Analysis, Solution, Symptom 2 – H3C Technologies H3C SecPath F1000-E User Manual
Page 255: Symptom 3
245
Analysis
1.
A communication failure exists between the NAS and the RADIUS server.
2.
The username is not in the format of userid@isp-name or the ISP domain for the user authentication
is not correctly configured on the NAS.
3.
The user is not configured on the RADIUS server.
4.
The password entered by the user is incorrect.
5.
The RADIUS server and the NAS are configured with different shared key.
Solution
Check that:
1.
The NAS and the RADIUS server can ping each other.
2.
The username is in the userid@isp-name format and the ISP domain for the user authentication is
correctly configured on the NAS.
3.
The user is configured on the RADIUS server.
4.
The correct password is entered.
5.
The same shared key is configured on both the RADIUS server and the NAS.
Symptom 2
RADIUS packets cannot reach the RADIUS server.
Analysis
1.
The NAS and the RADIUS server cannot communicate with each other.
2.
The NAS is not configured with the IP address of the RADIUS server.
3.
The UDP ports for authentication/authorization and accounting are not correct.
4.
The port numbers of the RADIUS server for authentication, authorization and accounting are being
used by other applications.
Solution
Check that:
1.
The communication links between the NAS and the RADIUS server work well at both physical and
link layers.
2.
The IP address of the RADIUS server is correctly configured on the NAS.
3.
UDP ports for authentication/authorization/accounting configured on the NAS are the same as
those configured on the RADIUS server.
4.
The port numbers of the RADIUS server for authentication, authorization and accounting are
available.
Symptom 3
A user is authenticated and authorized, but accounting for the user is not normal.
Analysis
1.
The accounting port number is not correct.
2.
Configuration of the authentication/authorization server and the accounting server are not correct
on the NAS. For example, one server is configured on the NAS to provide all the services of
authentication/authorization and accounting, but in fact the services are provided by different
servers.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS