FreeRadius PAP authentication for Non-EAPOL clients on Avaya 5500 switch.

Alan DeKok aland at deployingradius.com
Sun Mar 1 22:37:46 CET 2015


On Mar 1, 2015, at 3:53 PM, jan hugo prins <jhp at jhprins.org> wrote:
> The day after I posted this message I indeed found out that I had read
> over the MAC address a hundred times without noticing the difference.
> Only after pasting them below one another I noticed the difference, and
> then the problem was fixed very quickly.

  That’s good.

> For the option the switch offers to accommodate devices that can't do
> 802.1x themselves, you say that the solution Avaya offers is stupid.
> Could you tell me a solution that works where I can integrate devices
> that don't do 802.1x in an environment where all ports need 802.1x?

a) make the devices do 802.1X

b) make the port not do 802.1X

c) give up.

  Pick one.

> I only have one LDAP server configured for radius to look at. There are
> no other LDAP servers except this one cluster IP. Why do you think the
> requests are redirected to other LDAP servers? What part of the debug
> log makes you think this?

  Ok.. it’s not redirects, but multiple group comparisons (or something similar).  v3 should be able to be more efficient than that.

  Alan DeKok.




More information about the Freeradius-Users mailing list