cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
697
Views
0
Helpful
2
Replies

EAP-FAST not working

mjakobsson
Level 1
Level 1

Hi,

Having a problem here at our site when we´re trying to make EAP-FAST work.

The setup involves a

ACS Release 3.3(2) Build 2

The AP is a AIR-AP1131AG-E-K9 with c1130-k9w7-tar.123-4.JA as IOS

and on the client we´re running XP SP2 with ADU 2.1.0.2.

The ACS is configured for EAP-FAST authentication and the AP is also configured as a AAA client on the ACS.

The Radius authentication from the AP to the ACS works ok if we´re making an “Admin Access”.

But if we´re trying to make a EAP-FAST authentication from the client, a debug shows that nothing goes from the AP to the ACS.

The Local Radius Server on the AP is not activated, but the error message on the client is the same as described in the Release Notes for Cisco Aironnet 802.11a/b/g Client Adapters (CB21AG and PI21AG) Install Wizard 2.1, i.e. “Unable to EAP-FAST authenticate the wireless user in the specified amount of time. Network infrastructure might be down”.

Anyone got any idea?

2 Replies 2

jmagnusson
Level 1
Level 1

need to see configs....

aaa group server radius data_roamers

server "ACS IP" auth-port 1645 acct-port 1646

aaa group server radius infra_roamers

server "ACS ip " auth-port 1645 acct-port 1646

!

aaa authentication login default local

aaa authentication login eap_methods group rad_eap

aaa authentication login mac_methods local

aaa authentication login method_data_roamers group data_roamers

aaa authentication login method_infra_roamers group infra_roamers

aaa authorization exec default local

aaa accounting network acct_methods start-stop group rad_acct

aaa session-id common

Here comes parts of it.

ip subnet-zero

!

aaa new-model

!

aaa group server radius rad_eap

server 192.168.244.95 auth-port 1645 acct-port 1646

!

aaa group server radius rad_mac

!

aaa group server radius rad_acct

!

aaa group server radius rad_admin

server 192.168.244.95 auth-port 1645 acct-port 1646

!

aaa group server tacacs+ tac_admin

!

aaa group server radius rad_pmip

!

aaa group server radius dummy

!

aaa authentication login default local group tac_admin group rad_admin

aaa authentication login eap_methods group rad_eap

aaa authentication login mac_methods local

aaa authorization exec default local group tac_admin group rad_admin

aaa accounting network acct_methods start-stop group rad_acct

aaa session-id common

!

dot11 ssid ltbwllabb

authentication open

authentication network-eap eap_methods

!

power inline negotiation prestandard source

!

bridge irb

!

interface Dot11Radio0

no ip address

no ip route-cache

!

encryption key 1 size 128bit 7 F8CB09E06BB1A1B52B356D940C96 transmit-key

encryption key 2 size 128bit 7 CC93E7F398F69CD59F929FECC2A8

encryption key 3 size 128bit 7 6463D7EEE6D2EA8EA0A2CA739EA0

encryption mode wep mandatory

!

ssid ltbwllabb

!

short-slot-time

speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0

station-role root

no cdp enable

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio1

no ip address

no ip route-cache

!

encryption key 1 size 128bit 7 F8CB09E06BB1A1B52B356D940C96 transmit-key

encryption key 2 size 128bit 7 CC93E7F398F69CD59F929FECC2A8

encryption key 3 size 128bit 7 6463D7EEE6D2EA8EA0A2CA739EA0

encryption mode wep mandatory

!

ssid ltbwllabb

!

speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0

station-role root

no cdp enable

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface FastEthernet0

no ip address

no ip route-cache

duplex auto

speed auto

bridge-group 1

no bridge-group 1 source-learning

bridge-group 1 spanning-disabled

!

interface BVI1

ip address dhcp client-id FastEthernet0

no ip route-cache

!

ip http server

ip http authentication aaa

no ip http secure-server

ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag

ip radius source-interface BVI1

!

radius-server local

no authentication eapfast

no authentication leap

no authentication mac

!

radius-server attribute 32 include-in-access-req format %h

radius-server host 192.168.244.95 auth-port 1645 acct-port 1646 key 7 020B105A0F

radius-server vsa send accounting

!

control-plane

!

bridge 1 route ip

!

Review Cisco Networking for a $25 gift card