Mystical Radius Support on Cisco SG200-26 Smart Switch not working :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-09-2015 03:23 AM
Good Day Everyone,
Support Request: SR636256465
I have a problem with mythical radius and 802.1x support on a brand new SG200-26
Info as follows :
1.4.1.3 | |
a325fec192ba4927b6809c1867a22278 | |
1.3.5.06 | |
da8bcdbf216c7df1a3bcb41ec8669e76 | |
en-US | |
1.4.1.3 | |
|
Local support in Thailand can not give me any clear answers, so here goes ...
I have a working Radius server on the network, and bought the SG200-26 as well as other SG200-08 switches to do
1) Vlan sepperation of the school network.
2) Do 802.1x authentication with radius as well as dynamic vlan assignment etc...
Now, the fun starts ....
Configured all stuff as it should be, and the sg200-26 does not send a single byte to the radius server, checked it with wireshark and tcpdump ....
No transmission of anything to radius .....
Mystical radius support indeed ......
anyone care to give me some insights ?? it will be appreciated ...
Regards
Jean
- Labels:
-
Small Business Switches
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-10-2015 01:05 PM
just first shot: did you used domain name of RADIUS server(s) and just forgot to configure DNS server IPs on switch?
secondly: example configuration snip could help audience to understand your setup and increase chance to get your issue solved
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-10-2015 07:14 PM
Hi Michal,
Thanks for the reply :)
We have decided to scrap the cisco switch and go with something else, but in answer to your questions
1) No, I have used the ip-address for the server.
2) Description of my setup ...
The SG200-26 is connected to a PFSense Firewall box with a trunk port to carry vlan traffic.
Freeradius is also running on this PFSense Box.
Required functionality would be
1) vlan separation of the school network. - Working OK
2) Radius Authentication - 802.1x and or Plain MAC-Authentication of workstations connected to the physical network
3. dynamic Vlan assignment by Radius and switch
Radius Config : radiusd.conf
users file
The config is standard and works with other devices.
I have been able to get the switch to authenticate by radius after a complete factory restore and reconfig.
802.1x and mac authentication still doesnt work. Can see eap packets being generated now, before there was none, but the switch never tries to communicate with radius to auth a port...
Will upload wireshark captures today :)
