ZXR105250SeriesCongurationGuide
confignas
radiusisptestdefaultispenable
radiusisptestsharedsecretamtium
/*SharedkeynegotiatedwithcompanyB*/
radiusisptestaddaccounting10.150.12.101
/*AddressoftheauthenticationandaccountingserverofcompanyB*/
radiusisptestaddauthentication10.150.12.101
/*AddressoftheauthenticationandaccountingserverofcompanyB*/
radiusisptestclient172.16.0.181
/*ISPnameandIPaddressaccessingtheswitch*/
aaa-controlport1-24dot1xenable
aaa-controlport1-24accountingenable
aaa-controlport1-24port-modeauto
Whenthecongurationwascompleted,theauthenticationofsomecomputersinB1,B2
andB3timedout.
FaultAnalysis
Thestudents’accountsandcongurationwerecorrect,andthecongurationoftheZXR10
5250wascorrect.EvenifZTE’smaintenanceengineersreplacedthefaultyswitchwith
anewone,theproblemstillexisted.Thediagnosisresultwasthattheinterconnection
betweendevicesofZTEandcompanyBwasfaulty.
Bycapturingpackets,ZTE’smaintenanceengineersfoundthattheZXR105250senta
RadiusAccessRequestmessagetotheauthenticationandaccountingserverofcompany
B,butdidnotreceivearesponsemessage.Innormalcircumstance,theRadiusmessage
receivingandsendingprocedureisasfollows:
1.Whentheserveraccessestheswitch,theswitchsendsanAccessRequestmessage.
2.TheserverreturnsanAccessChallengemessage.
3.TheswitchsendsanAccessRequestmessageagain.
4.TheserverreturnsanAccessAcceptmessage.
5.TheswitchsendsanAccountingRequestmessage.
6.TheserverreturnsanAccountingResponsemessage.
BecausetheauthenticationdatapacketowscapturedonthetwosameZXR105250
deviceswerenotthesame,thediagnosisresultwasthatthecongurationofthe
authenticationandaccountingserverofcompanyBwasincorrect.Engineersofcompany
Bcheckedalarmsontheauthenticationandaccountingserver,andanalarm"APnot
supportuserauthtype”waslocated.Thatis,authenticationtypesoftheserverand
theswitchweredifferent.Whentheback-endcongurationoftheauthenticationand
accountingserverwaschecked,itwasfoundthatthesharedkeyontheswitchesof
buildingsB1,B2andB3wassetto“antium”,butthenegotiatedkeywas"amtium".
7-8
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential