08-22-2023 12:55 AM
Hello
When accessing a switch device in a remote location, you want to log in as an administrator by connecting the Radius Server, not the local account.
It was confirmed that the Genian NAC server was connected to the Radius server and login was successful.
It has also been confirmed that login failure logs are left normally if the account information is incorrect when attempting to log in.
However, the problem is that if the administrator login is successful, the normal authentication log cannot be left.
To solve this problem, it is said that the IP or MAC Address information of the client that tried to log in to the NAC server must be transmitted.
Specifically, MAC Address information should be transmitted to the Calling-Station-Id Field or IP Address information should be transmitted to the Framed-IP-Address Field.
I tried to transmit the information through the radius attribute setting, but it was not successful. Without dot1x setting, only IP address information could be transmitted to Calling-Station-ID Field.
In summary, when an administrator accesses a switch from a remote location, authentication must be required through the Radius Server. do.
thank you
08-29-2023 10:45 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide