
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
UNSOLVED
3448 802.1x EAP RADIUS-based VLAN configuration not working
I have a 3448 running SW version 1.0.0.112, set up to use 802.1x with my FreeRADIUS server. My client authenticates just fine, and my RADIUS server sends back the following attributes (see 802.1x-2004 D.3.31):
But the 3448 leaves the port in the guest VLAN, and never moves it to VLAN 5 like it's supposed to. This makes 802.1x pretty much useless to me, as I can't use it to assign users to VLANs. Is this a known defect in the 3448, or is there some error in my configuration preventing this from working? My configuration is as follows:
Sending Access-Accept of id 0 to 192.168.0.3 port 49154
Tunnel-Type:0 = VLAN
Tunnel-Medium-Type:0 = IEEE-802
Tunnel-Private-Group-Id:0 = "5"
MS-MPPE-Recv-Key = 0xb4e5475313e53786f661bc6ce1fb1fca821acf7dadd893f3d64bd272e5a5f400
MS-MPPE-Send-Key = 0x79351e8dbb34c952ce0a96190f21790a7251818d545458a778e691ab2eb74c64
EAP-Message = 0x034a0004
Message-Authenticator = 0x00000000000000000000000000000000
User-Name = "CLIENT\\User"
But the 3448 leaves the port in the guest VLAN, and never moves it to VLAN 5 like it's supposed to. This makes 802.1x pretty much useless to me, as I can't use it to assign users to VLANs. Is this a known defect in the 3448, or is there some error in my configuration preventing this from working? My configuration is as follows:
vlan database
vlan 4-6,24
exit
interface range ethernet e(1,48)
switchport access vlan 4
exit
interface vlan 24
dot1x guest-vlan
exit
interface range ethernet e(11-12)
dot1x guest-vlan enable
exit
dot1x system-auth-control
interface range ethernet e(11-12)
dot1x port-control auto
exit
interface vlan 4
ip address 192.168.0.3 255.255.255.0
exit
hostname test-switch
radius-server host 192.168.0.2 auth-port 1812 key testkey usage dot1.x
aaa authentication dot1x default radius
ip ssh server
Message Edited by cmetz on 07-06-200607:48 PM
Responses (1)
Solutions (0)

DELL-Cuong N.
1017 Posts
452
0
Posted July 17th, 2006 12:00
The 34xx supports 802.1x radius authentication to validate that the user should have access to the port. It doesn't currently support the VLAN tunnel type attribute of 802.1x.
What you can do is configure the port to be a member of specific VLAN (or VLANs) when authorized and configure a guest VLAN for when the port is unauthorized. Now when the user is authorized then the port will move into the configured (on the switch) VLAN otherwise it will remain in the guest VLAN.
You should not attempt to use the VLAN tunnel type for the 34xx in this case since it will not recognize it and will consider the response from the server to be invalid and therefore not properly authorize the port for the user.
Cuong.