Start a Conversation

Unsolved

L

32 Posts

615

August 15th, 2022 03:00

Dell N3024P doesn't send Radius Attribute Service-Type 10

Hi all,

 

I'm facing an issue where my switch / the endpoint is not sending the correct 'Service-Type' Radius attribute to my radius server. When the endpoint is authenticating, it only sends 'Service-Type' 1 (Login-User) and not 10 (Call-Check).

I've globally enabled sending the service-type in the Access-Request message using command: 'radius-server attribute 6 on-for-login-auth' like described on https://dl.dell.com/manuals/all-products/esuprt_ser_stor_net/esuprt_networking/esuprt_net_fxd_prt_swtchs/networking-n3000-series_administrator-guide12_en-us.pdf (P. 938). 

 

Port configuration:

description "NAC ENABLED"
spanning-tree portfast
switchport mode general
dot1x port-control mac-based
dot1x reauthentication
dot1x timeout quiet-period 1
dot1x timeout tx-period 1
dot1x timeout guest-vlan-period 10
dot1x max-req 3
dot1x mac-auth-bypass
authentication order dot1x mab
authentication priority dot1x mab










 

The authentication-history log proofs that MAB is working:

SWITCH(config-if-Gi1/0/1)#show authentication authentication-history gigabitethernet 1/0/1

Timestamp Interface MAC Address Auth Status Method
--------------------- --------- -------------- ------------ --------------
Aug 15 2022 11:10:02 Gi1/0/1 4448.C1CF.E52E Unauthorized MAB

Aug 15 2022 11:09:40 Gi1/0/1 4448.C1CF.E52E Unauthorized MAB

Aug 15 2022 11:09:17 Gi1/0/1 4448.C1CF.E52E Unauthorized MAB

 

Screenshot of Service-Type that is received on radius server (ClearPass):

lk2819_0-1660559804755.png

 

Model: Dell N3024P 

Firmware: 6.3.2.3. 

 

I want to use the different service types (1 or 10) to differentiate the use of 802.1x or MAB on the radius server.  Why is the access-request not sending 'Service-Type' 10? 

 

 

 

Moderator

 • 

3.7K Posts

August 15th, 2022 08:00

Hello lk2819,

 

I think this may help you.

Page: 243 - Supported RADIUS Attributes

Dell Networking N-Series N1500, N2000, N3000, and N4000 Switches User’s Configuration Guide Version 6.3.0.0 and Later

https://dell.to/3A1wjG1

 

32 Posts

August 16th, 2022 00:00

Hi Charles,

Thank you for your answer, I see that Service-Type (10) is not supported on the N3024P. 

However, I have a few Dell N3048's and N2048's that do successfully send Service-Type 10 included in the RADIUS Access-Request. Any idea on why this does work on these models? 

Working Model: Dell EMC Networking Switch N3048

Firmware version: 6.5.4.17

 

Moderator

 • 

3.4K Posts

August 16th, 2022 02:00

Hello @lk2819,

 

We do not have any idea as it is not provided any information in the guide. Probably if you need further details why it was not supported, I suggest to log a support call ticket to check with engineering. 

 

No Events found!

Top