<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Identify: short 802.1X EAP-PEAP sessions with Acct-Terminate-Cause = 105 in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28946#M137</link>
    <description>Hello Umut,    Thanks for your quick reply.    I suppose the source code abstract is from the EWC software. Are other non-standard Acct-Terminate-Cause values available somewhere (as this can be useful for any further troubleshooting).    Can you also clarify when this CHANGED_WLAN_SERVICE condition is raised? Is this when the user changes IP address? The VNS associated with the SSID where the problem arises uses the same role for Non-Authenticated and Authenticated users.    In the logs and the RADIUS accounting, I see that for the short sessions may have or not have a valid associated IP address (some have 0.0.0.0 or an IP in the link-local range).    The network where the SSID is deployed is known to have a slow DHCP server (IP address attribution can take several seconds). For the IP range associated to the SSID, lease has been set to a long value (1 week) as this is supposed to help troubleshooting.    Would the option "Defer sending the accounting start request until the client's IP address is known." in the "VNS" / "Global" / "Authentication" / "Advanced" section help? If not, I will make a request for the DHCP lease to be reduces (then is a value of a few hours suitable?).    Regards,</description>
    <pubDate>Wed, 17 May 2017 14:45:00 GMT</pubDate>
    <dc:creator>gherbiet</dc:creator>
    <dc:date>2017-05-17T14:45:00Z</dc:date>
    <item>
      <title>Identify: short 802.1X EAP-PEAP sessions with Acct-Terminate-Cause = 105</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28944#M135</link>
      <description>Hello community,&lt;BR /&gt;
&lt;BR /&gt;
I have set up an EAP-PEAP 802.1X SSID in bridge at EWC topology on a cluster of C5210 running 09.21.16.0013 (as we need to support a couple of 3600 series APs). I have seen a couple of changes in 9.21.17.0006 related to RADIUS but I don't think it is related to the problem I am facing.&lt;BR /&gt;
&lt;BR /&gt;
The RADIUS authentication is performed by a FreeRADIUS server (version 2.2.5, installed from packages on a Debian "Jessie" 8.8).&lt;BR /&gt;
&lt;BR /&gt;
I have noticed that a lot of users are experiencing very short sessions (in the order of 0 to a few seconds) that terminate with an Accounting-Stop message with the Acct-Terminate-Cause attribute set to "105". When the end-devices have stored the network credentials then authentication reoccurs. However, when this is not the case they are just disconnected from the network and do not reconnect.&lt;BR /&gt;
&lt;BR /&gt;
On the controller side, the relevant options are:&lt;BR /&gt;
&lt;BR /&gt;
In "VNS" / "Global" / "Authentication" / "RADIUS Servers" / "RADIUS Settings" (click on the RADIUS Alias in the Servers table:&lt;BR /&gt;
- Interim Accounting Interval: 5 (minutes)&lt;BR /&gt;
- Send Interim Accounting Records for: Fast Failover Events: checked&lt;BR /&gt;
&lt;BR /&gt;
On the same page, on the "Advanced" window, "RADIUS Accounting" is checked as well.&lt;BR /&gt;
&lt;BR /&gt;
Finally under "VNS" / "WLAN Services" / "&lt;NAMEOFMYWLAN&gt;" / "Auth &amp;amp; Acct", in the "Radius TLVs" (that shall spell "RADIUS TLVs" btw), all VSAs are checked, "Replace Called Station ID with Zone name in RADIUS Requests" is unchecked.&lt;BR /&gt;
&lt;BR /&gt;
On the RADIUS server side, the relevant attributes associated to users that face this issue are as follows:&lt;BR /&gt;
- Idle-Timeout := 600&lt;BR /&gt;
&lt;BR /&gt;
I use the same RADIUS server with Wi-Fi network from other vendors and I did not face this issue.&lt;BR /&gt;
&lt;BR /&gt;
Do you have an idea of what might cause the controller to prematurely stop the RADIUS session, especially with this this Acct-Terminate-Cause value (that is not documented in RFC 2866) ?&lt;/NAMEOFMYWLAN&gt;</description>
      <pubDate>Wed, 17 May 2017 13:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28944#M135</guid>
      <dc:creator>gherbiet</dc:creator>
      <dc:date>2017-05-17T13:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: Identify: short 802.1X EAP-PEAP sessions with Acct-Terminate-Cause = 105</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28945#M136</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
the meaning of this should be&lt;BR /&gt;
&lt;BR /&gt;
Acct-Terminate-Cause attribute set to "105".&lt;BR /&gt;
&lt;BR /&gt;
--&amp;gt; #define  CHANGED_WLAN_SERVICE            105&lt;BR /&gt;
&lt;BR /&gt;
Look if the user get IP in the new SSID?&lt;BR /&gt;
&lt;BR /&gt;
Decrease the leased time on DHCP Server?&lt;BR /&gt;
&lt;BR /&gt;
    &lt;BR /&gt;
Regards&lt;BR /&gt;
Umut&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 17 May 2017 14:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28945#M136</guid>
      <dc:creator>Umut_Aydin</dc:creator>
      <dc:date>2017-05-17T14:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Identify: short 802.1X EAP-PEAP sessions with Acct-Terminate-Cause = 105</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28946#M137</link>
      <description>Hello Umut,    Thanks for your quick reply.    I suppose the source code abstract is from the EWC software. Are other non-standard Acct-Terminate-Cause values available somewhere (as this can be useful for any further troubleshooting).    Can you also clarify when this CHANGED_WLAN_SERVICE condition is raised? Is this when the user changes IP address? The VNS associated with the SSID where the problem arises uses the same role for Non-Authenticated and Authenticated users.    In the logs and the RADIUS accounting, I see that for the short sessions may have or not have a valid associated IP address (some have 0.0.0.0 or an IP in the link-local range).    The network where the SSID is deployed is known to have a slow DHCP server (IP address attribution can take several seconds). For the IP range associated to the SSID, lease has been set to a long value (1 week) as this is supposed to help troubleshooting.    Would the option "Defer sending the accounting start request until the client's IP address is known." in the "VNS" / "Global" / "Authentication" / "Advanced" section help? If not, I will make a request for the DHCP lease to be reduces (then is a value of a few hours suitable?).    Regards,</description>
      <pubDate>Wed, 17 May 2017 14:45:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28946#M137</guid>
      <dc:creator>gherbiet</dc:creator>
      <dc:date>2017-05-17T14:45:00Z</dc:date>
    </item>
    <item>
      <title>RE: Identify: short 802.1X EAP-PEAP sessions with Acct-Terminate-Cause = 105</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28947#M138</link>
      <description>Hi Guillaume-Jean,&lt;BR /&gt;
&lt;BR /&gt;
this happens CHANGED_WLAN_SERVICE if the user need or should change his SSID/TOPOLOYG(VLAN) after succesfully authentication.&lt;BR /&gt;
Since he stuck in the old SSID IP world the client doesn't renew his IP.&lt;BR /&gt;
Therefore if you wanted change the WLAN ( to other SSID ) then you need lower the DHCP lease time so that the Client ask faster for his new IP  .&lt;BR /&gt;
&lt;BR /&gt;
This point provides improvements.&lt;BR /&gt;
&lt;BR /&gt;
1.Change unauthenticated behavior to "Discard Unauthenticated Traffic"  in the non-auth policy. &lt;BR /&gt;
2.Super low lease timer in the start off topology.&lt;BR /&gt;
3.Under the MAC Authorization Config, checking the option "RADIUS Accounting begins after MAC-based authorization completes". &lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
&lt;BR /&gt;
Umut&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 18 May 2017 13:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/identify-short-802-1x-eap-peap-sessions-with-acct-terminate/m-p/28947#M138</guid>
      <dc:creator>Umut_Aydin</dc:creator>
      <dc:date>2017-05-18T13:52:00Z</dc:date>
    </item>
  </channel>
</rss>

