Extreme C5210, cannot get RADIUS controller logon to work to save my life

  • 0
  • 1
  • Problem
  • Updated 3 years ago
  • Solved
I am attempting to do something really simple. That is, get RADIUS off the ground. I figured the easiest starting task would be to use it for controller management logons, but even this has proved impossible.

Now I am in a situation where RADIUS on my Windows 2008 R2 server is logging a success "Network Policy Server granted full access to a user because the host met the defined health policy" and yet my Extreme controller is denying the logon.

When I run a Wireshark, I can see the ACCESS-REQUEST and ACCESS-ACCEPT messages being exchanged.

So why isn't my Extreme controller happy with this outcome?

SOME PICTURES:









Photo of Steve Ballantyne

Steve Ballantyne

  • 5,682 Points 5k badge 2x thumb

Posted 3 years ago

  • 0
  • 1
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,502 Points 20k badge 2x thumb
You need to return back Service-Type=Administrative 
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,502 Points 20k badge 2x thumb
Also get rid of NAS Port Type VPN as a Condition. 
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,502 Points 20k badge 2x thumb
Let me check out the guides... I'm sure it's there somewhere. 
Photo of Doug Hyde

Doug Hyde, Technical Support Manager

  • 20,502 Points 20k badge 2x thumb
I'm going to add the Adminstrative option to the article. The Enterasys policy string might be confusing if you...
A. Don't know what Enterasys is or means
B. Don't use Policy Manager
Photo of Jeremy

Jeremy, Embassador

  • 9,788 Points 5k badge 2x thumb
Doug, you beat me to it!