Switches, Hubs, and Modems
1753546 Members
5656 Online
108795 Solutions
New Discussion юеВ

Web Authentication and RADIUS

 
SOLVED
Go to solution
doubleH
Regular Advisor

Web Authentication and RADIUS

I am trying to get my 5406 web authentication to work with RADIUS and am having no luck. I really don't know what settings I should be using in the Remote Access Policy. What type of authentication should I use?

RADIUS Server
Windows 2003 SP1 Domain Controller
IAS

Switch Config (K 12.14)
aaa authentication web login radius local
aaa authentication web enable radius local
radius-server host 192.168.77.249
radius-server key hp

Thanks
4 REPLIES 4
doubleH
Regular Advisor

Re: Web Authentication and RADIUS

i should mention that when i hit the web interface it prompts me for a user name and password. if i put in my domain username and password it won't work. if i put in the password for manager i can logon to the web interface.
doubleH
Regular Advisor

Re: Web Authentication and RADIUS

here is the error log from the IAS server...

Event Type: Warning
Event Source: IAS
Event Category: None
Event ID: 2
Date: 7/24/2007
Time: 1:41:14 PM
User: N/A
Computer: LYRA
Description:
User JOE was denied access.
Fully-Qualified-User-Name = domain.com/OU/JOE
NAS-IP-Address = 192.168.77.1
NAS-Identifier = CORE1
Called-Station-Identifier =
Calling-Station-Identifier =
Client-Friendly-Name = CORE1
Client-IP-Address = 192.168.73.1
NAS-Port-Type = Virtual
NAS-Port =
Proxy-Policy-Name = Use Windows authentication for all users
Authentication-Provider = Windows
Authentication-Server =
Policy-Name = Web Access to CORE1
Authentication-Type = PAP
EAP-Type =
Reason-Code = 66
Reason = The user attempted to use an authentication method that is not enabled on the matching remote access policy.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 00 00 00 00 ....
Matt Hobbs
Honored Contributor
Solution

Re: Web Authentication and RADIUS

Under the Authentication tab of your IAS policy, I think you need to select PAP/SPAP.
doubleH
Regular Advisor

Re: Web Authentication and RADIUS

thanks matt. that did it. it's weird because after i initially establish a connection to the switch with my domain credentials I can go back and edit the IAS policy and take off PAP and just enable CHAP v2 and it still works. i confirmed this on a 3500 as well...weird.