19.07.2013 Views

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CCNP</strong>v6 <strong>TSHOOT</strong><br />

Dec 6 17:10:16.580: RADIUS(00000010): Config NAS IP: 0.0.0.0<br />

Dec 6 17:10:16.580: RADIUS/ENCODE(00000010): acct_session_id: 16<br />

Dec 6 17:10:16.580: RADIUS(00000010): se<br />

DLS1(config)#nding<br />

Dec 6 17:10:16.580: RADIUS/ENCODE: Best Local IP-Address 10.1.50.252 for Radius<br />

-Server 10.1.50.1<br />

Dec 6 17:10:16.580: RADIUS(00000010): Send Access-Request to 10.1.50.1:1812 id<br />

1645/13, len 82<br />

Dec 6 17:10:16.580: RADIUS: authenticator 17 3A 1D 34 81 4C F1 6F - 89 62 05 1<br />

3 14 8F 33 4B<br />

Dec 6 17:10:16.580: RADIUS: User-Name [1] 9 "baduser"<br />

Dec 6 17:10:16.580: RADIUS: User-Password [2] 18 *<br />

Dec 6 17:10:16.580: RADIUS: NAS-Port [5] 6 1<br />

Dec 6 17:10:16.580: RADIUS: NAS-Port-Id [87] 6 "tty1"<br />

Dec 6 17:10:16.580: RADIUS: NAS-Port-Type [61] 6 Virtual<br />

[5]<br />

Dec 6 17:10:16.580: RADIUS: Calling-Station-Id [31] 11 "10.1.10.1"<br />

Dec 6 17:10:16.580: RADIUS: NAS-IP-Address [4] 6 10.1.50.252<br />

Dec 6 17:10:16.588: RADIUS: Received from id 1645/13 10.1.50.1:1812, Access-Rej<br />

ect, len 20<br />

Dec 6 17:10:16.588: RADIUS: authenticator 81 34 66 76 58 03 AF 9B - CF D5 93 F<br />

2 C6 13 6<br />

DLS1(config)#7 7D<br />

Dec 6 17:10:16.588: RADIUS(00000010): Received from id 1645/13<br />

Dec 6 17:10:18.593: RADIUS/ENCODE(00000010): ask "Username: "<br />

The above example shows the exchange between the RADIUS client and server when the client is using the<br />

same port numbers as the server and a bad login is attempted (nonexistent username and bad password). Note<br />

the Access-Reject message. Switch DLS1 then prompts immediately to allow entry of a correct username and<br />

password combination.<br />

AAA-related Commands<br />

Incorrect RADIUS port numbers:<br />

DLS1#show aaa servers<br />

RADIUS: id 2, priority 1, host 10.1.50.1, auth-port 1645, acct-port 1646<br />

State: current UP, duration 13752s, previous duration 0s<br />

Dead: total time 0s, count 0<br />

Quarantined: No<br />

Authen: request 8, timeouts 8<br />

Response: unexpected 0, server error 0, incorrect 0, time 0ms<br />

Transaction: success 0, failure 2<br />

<br />

The above example shows that the AAA server is RADIUS and lists the IP address and ports defined on the<br />

client. Note the eight requests and eight timeouts, resulting in two failed authentication attempts.<br />

Correct RADIUS port numbers:<br />

R3#show aaa servers<br />

RADIUS: id 1, priority 1, host 10.1.50.1, auth-port 1812, acct-port 1813<br />

State: current UP, duration 23188s, previous duration 0s<br />

All contents are Copyright © 1992–2010 <strong>Cisco</strong> Systems, Inc. All rights reserved. This document is <strong>Cisco</strong> Public Information. Page 14 of 22

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!