12-21-2020 09:05 AM
Hi,
I am facing some strange thing.
using MAC authentication on a ERS4900 switch for a Canon printer, the printer is losing connections after a while and the state description in XMC Control is “The session is no longer active due to: User-Request.”
what can cause this and how to avoid it?
kind regards
Mark van Strien
Solved! Go to Solution.
12-22-2020 10:02 PM
Mark
With such symptoms, I would check the EAP timeouts and double check if STP admin-edge is enabled on the ports.
Mig
12-21-2020 04:01 PM
Hello Mark,
if there is no mac on the port no authentication can happen.
It seems that the printer does take the port down, i.e. it falls to any power safe state. Please check the printer settings again.
12-21-2020 04:01 PM
On the EXOS side of things, ran into similar issue and had to adjust the iparp timeout to 5 minutes. A constant ping should have worked to bypass arp timeout, so this may be a totally different issue.
12-21-2020 03:59 PM
i made an export of the end-system events for the test printer.
ID,"State","Time Stamp","MAC Address","Device Family","Device Type","IP Address","Host Name","User Name","Auth Type","Reason","Profile","Switch IP","Switch Nickname","Switch Port","Switch Location","Authorization","Access Control Engine/Source IP","Event Source","RADIUS Server IP","Extended State","State Description","Last Scan Time","Switch Port Index","Port Info Raw","ELIN","Zone","Registration Type"
23830,"Disconnected","12/21/2020 04:49:07 PM","00:BB:C1:74:8A:3B","","","172.21.103.194","c1056.domain.lan","","MAC (PAP)","Rule: ""ERS PRN CANON""","ADRZ PRN CANON","192.168.150.55","192.168.150.55","0/1","","FA-VLAN-Create='1', FA-VLAN-ISID='102:102', FA-VLAN-PVID='102', FA-Client-Trust='1', Egress-VLANID='0x32000066'","172.21.0.37","Access Control Engine","","","The session is no longer active due to: User-Request.","--","1","IFNAME=0/1 IFDESC=Extreme Networks Ethernet Routing Switch 4950GTS-PWR+ Module - Port 1","","",""
23823,"Accept","12/21/2020 03:14:24 PM","00:BB:C1:74:8A:3B","","","172.21.103.194","c1056.domain.lan","","MAC (PAP)","Rule: ""ERS PRN CANON""","ADRZ PRN CANON","192.168.150.55","192.168.150.55","0/1","","FA-VLAN-Create='1', FA-VLAN-ISID='102:102', FA-VLAN-PVID='102', FA-Client-Trust='1', Egress-VLANID='0x32000066'","172.21.0.37","Access Control Engine","","","","--","1","IFNAME=0/1 IFDESC=Extreme Networks Ethernet Routing Switch 4950GTS-PWR+ Module - Port 1","","",""
23820,"Accept","12/21/2020 03:14:14 PM","00:BB:C1:74:8A:3B","","","","c1056.domain.lan","","MAC (PAP)","Rule: ""ERS PRN CANON""","ADRZ PRN CANON","192.168.150.55","192.168.150.55","0/1","","FA-VLAN-Create='1', FA-VLAN-ISID='102:102', FA-VLAN-PVID='102', FA-Client-Trust='1', Egress-VLANID='0x32000066'","172.21.0.37","Access Control Engine","","Resolving IP Address","","--","1","IFNAME=0/1 IFDESC=Extreme Networks Ethernet Routing Switch 4950GTS-PWR+ Module - Port 1","","",""
23821,"Accept","12/21/2020 03:14:14 PM","00:BB:C1:74:8A:3B","","","","c1056.domain.lan","","MAC (PAP)","Rule: ""ERS PRN CANON""","ADRZ PRN CANON","192.168.150.55","192.168.150.55","0/1","","FA-VLAN-Create='1', FA-VLAN-ISID='102:102', FA-VLAN-PVID='102', FA-Client-Trust='1', Egress-VLANID='0x32000066'","172.21.0.37","Access Control Engine","","","Authenticated MAC locally. Rule 5 [AUTH_MAC, ""*"", Any] , Auth Method: LOCAL_AUTH","--","1","IFNAME=0/1 IFDESC=Extreme Networks Ethernet Routing Switch 4950GTS-PWR+ Module - Port 1","","",""
can't add a file so is the csv file in text.
regards Mark
12-21-2020 03:55 PM
Stephan,
after connection is lost there is no mac in the eap table and no mac in the mac-addres-table of the switch. also the vlan removed from the port by the switch.
regards Mark
12-21-2020 02:45 PM
Ok, check if there is a mac on the port in case you see the connection loss.
You will see the mac in the mac address table on the switch