.Thediagnosisresultisthattheproblemisinterconnectionbetween
thetwodevices.
Bythepacketsnifng,wendthatZXR102900EsendsAccessRequestofradiusprotocol
toaccountingserverofcompanyBbutthelaterresponsemessageisnotreceived.In
normalcircumstance,theradiusprotocolmessagereceivingandsendingprocedureisas
follows:
AccessswitchsendsAccessRequestmessage
ServerreturnsAccessChallengemessage
SwitchsendsAccessRequestmessageagain
ServerreturnsAccessAcceptmessage
SwitchsendsAccountingRequestmessage
ServerreturnsAccountingResponsemessage
BecausetheproceduresofauthenticationdatapacketssniffedfromthetwosameZXR10
2900Esarenotsame,thediagnosisresultiscompanyBaccountingserverconguration
problem.TheengineerofcompanyBchecksthealarminformationoftheirserver,nd
thatthealarmofAPnotsupportuserauthtypeexists,thatis,theauthenticationtypes
6-8
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential