cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

Integrating rujie with extreme control

Integrating rujie with extreme control

Ahmed_101
New Contributor III

Hi all, 
I have an issue where i have a rujie switches and cisco switches for a customer.
So i configured mac authentication in cisco switches and it works fine but when i configured it on rujie switches i encountered issue where the rujie switch is sending radius packets to extreme control engine but the engine doesnt seems to send any response back. 
Here is some information from the rujie switch. 

Server Index..................................... 1
Server Address................................... x.x.x.x
Server Port...................................... 1812
Msg Round Trip Time.............................. 0 (msec)
First Requests................................... 40
Retry Requests................................... 21
Accept Responses................................. 0
Reject Responses................................. 0
Challenge Responses.............................. 0
Malformed Msgs................................... 0
Bad Authenticator Msgs........................... 0
Pending Requests................................. 40
Timeout Requests................................. 21
Unknowntype Msgs................................. 0
Other Drops...................................... 0

rujie(config)#show dot1x sum

ID Username MAC IP Interface VLAN Auth-State Backend-state Port-Status User-Type Time
--------- ------------------------------ -------------- --------------- --------- ---- --------------- ------------- ----------- --------- -----------------
69 805e0c63e434 805e.0c63.e434 0.0.0.0 Gi0/5 58 Authenticating Response Un-authed static User is offline

Any help will be appreciated. 

2 REPLIES 2

OscarK
Extreme Employee

Check the message authenticator attribute on the switch settings in Control. By default this is set to required and if the switch does not include it, the request will be silently dropped.

The Message-Authenticator is now required by RADIUS clients due to last year's BlastRADIUS vulnerability. See https://extreme-networks.my.site.com/ExtrArticleDetail?an=000121853 for some additional detail.

GTM-P2G8KFN