I didn't say it wasn't working. I was simply asking why it had to be this complicated.
The switch could simply send an Access-Request to the Radius Server which would reply with a response (Access-Accept) containing all the necessary attributes and that would be it.
That's what it does anyway, but the switch only accepts the VLAN (Tunnel-Private-Group-ID) once a successful EAP dialogue inside the Radius session has taken place too. Why?
DELL-Josh Cr
Moderator
•
9.5K Posts
0
April 13th, 2017 15:00
Hi,
What firmware version are you using? Are you using Windows as your RADIUS server? http://en.community.dell.com/techcenter/networking/w/wiki/11739.dell-networking-n-series-dot1x-mac-authentication-bypass
jammac
1 Rookie
•
124 Posts
0
April 13th, 2017 15:00
It's N3000 v6.3.2.4 and Freeradius v3.
I didn't say it wasn't working. I was simply asking why it had to be this complicated.
The switch could simply send an Access-Request to the Radius Server which would reply with a response (Access-Accept) containing all the necessary attributes and that would be it.
That's what it does anyway, but the switch only accepts the VLAN (Tunnel-Private-Group-ID) once a successful EAP dialogue inside the Radius session has taken place too. Why?
DELL-Josh Cr
Moderator
•
9.5K Posts
0
April 14th, 2017 09:00
I will check with the engineering team.
DELL-Josh Cr
Moderator
•
9.5K Posts
0
April 19th, 2017 17:00
I was not able to get a reason for why it is like this.
jammac
1 Rookie
•
124 Posts
0
April 20th, 2017 01:00
Too bad no one seems to know what's going on. Probably it's that way because Broadcom sell it that way, but that still is no explanation :)
Guess I'll try Professional Support on that and see how professional they are :)
md1x0n
1 Message
0
June 22nd, 2018 10:00
Were you able to force the EAP message inside RADIUS so that the switch would accept VLAN assigment with MAB?
We've been struggling with this same problem.