06-17-2020 03:07 PM
Hello all, recent problem that has popped up after working for a while.
Aerohive using Radius proxy to a 2012 R2 server using NPS. I can watch the request pass through to the NPS server and be approved, but then the devices do not get a DHCP address. When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.
Does anyone know what I can do to fix this? Stuck at the moment
Denis
Solved! Go to Solution.
06-17-2020 04:56 PM
Hi,
When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.
That happens for me only if I select to test the “RADIUS accounting server”.
Are you sure you’ve run the test for authentication as shown below…
BTW, my test result for this test was “The RADIUS server rejected the Access Request message. Check the submitted user name and password.” because my NAC didn’t liked that the message doesn’t include a end system MAC address.
Could you connect the client again to the WLAN and run “show station” on the AP CLI and post the a screenshot of the output and please tell us the client MAC.
-Ron
06-18-2021 07:50 AM
Hello Tomasz,
We’re having exact problem like the original poster described. Authentication works fine with NPS servers but the device is not being put in the target VLAN per the attribute, and thus no IP address assigned. This is happening to some users only but not all.
DHCP server is working fine.
Been fighting this for 3-4 days now. Hope someone can point me in the right direction.
06-23-2020 11:43 AM
Hi Denis,
Just to add, between RADIUS auth and DHCP process there is also a lot of other potential points of failure.
By saying ‘no attributes’ you mean the device is not being put in it’s target VLAN and thus it cannot get an IP address?
Hope that helps,
Tomasz
06-17-2020 04:56 PM
Hi,
When running a Radius test off the hive manager, it says the radius server is reachable, but does not return any attributes.
That happens for me only if I select to test the “RADIUS accounting server”.
Are you sure you’ve run the test for authentication as shown below…
BTW, my test result for this test was “The RADIUS server rejected the Access Request message. Check the submitted user name and password.” because my NAC didn’t liked that the message doesn’t include a end system MAC address.
Could you connect the client again to the WLAN and run “show station” on the AP CLI and post the a screenshot of the output and please tell us the client MAC.
-Ron