Strage problem

Dajka Tamás tdajka at geomant.com
Thu Jan 15 11:44:52 CET 2009


Hi all,

I'm facing a really strange problem. The setup:

 IAS+RRAS on Windows 2k3 server - FW with proxy - FREERADIUS on linux

There are to clients for the freeradius:
 - Linksys WRT300N ( 802.1x + WPA2 on wifi )
 - Cisco 3750G ( 802.1x on wired port )

The freeradius is configured as a proxy for IAS, and with the Wrt300N and the wifi it's working fine!
But with the Cisco I'm getting this:

Thu Jan 15 11:19:36 2009 : Error: WARNING: Malformed RADIUS packet from host [fwproxy_IP]: received 1500 octets, packet length says 1581
Thu Jan 15 11:19:41 2009 : Error: WARNING: Malformed RADIUS packet from host [fwproxy_IP]: received 1500 octets, packet length says 1581
Thu Jan 15 11:19:47 2009 : Error: WARNING: Malformed RADIUS packet from host [fwproxy_IP]: received 1500 octets, packet length says 1581
Thu Jan 15 11:19:50 2009 : Error: Rejecting request 21 due to lack of any response from home server [fwproxy_IP] port 1812

The tcpdump on the freeradius server shows:

11:19:47.389332 IP [freerad_server_ip].1814 > [fwproxy_ip].1812: RADIUS, Access Request (1), id: 0xdd length: 225
11:19:47.392714 IP [fwproxy_ip].1812 > [freerad_server_ip].1814: RADIUS, Access Challenge (11), id: 0xdd length: 1472


Sniffing on the FW's inside leg, the IAS sends back Access-challenge for the Access-Request. What's the matter?


Cheers,

           Tamas



More information about the Freeradius-Users mailing list