FreeRadius authentication problems

Phil Mayers p.mayers at imperial.ac.uk
Tue Dec 4 10:33:33 CET 2012


On 12/04/2012 07:32 AM, Taneli Virtanen wrote:
> User[client mac address] fails authentication too many times in a row
> when joining WLAN[opetus-x/opetusx] at AP[ap1
> <https://192.168.154.12/admin/mon_ap.jsp?n=c4:01:7c:1a:50:60>].
> User[client mac address] is temporarily blocked from the system for [30
> seconds].
>
> Ok, after doing some searching I found more comprehensive logs on Ruckus
> which reveal the previous lines when trying to connect to the radius
> network.
>
> So, apparently it never actually does connect to it, but since the
> authentication happens OK on the FreeRadius side, I'm left to believe
> that it is in fact Ruckus who isn't happy with me trying to join the
> network.
>

It might be EAP-identity packets hitting timeout/retry limits, due to 
wireless-level problems (interference, poor signal). This is very 
common, and lots of people tend to "associate" (pardon the pun) the 
problem with authentication, but in truth the identity request is really 
"just prior" to auth starting. It's only once the client sends an 
identity response that EAP gets started.


More information about the Freeradius-Users mailing list