cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
724
Views
0
Helpful
8
Replies

IOS XR and Freeradius

Hello everyone!

 

I'm trying to configure AAA authentication on my ASR9K box with remote freeradius server and the problem is that ios xr prepands extra symbols to User-Password attribute:

User-Password = "qwerty\000\001P\036`\264O\223\265|"

as result i get this message:

pap: ERROR: MD5 digest does not match "known good" digest

 

How can i fix that?

 

8 REPLIES 8
Highlighted
Cisco Employee

Re: IOS XR and Freeradius

This is very strange because ASR9k should not prepend any characters. Are you sure it's the asr9k who does the prepending? What IOS XR release are you running?

Highlighted

Re: IOS XR and Freeradius

Aleksandar,

 

my assumption is based on fact, that there is no problem with other devices that use same radius server.

For an example all is ok with ASR1k, 7604, ME3600x.

I use same configuration of AAA, secret key and user/password for all devices.

Highlighted
Cisco Employee

Re: IOS XR and Freeradius

what IOS XR release are you running on the asr9k?

Highlighted

Re: IOS XR and Freeradius

Version 5.3.4

disk0:asr9k-mpls-px-5.3.4

disk0:asr9k-mini-px-5.3.4
disk0:asr9k-mgbl-px-5.3.4
disk0:asr9k-mcast-px-5.3.4
disk0:asr9k-k9sec-px-5.3.4
disk0:asr9k-fpd-px-5.3.4
disk0:asr9k-px-5.3.4.sp3-1.0.0
disk0:asr9k-doc-px-5.3.4

Highlighted
Cisco Employee

Re: IOS XR and Freeradius

This doesn't ring a bell and I also can't find records of similar bugs in our database. I see that you are still running SP3. Could you install the latest Service Pack (SP9). If the problem still remains, you can use "debug radius authentication" and "debug radius detail" to see what the asr9k is sending to and receiving from the radius server.

Highlighted
Beginner

Re: IOS XR and Freeradius

Hello Alexander,
I'm experiencing your same issue with version disk0:asr9k-os-mbi-6.1.4
Other asr9k with disk0:asr9k-os-mbi-6.4.2 it's working fine.

Did you find any workaround to fix in older version?

Thanks,
Giacomo
Highlighted

Re: IOS XR and Freeradius

Hello!
The bug was opened on this case:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvi31649

I did't have time to try workaround because changed my job.
Highlighted
Beginner

Re: IOS XR and Freeradius

Hello, this is unrelated but could you post the config for the ASR9k freeradius authentication.

I have problems  with MSCHAPv2 authentication. Is it even supported? We are using it without issues on Cisco Nexuses.

Thanks

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here