cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
1752
Views
0
Helpful
12
Replies

User authentication request was rejected by server on Radius Server

Fachrezi Aldian
Level 1
Level 1

Hello everyone

I have a cisco Catalyst C2960X and configured radius.
I have configured it, but when I try to test group aaa, there is the following information:
User authentication request was rejected by server.

Then I checked the radius server clearpass, there is no log from my ip switch.
Can anyone explain what I should do?
Thank you

12 Replies 12

debug aaa auth 

debug radius 
share above two 

MHM

Fachrezi Aldian
Level 1
Level 1

C2960X_Lt4_A#debug radius
Radius protocol debugging is on
Radius protocol brief debugging is off
Radius protocol verbose debugging is off
Radius packet hex dump debugging is off
Radius packet protocol debugging is on
Radius elog debugging debugging is off
Radius packet retransmission debugging is off
Radius table debugging is on
Radius server fail-over debugging is off

 

C2960X_Lt4_A#debug aaa authentication
AAA Authentication debugging is on

Yes friend 
now try access and share the output of debug 

Thanks 

MHM

Sorry, I don't understand what you mean, where are we trying to access this from?

You config radius for login auth?

If yes the  try access to SW via VTY

Or run test again 

And share the output of debug 

MHM

I configured the switch as a radius client, and as a radius server it is an Aruba celarpass

""I have configured it, but when I try to test group aaa, there is the following information:
User authentication request was rejected by server.""

You test aaa group  and failed 

Do same test again and share output of debug 

MHM

C2960X_Lt4_A#test aaa group radius server "x.x.x.x" "user" "password" legacy
Attempting authentication test to server-group radius using radius
User authentication request was rejected by server.

 

And there is no debug at all???

MHM

yes, i can't see the debug

 

Can I see the radius config 

And exact modle of aruba 

MHM

aaa group server tacacs+ clearpass
!
aaa authentication login default group tacacs+ local
aaa authentication dot1x default group radius
aaa authorization exec default group tacacs+ if-authenticated
aaa authorization network default group radius
aaa accounting dot1x default start-stop group radius
aaa accounting exec default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
!
!
!
!
!
aaa server radius dynamic-author
client "x.x.x.x" server-key 7 06071D344E4F584B56
port 3799
auth-type all

 

the aruba is appliance, aruba clearpass c1000s-1200r4 sw appliance