cancel
Showing results for 
Search instead for 
Did you mean: 

Aerohive Radius not passing DHCP after success

Aerohive Radius not passing DHCP after success

Drecchia
New Contributor

Hello all, recent problem that has popped up after working for a while.

 

Aerohive using Radius proxy to a 2012 R2 server using NPS.  I can watch the request pass through to the NPS server and be approved, but then the devices do not get a DHCP address.  When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.

 

Does anyone know what I can do to fix this?  Stuck at the moment

 

Denis 

1 ACCEPTED SOLUTION

Ronald_Dvorak
Honored Contributor

Hi,

When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.

 

That happens for me only if I select to test the “RADIUS accounting server”.

Are you sure you’ve run the test for authentication as shown below…

3c033ae8925b4ad6a5fa7cbad5df8a7f_e3260659-b595-488a-baa4-329c157275ea.png

 

BTW, my test result for this test was “The RADIUS server rejected the Access Request message. Check the submitted user name and password.” because my NAC didn’t liked that the message doesn’t include a end system MAC address.

 

Could you connect the client again to the WLAN and run “show station” on the AP CLI and post the a screenshot of the output and please tell us the client MAC.

 

-Ron

View solution in original post

3 REPLIES 3

Adao12
New Contributor

Hello Tomasz,

 

We’re having exact problem like the original poster described. Authentication works fine with NPS servers but the device is not being put in the target VLAN per the attribute, and thus no IP address assigned. This is happening to some users only but not all.

DHCP server is working fine.

 

Been fighting this for 3-4 days now. Hope someone can point me in the right direction.

Tomasz
Valued Contributor II

Hi Denis,

 

Just to add, between RADIUS auth and DHCP process there is also a lot of other potential points of failure.

By saying ‘no attributes’ you mean the device is not being put in it’s target VLAN and thus it cannot get an IP address?

 

 

Hope that helps,

Tomasz

 

Ronald_Dvorak
Honored Contributor

Hi,

When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.

 

That happens for me only if I select to test the “RADIUS accounting server”.

Are you sure you’ve run the test for authentication as shown below…

3c033ae8925b4ad6a5fa7cbad5df8a7f_e3260659-b595-488a-baa4-329c157275ea.png

 

BTW, my test result for this test was “The RADIUS server rejected the Access Request message. Check the submitted user name and password.” because my NAC didn’t liked that the message doesn’t include a end system MAC address.

 

Could you connect the client again to the WLAN and run “show station” on the AP CLI and post the a screenshot of the output and please tell us the client MAC.

 

-Ron

GTM-P2G8KFN