Unsolved

This post is more than 5 years old

4 Posts

25057

August 12th, 2008 13:00

[3548] How to enable RADIUS-based authentication? (Login & 802.1x)

Good day everyone.

 

I see that PowerConnect 3548 supports RADIUS authentication for both system login and network users authentication.

 

We have MS Windows Server 2003 SP2 Enterprise with Internet Authentication Service installed and configured properly. I configured the switch as follows:

- System -> Management Security -> RADIUS: I added our RADIUS server with its configurations (IP address, authentication port, shared secret) and set its Usage type to All (which should allow both Login & 802.1x authentication as the manual suggests).

 

- Switch -> Network Security -> Port Based Authentication:

I set the following fields: 

"Port Based Authentication State" to "Enable"

"Authentication Method" to "RADIUS"

"Guest VLAN" to "Disable"

"VLAN List" to "None"

 

Then, on the same section of Port Based Authentication, I set the field "Admin Interface Control" to "Auto," which should direct authentication requests to the RADIUS server, if I got the manual right.

 

Now here is my problem with 802.1x login authentication:

1) Whenever a user whom his port-control field was set to "Auto," he will get an unauthorization response (not sure if it was from the RADIUS server or from the switch, though couldn't find any signs of a request in the RADIUS log files). Thus the port state always appears as "Unautherized," without even asking for login credentials! Also, any port whose its state was set to "Auto" will never get DHCP settings from the DHCP server which means it's being blocked from the network.

 

And here is my problem with system (switch) login authentication:

2) Whenever I try to login the switch using my Active Directory username, the switch gives me a message saying "incorrect username or passowrd." When I go to the Event Viewer on the RADIUS server, I can see that the switch made an authentication request and the user was granted access!

I forgot to mention that I changed the order of authentication on the switch to be: RADIUS then Local.

 

How do I force Ethernet users to authenticate themselves againest the RADIUS server? Also how to solve the login authentication dilemma?

 

Thanks!

4 Posts

August 13th, 2008 19:00

OK after chatting with a Dell tech support agent, I figured out what I had been missing. It was the clients that weren't configured to send 802.1x authentication requests.

 

On Windows Vista, you have to enable a service called "Wired AutoConfig" that enables the authentication option. Then you right click on the network connection that you will be using for connecting with the network and choose Properties. You'll find a new tab called "Authentication" and there you go!

 

Good luck!

No Events found!

Top