<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EXOS does not attempt RADIUS authentication with Secondary server. in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85670#M20612</link>
    <description>I was able to resolve the issue. In the production environment, it turned out that there was a second firewall that had to be configured to allow traffic to the secondary server. In the GNS3 simulation I have no idea what happened but I rebuilt it and it also works there now. I am aware of that bug but I was using later versions of EXOS.</description>
    <pubDate>Thu, 23 May 2019 14:24:48 GMT</pubDate>
    <dc:creator>johnwcalder</dc:creator>
    <dc:date>2019-05-23T14:24:48Z</dc:date>
    <item>
      <title>EXOS does not attempt RADIUS authentication with Secondary server.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85667#M20609</link>
      <description>At the moment I have a problem where a group of Extreme switches configured to use RADIUS authentication do not automatically attempt authentication with the secondary server when the primary server is down.&lt;BR /&gt;
I have been able to replicate this problem in GNS3 with a more simplified setup than what we have in the production environment. I have two radius servers that are identical in every way except their IP addresses, and I have an Extreme switch that is configured to use those servers for authentication.&lt;BR /&gt;
There are no problems authenticating when the primary RADIUS server is running, however, when I shut it down I am no longer able to authenticate when I connect to the Extreme switch. I even did a packet capture on the link and I noticed that the switch doesn't even attempt to send any traffic to the secondary server even when I have shut down RADIUS on the primary server. Is there something I'm missing?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Primary Switch Management RADIUS server: Status is Active&lt;BR /&gt;    host name     :&lt;BR /&gt;    IP address    :  192.168.1.102&lt;BR /&gt;    Server IP Port:  1812&lt;BR /&gt;    Client address:  192.168.1.1 (VR-Default)&lt;BR /&gt;    Retries       :  3 *&lt;BR /&gt;    Timeout       :  3 *&lt;BR /&gt;    shared secret :  #$h+DxdMlNe3EYSMxwsPsNlYj2LWWYxw==&lt;BR /&gt;Access Requests   :  33         Access Accepts    :  5&lt;BR /&gt;Access Rejects    :  2          Access Challenges :  0&lt;BR /&gt;Access Retransmits:  20         Client timeouts   :  26&lt;BR /&gt;Bad authenticators:  0          Unknown types     :  0&lt;BR /&gt;Round Trip Time   :  1&lt;BR /&gt;&lt;BR /&gt;Secondary Switch Management RADIUS server: Status is Active&lt;BR /&gt;    host name     :&lt;BR /&gt;    IP address    :  192.168.1.101&lt;BR /&gt;    Server IP Port:  1812&lt;BR /&gt;    Client address:  192.168.1.1 (VR-Default)&lt;BR /&gt;    Retries       :  3 *&lt;BR /&gt;    Timeout       :  3 *&lt;BR /&gt;    shared secret :  #$JxV/rt7kEyedqcs23mzy3LBwXaPJIw==&lt;BR /&gt;Access Requests   :  12         Access Accepts    :  0&lt;BR /&gt;Access Rejects    :  0          Access Challenges :  0&lt;BR /&gt;Access Retransmits:  12         Client timeouts   :  12&lt;BR /&gt;Bad authenticators:  0          Unknown types     :  0&lt;BR /&gt;Round Trip Time   :  0&lt;BR /&gt;&lt;BR /&gt;Primary Netlogin RADIUS server: Status is Active&lt;BR /&gt;    host name     :&lt;BR /&gt;    IP address    :  192.168.1.102&lt;BR /&gt;    Server IP Port:  1812&lt;BR /&gt;    Client address:  192.168.1.1 (VR-Default)&lt;BR /&gt;    Retries       :  3 *&lt;BR /&gt;    Timeout       :  3 *&lt;BR /&gt;    shared secret :  #$e9OdqIFaHYGPuQcHF3wdhaZCsvWB5Q==&lt;BR /&gt;Access Requests   :  0          Access Accepts    :  0&lt;BR /&gt;Access Rejects    :  0          Access Challenges :  0&lt;BR /&gt;Access Retransmits:  0          Client timeouts   :  0&lt;BR /&gt;Bad authenticators:  0          Unknown types     :  0&lt;BR /&gt;Round Trip Time   :  0&lt;BR /&gt;&lt;BR /&gt;Secondary Netlogin RADIUS server: Status is Active&lt;BR /&gt;    host name     :&lt;BR /&gt;    IP address    :  192.168.1.101&lt;BR /&gt;    Server IP Port:  1812&lt;BR /&gt;    Client address:  192.168.1.1 (VR-Default)&lt;BR /&gt;    Retries       :  3 *&lt;BR /&gt;    Timeout       :  3 *&lt;BR /&gt;    shared secret :  #$jcBzMhO5yJzEuzDJ8M5mt8h3g0Wjvw==&lt;BR /&gt;Access Requests   :  0          Access Accepts    :  0&lt;BR /&gt;Access Rejects    :  0          Access Challenges :  0&lt;BR /&gt;Access Retransmits:  0          Client timeouts   :  0&lt;BR /&gt;Bad authenticators:  0          Unknown types     :  0&lt;BR /&gt;Round Trip Time   :  0&lt;BR /&gt;&lt;BR /&gt;Legend: An asterisk (*) indicates a global value is in use.&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 May 2019 18:35:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85667#M20609</guid>
      <dc:creator>johnwcalder</dc:creator>
      <dc:date>2019-05-21T18:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS does not attempt RADIUS authentication with Secondary server.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85668#M20610</link>
      <description>Hi John,&lt;BR /&gt;
&lt;BR /&gt;
Just to make sure - what version of EXOS do you use for your production and GNS3 testing?&lt;BR /&gt;
Is it ok for you to share the output of 'show configuration aaa'?&lt;BR /&gt;
&lt;BR /&gt;
Kind regards,&lt;BR /&gt;
Tomasz</description>
      <pubDate>Wed, 22 May 2019 01:39:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85668#M20610</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2019-05-22T01:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS does not attempt RADIUS authentication with Secondary server.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85669#M20611</link>
      <description>Hi John,&lt;BR /&gt;
&lt;BR /&gt;
What is the EXOS version? As there is a known bug for that in prior EXOS 16.1 version.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
David</description>
      <pubDate>Wed, 22 May 2019 08:51:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85669#M20611</guid>
      <dc:creator>David_Choi</dc:creator>
      <dc:date>2019-05-22T08:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS does not attempt RADIUS authentication with Secondary server.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85670#M20612</link>
      <description>I was able to resolve the issue. In the production environment, it turned out that there was a second firewall that had to be configured to allow traffic to the secondary server. In the GNS3 simulation I have no idea what happened but I rebuilt it and it also works there now. I am aware of that bug but I was using later versions of EXOS.</description>
      <pubDate>Thu, 23 May 2019 14:24:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-does-not-attempt-radius-authentication-with-secondary/m-p/85670#M20612</guid>
      <dc:creator>johnwcalder</dc:creator>
      <dc:date>2019-05-23T14:24:48Z</dc:date>
    </item>
  </channel>
</rss>

