FreeRADIUS not sending "Access-Accept" for Cisco Phone

Alan DeKok aland at deployingradius.com
Thu May 26 15:48:57 CEST 2016


On May 26, 2016, at 3:44 AM, craig at mypenguin.net.au wrote:
> 802.1x Authentication with EAP-TLS, works perfectly with a Centos
> client, however not from a Cisco IP Phone.
> 
> Basic Specs For Server;
> * Centos 7.2 x64
> * freeradius-3.0.4-6.el7.x86_64

  3.0.11 would be better... but OK

> * Communicating through a Dell N3000 switch.
> * Cisco 7841 IP Phone
> 
> I've been studying the debug logs as best I can, the working log clearly
> shows "Sending Access Accept Packet" (output below).

  Which tells you it works.  i.e. there's no new information in the log.

> However when I read the debug for the Cisco phone connection, we see
> hundreds (would eventually be thousands) of attempts without ever seeing the below successful packet
> sent back. 

  So... what is the debug output when it goes wrong?

> I'm just after any suggestions on how to better debug the connection from the Cisco
> phone?

  Read the debug output when the Cisco phone connects?

  Alan DeKok.




More information about the Freeradius-Users mailing list