cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
659
Views
1
Helpful
18
Replies

Can't authenticate with NPS Radius on CISCO CBS250-24T

Sorin Vlasceanu
Level 1
Level 1

Hello,

I recently started to use NPS Radius (included in Windows Server 2019) to authenticate on a series of Cisco Switches (SF200, SF220, SG200, SG220, SG250, CBS220-8T, CBS220-24T, CBS250-24T, CBS350-24T).

So far only SF220, SG220 and CBS220 are working fine.

The others are returning the error "Invalid user name or password. Please try again"

I am using the GUI interface.

Any ideas?

Thank you.

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - Added reply ; review this thread and check if it can help you :
                         https://community.cisco.com/t5/switches-small-business/radius-on-sf200-24/m-p/2429501#M11421

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

18 Replies 18

marce1000
VIP
VIP

 

           - Check the NPS radius server's   logs for the particular authenticating (and or failing attempts)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hello,

I checked the logs. The most detailed reason for rejecting the connection was that "Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect".

The problem is that from all the switches I use (SF200, SF220, SG200, SG220, SG250, CBS220-8T, CBS220-24T and CBS350) the only ones that works are SF220, SG220 and CBS220. The others present the same problem. All are configured the same. I already tried firmware updates.

An earlier post here (about 2 years ago) was referring to the same issue with SG200. So the problem seams to be old but until now no fix.

Thank you.

 

  >..."Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect".
        - Correct these parameters  ,

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hello,

The username or password is not an issue. I have tried several times and
the credentials are corect. As i said earlier it seems to be an error which
appears only on specific models.

 

 - Can you verify if this syndrome is related to radius (or not) , by  for instance configuring the user local on the device with the same username and password ;                                                                                                       does that work ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hello,

You realize that it's not ok. If I configure the user localy with the same username and password the switch will use those credentials to authenticate me, not the one provided by the RADIUS.

Sorry to repeat myself but the RADIUS server is working fine because it's implemented on some switches and I can authenticate with the credentials it's providing.

The problem appears on specific models. (which I enumerated before).

- It's only asked for a short test ,tx!

M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

With a local user (same username and password or different ones) its
working. That's how I logged in to configure Radius client on the switch.

- Do any of the passwords have special characters ?

M.


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

No. Just small caps, large caps and numbers.

Ok. I will try.
The local user works with all 4 categories.

 

   - What do you mean by '4 categories' ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Small caps, large caps, numbers, special characters (!? _@#$)

 

  - Try to make a  packet capure (using tcpdump , or other tool) ; to examine what is send to the radius server and check if that corresponds with the real credentials entered , (radius  is not encrypted)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '