cancel
Showing results for 
Search instead for 
Did you mean: 

NAC 6.2.0.221 & IdentiFi 9.15.0 RADIUS config problem

NAC 6.2.0.221 & IdentiFi 9.15.0 RADIUS config problem

LeoP1
Contributor
Greeting Guys,

Sorry about the long post, but I've tried to get as many information as I could...

I'm testing in lab the latest releases of NMS & NAC and IdentiFi, but I'm getting some issues...

The NAC Manager help tells us to config manually RADIUS Accounting on IdentiFi...

Doing some tests, I found that if I set on the NAC Manager Switches tab the IdentiFi Controller to use "Radius Accounting -> Enabled" NAC enforces the config without errors, but when using "Verify RADIUS Configuration" it shows a message like "Switch does not support ETS RADIUS Accounting MIBs.".

db443afccf5f4828b47b533360f22c73_RackMultipart20150416-13242-d4bbo9-NAC_Identify-Config_inline.png



db443afccf5f4828b47b533360f22c73_RackMultipart20150416-1669-2ep08c-NAC-Verify-Radius_inline.png



Setting, on NAC Manager's Switch Config, "Radius Accounting" to "Disable" make the "Verify RADIUS Configuration" to pass without any errors.

Looking the the IdentiFi, at the Global Authentication Settings, it shows the NAC Appliance as the only RADIUS, but Accounting Priority as "-".

Opening the Server Details, the Accounting Priority is set to "0" (Radius Accounting is enabled on the "Advanced" button below).

db443afccf5f4828b47b533360f22c73_RackMultipart20150416-22077-15mpu8d-IdentiFi-Radius-general_inline.png



db443afccf5f4828b47b533360f22c73_RackMultipart20150416-12454-lwo7nm-IdentiFi-Radius-Detail_inline.png



db443afccf5f4828b47b533360f22c73_RackMultipart20150416-13688-1aqj9lj-Identify-radius-Advanced_inline.png



Taking a look at WLAN Service Auth & Acct, as the priority of the Accounting is set to 0 and RADIUS is set to "Strict Mode", the Acct box is unset and not editable.

db443afccf5f4828b47b533360f22c73_RackMultipart20150416-1669-kcg3k-IdentiFi-Wlan-Auth-greyed_inline.png



If I set the Accounting priority on Global Authentication tab to "1" and saving config, it works as expected (Acct checkbox on WLAN Auth&Acct is marked and everything goes ok).

Now the problem arises... After making these adjustments to the IdentiFI config, on a new Enforce from NAC Manager (with "Force Reconfiguration of All Switches" checkbox set), no error messages presented, BUT Authentication on IdentiFi stop working...

Checking the NAC Manager "Verify RADIUS Configuration" it shows the following message: 'RADIUS Authentication should be enabled. Primary RADIUS should be "10.100.0.251" insted of "" '

db443afccf5f4828b47b533360f22c73_RackMultipart20150416-22077-p13ksw-NAC-Verify-radius-postIdentificonfig_inline.png



Looking at the IdentiFi Global Auth config, now it shows the NAC as a RADIUS again, BUT with the Authentication Priority as "-". Taking a deeper look at the Server Details, now the Authentication Priority is set to "0" (and on the WLAN Auth&Acct, only the Acct checkbox is selected), looking like the Auth is Disabled.

db443afccf5f4828b47b533360f22c73_RackMultipart20150416-13242-xwavba-IdentiFi-PostConfigandEnforce-Radius-general_inline.png



db443afccf5f4828b47b533360f22c73_RackMultipart20150416-28841-v9d2eu-IdentiFi-PostConfigandEnforce-detail_inline.png



db443afccf5f4828b47b533360f22c73_RackMultipart20150416-20969-q636ei-IdentiFi-PostConfigandEnforce-WLAN-Auth_inline.png


The only way to make the Auth work again is to manually set the Authentication Priority to "1" on Global Auth Config. Now everything got back to work as expected.

After doing this, the NAC Manager "Verify RADIUS Configuration" passes without any warnings of changes on NAC Config.

But, If I run a new Enforce (with Reconfig All Switches set) on NAC Manager, the Authentication Priority comes back to "0" and everything stops authenticating on IdentiFi.

After this, going a little further, if I manually set Authentication Priority to "1" and Accounting Priority to "0" and run a new Enforce (with Reconfig All Switches) on NAC Manager, everything works fine, but RADIUS Accounting for NAC Appliance on IdentiFi is disabled. The same effect is reached when, instead of editing the Priorities values, I delete the RADIUS on IdentiFi and run a new Enforce on NAC Manager.

I have customers that have (or are planning) to deploy IdentiFi + NAC and want to use Radius Auth and Acct, but this issue could be a real problem on a live environment.

Is this a bug or I'm missing something?

Best regards,

-Leo

1 REPLY 1

Ronald_Dvorak
Honored Contributor
I've run into the same before - looks like a bug as I don't see why prio should be 0.
1 was always the first one in the list in the controller GUI.
GTM-P2G8KFN