cancel
Showing results for 
Search instead for 
Did you mean: 

How to remove the External Radius Server object from HM ?

How to remove the External Radius Server object from HM ?

prashan
New Contributor III

I tried to remove external radius server object from HM. But when i try to remove the object, it will give following error . "The External RADIUS Server cannot be removed because it is used by another object (RADIUS Client Object Entry). Please disassociate references from other configuration items before removing the item."

 

I don't find any RADIUS Client Object Entry in HM

 

Can any expert help me out here

1 ACCEPTED SOLUTION

samantha_lynn
Esteemed Contributor III

If all of your APs are showing a green check mark next to the host name on the Monitor page, then you'll just want to click on that green check mark, which will open the audit view. You'll want to go to the Complete tab in the audit view, and check the output shown there to see what Radius object it has in use. We'll only need this from one AP per network policy you have deployed, again as long as all APs are fully updated currently. If they are not fully updated, we'll want to push a complete configuration, and then try to delete the Radius object again. If you're unable to push a complete configuration, we'd have to SSH in to each AP and run the commands "console page 0" and "show run", and then check that output for the Radius server in use.

View solution in original post

24 REPLIES 24

AnonymousM
Valued Contributor II
Hi all,

I’ve solved it by reinstalling a brand new HiveManager (on-premises).
Though this is not ideally for must of you, the existence of a non-removable object annoyed me too much.

Met vriendelijke groet,

Jeroen Bakker
Senior Technical Consultant & Security Officer

Overschieseweg 323 | Schiedam
Algemeen: 010 - 591 10 21
Direct: 088 - 676 37 57
j.bakker@ormer.nl | www.ormer.nl

* Afwezig op dinsdag

wies_hays
New Contributor III

Nicholas described the solution to get around this!

 

 

The core of this is, that web user interface lets you edit "External RADIUS Servers"(Configure/Common Objects/Aujtentication), but not "RADIUS Server groups".

 

"RADIUS Server groups" is what you actually apply to the Authentication Settings of an SSID with Enterprise Authentication.

 

AFAIK this is the only place where you can configure "RADIUS Server Groups", though the interface is titled "Configure RADIUS Servers" (IMHO this should be changes to something like "Configure RADIUS server group").

 

Here are the steps how to reproduce that problem (applies to  12.8.2.2-NGVASEP18 ... that's on-prmisses, not the cloud version)

 

  1. Create a few External RADIUS server objects under "Common Objects/AUTHENTICATION".
  2. Create a new policy or use an existing one: Create a new SSID (standard network) in that policy. In "SSID Usage/SSID Authentication" select "Enterprise".
  3. Under "Authentication Settings"/Authenticate via RADIUS Server click on the "+" next to "Default RADIUS Server Group"
  4. Dialogue "Configure RADIUS server group" opens. Enter a name for your RADIUS Server group.
  5. Click on the "select"-icon right of the "ADD"-button.
  6. Select one or more of the Objects you created in step 1. Then click on "SELECT SERVERS".
  7. Back to the previous dialogue click on "SAVE RADIUS".
  8. Back the "Wireles Network" configuration enter a name for the SSID then click on "SAVE".
  9. Click on "NEXT" untill you see the "UPLOAD" button. You don't have to upload!
  10. Now back to CONFIGURE/NETWORK POLICIES and delete the SSID you just created (by clicking on the trash can the pops once the mouse pointer is over the SSID object.). You can also delete the policy if it was just for testing..
  11. Now go to CONFIGURE/COMMON OBJECTS/POLICY/SSIDs. Also delete your SSID there.
  12. Finally go back to CONFIGURE/COMMON OBJECTS/AUTHENTICATION/External RADIUS Servers" and delete the objects you created in step 1.

 

You will find that objects you did not select for your Group (step 6) can easily be deleted.

 

Those you did select, cannot be deleted with error: "The External RADIUS Server cannot be removed because it is used by another object (RADIUS Client Object Entry). Please disassociate references from other configuration items before removing the item."

The "Used by" in this table is empty of course.

 

The only way to delete these objects is as Nicholas described:

Create a new SSID with Enterprise authentication and click on the "select"-icon next to "Default RADIUS Server Group". Here you can see the group you created and are able to delete it.

 

Once you have done that, you are also able to delete your External RADIUS Server objects.

 

I hope AeroHive will improve this. IMHO The groups must be editable under COMMON OBJECTS/AUTHENTICATION.

Thanks for the instructions, yet i have still the problem, that i cant delete the Radius Server Group, even if i ,as you described create a new SSID (in Enterprise mode). The error message still remains the same. Is there any way to fix this?

Thanks in advance for your help! 🙂

(I am using the cloud version of Cloud IQ)

nicholas_moore
New Contributor

Based on the error message given by Prashan, there is a RADIUS Server Group object that is still using the servers you are trying to delete. You would want to go into a RADIUS SSID(or create one) then use the Select icon next to RADIUS Server Groups. From here, you can delete the groups, freeing the RADIUS Server for deletion from Common Objects.

GTM-P2G8KFN