07-18-2005 04:10 AM - edited 07-04-2021 10:58 AM
Hi,
Having a problem here at our site when we´re trying to make EAP-FAST work.
The setup involves a
ACS Release 3.3(2) Build 2
The AP is a AIR-AP1131AG-E-K9 with c1130-k9w7-tar.123-4.JA as IOS
and on the client we´re running XP SP2 with ADU 2.1.0.2.
The ACS is configured for EAP-FAST authentication and the AP is also configured as a AAA client on the ACS.
The Radius authentication from the AP to the ACS works ok if we´re making an Admin Access.
But if we´re trying to make a EAP-FAST authentication from the client, a debug shows that nothing goes from the AP to the ACS.
The Local Radius Server on the AP is not activated, but the error message on the client is the same as described in the Release Notes for Cisco Aironnet 802.11a/b/g Client Adapters (CB21AG and PI21AG) Install Wizard 2.1, i.e. Unable to EAP-FAST authenticate the wireless user in the specified amount of time. Network infrastructure might be down.
Anyone got any idea?
07-21-2005 12:33 PM
need to see configs....
aaa group server radius data_roamers
server "ACS IP" auth-port 1645 acct-port 1646
aaa group server radius infra_roamers
server "ACS ip " auth-port 1645 acct-port 1646
!
aaa authentication login default local
aaa authentication login eap_methods group rad_eap
aaa authentication login mac_methods local
aaa authentication login method_data_roamers group data_roamers
aaa authentication login method_infra_roamers group infra_roamers
aaa authorization exec default local
aaa accounting network acct_methods start-stop group rad_acct
aaa session-id common
07-22-2005 02:11 AM
Here comes parts of it.
ip subnet-zero
!
aaa new-model
!
aaa group server radius rad_eap
server 192.168.244.95 auth-port 1645 acct-port 1646
!
aaa group server radius rad_mac
!
aaa group server radius rad_acct
!
aaa group server radius rad_admin
server 192.168.244.95 auth-port 1645 acct-port 1646
!
aaa group server tacacs+ tac_admin
!
aaa group server radius rad_pmip
!
aaa group server radius dummy
!
aaa authentication login default local group tac_admin group rad_admin
aaa authentication login eap_methods group rad_eap
aaa authentication login mac_methods local
aaa authorization exec default local group tac_admin group rad_admin
aaa accounting network acct_methods start-stop group rad_acct
aaa session-id common
!
dot11 ssid ltbwllabb
authentication open
authentication network-eap eap_methods
!
power inline negotiation prestandard source
!
bridge irb
!
interface Dot11Radio0
no ip address
no ip route-cache
!
encryption key 1 size 128bit 7 F8CB09E06BB1A1B52B356D940C96 transmit-key
encryption key 2 size 128bit 7 CC93E7F398F69CD59F929FECC2A8
encryption key 3 size 128bit 7 6463D7EEE6D2EA8EA0A2CA739EA0
encryption mode wep mandatory
!
ssid ltbwllabb
!
short-slot-time
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio1
no ip address
no ip route-cache
!
encryption key 1 size 128bit 7 F8CB09E06BB1A1B52B356D940C96 transmit-key
encryption key 2 size 128bit 7 CC93E7F398F69CD59F929FECC2A8
encryption key 3 size 128bit 7 6463D7EEE6D2EA8EA0A2CA739EA0
encryption mode wep mandatory
!
ssid ltbwllabb
!
speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
station-role root
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface BVI1
ip address dhcp client-id FastEthernet0
no ip route-cache
!
ip http server
ip http authentication aaa
no ip http secure-server
ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
ip radius source-interface BVI1
!
radius-server local
no authentication eapfast
no authentication leap
no authentication mac
!
radius-server attribute 32 include-in-access-req format %h
radius-server host 192.168.244.95 auth-port 1645 acct-port 1646 key 7 020B105A0F
radius-server vsa send accounting
!
control-plane
!
bridge 1 route ip
!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide