深信服社区»版块 安全类 行为管理AC AC1220的Radius单点登录失败,建议改一下提高兼容性! ...

AC1220的Radius单点登录失败,建议改一下提高兼容性!

查看数: 4346 | 评论数: 6 | 收藏 0
关灯 | 提示:支持键盘翻页<-左 右->
    组图打开中,请稍候......
发布时间: 2017-7-20 21:29

正文摘要:

我们购买的AC1220,启用测试时发现Radius单点登录失败。 无线网802.1X认证方式,手机通常是先需要Radius认证通过后,才会跟内网的DHCP服务器获取到IP地址。 目前AC设备要求认证数据包里有Framed-IP-Address 才能实 ...

回复

周sir 发表于 2017-7-25 11:17
我也有相同的问题,客户有线无线做802.1X,Radius下发VLAN,实现不同账号分组与内部访问权限控制,对然后希望通过AC能够看到对应的用户,实现这个流控和外部访问权限控制。
AC产品规划经理53612 发表于 2017-7-24 14:12
您好,我们认证的最基础要求,是需要有IP信息的,没有IP信息,是没办法做认证的,因为所有逻辑都是基于IP来做的.,所以即使把Framed-IP-Address,  改为获取 Calling-Station-Id,没有IP地址获取到,也还是不行的.
这种场景的话,以前我们做过一些定制,是raduis和DHCP做联动,把MAC, IP,用户信息都做关联来实现.
stinby 发表于 2017-7-21 17:47
能改吗?
stinby 发表于 2017-7-21 16:55
RADIUS属性在报文中的支持情况
不同的RADIUS报文对于RADIUS属性的支持情况也不相同。RADIUS属性在报文中的支持情况包括:
  • RADIUS认证报文中属性的支持情况,如[url=mkMSITStore:\BaiduYunDownload\AR2220-S\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S_V200R007_%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3(chm)\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S%20V200R007%20%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3.chm::/dc/dc_fd_aaa_0011.html#dc_fd_aaa_0011_3__table-radius-3]表3[/url]所示。
  • RADIUS计费报文中属性的支持情况,如[url=mkMSITStore:\BaiduYunDownload\AR2220-S\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S_V200R007_%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3(chm)\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S%20V200R007%20%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3.chm::/dc/dc_fd_aaa_0011.html#dc_fd_aaa_0011_3__table-radius-4]表4[/url]所示。
  • RADIUS授权报文中属性的支持情况,如[url=mkMSITStore:\BaiduYunDownload\AR2220-S\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S_V200R007_%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3(chm)\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S%20V200R007%20%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3.chm::/dc/dc_fd_aaa_0011.html#dc_fd_aaa_0011_3__table-radius-5]表5[/url]所示。

[img]mkMSITStore:\BaiduYunDownload\AR2220-S\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S_V200R007_%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3(chm)\AR100-S&AR110-S&AR120-S&AR150-S&AR160-S&AR200-S&AR1200-S&AR2200-S&AR3200-S%20V200R007%20%E4%BA%A7%E5%93%81%E6%96%87%E6%A1%A3.chm::/public_sys-resources/icon-note.gif[/img] 说明:
  • 1:表示该属性在该类型报文中一定出现一次;
  • 0:表示该属性在该类型报文中一定不能出现(即使出现也不起任何作用,该属性将被丢弃);
  • 0-1:表示该属性在该类型报文中可能出现一次,也可能不出现;
  • 0+:表示零个或多个该属性可能出现在该类型报文中。

属性
Access-Request
Access-Accept
Access-Reject
Access-Challenge
表3 RADIUS认证报文中属性的支持情况
属性
Access-Request
Access-Accept
Access-Reject
Access-Challenge

User-Name(1)
1
0-1
0
0

User-Password(2)
0-1
0
0
0

Chap-Password(3)
0-1
0
0
0

NAS-IP-Address(4)
1
0
0
0

NAS-Port(5)
1
0
0
0

Service-Type(6)
1
0-1
0
0

Framed-Protocol(7)
1
0-1
0
0

Framed-IP-Address(8)
0-1
0
0
0

Framed-IP-Netmask(9)
0
0-1
0
0

Filter-Id(11)
0
0-1
0
0

Framed-MTU(12)
0-1
0
0
0

Login-IP-Host(14)
0-1
0-1
0
0

Login-Service(15)
0
0-1
0
0

Reply-Message(18)
0
0-1
0-1
0

Callback-Number(19)
0
0-1
0
0

Framed-Route(22)
0
0-1
0
0

State(24)
0-1
0-1
0
0-1

Class(25)
0
0-1
0
0

Session-Timeout(27)
0
0-1
0
0-1

Idle-Timeout(28)
0
0-1
0
0

Termination-Action(29)
0
0-1
0
0-1

Called_Station_Id(30)
0-1
0
0
0

Calling-Station-Id(31)
1
0
0
0

NAS-Identifier(32)
1
0
0
0

Acct-session-id(44)
1
0
0
0

CHAP_Challenge(60)
0-1
0
0
0

NAS-Port-Type(61)
1
0
0
0

Tunnel-Type(64)
0
0-1
0
0

Tunnel-Medium-Type(65)
0
0-1
0
0

EAP-Message(79)
0-1
0-1
0-1
0-1

Message-Authenticator(80)
0-1
0-1
0-1
0-1

Tunnel-Private-Group-ID(81)
0
0-1
0
0

Acct-Interim-Interval(85)
0
0-1
0
0

NAS-Port-Id(87)
1
0
0
0

Framed-Pool(88)
0
1
0
0

NAS-IPv6-Address(95)
0-1
0
0
0

HW-Input-Peak-Information-Rate(26-1)
0
0-1
0
0

HW-Input-Committed-Information-Rate(26-2)
0
0-1
0
0

HW-Input-Committed-Burst-Size(26-3)
0
0-1
0
0

HW-Output-Peak-Information-Rate(26-4)
0
0-1
0
0

HW-Output-Committed-Information-Rate(26-5)
0
0-1
0
0

HW-Output-Committed-Burst-Size(26-6)
0
0-1
0
0

HW-Remanent-Volume(26-15)
0
0-1
0
0

HW_ConnectID(26-26)
1
0
0
0

Ftp_directory(26-28)
0
0-1
0
0

HW-Exec-Privilege(26-29)
0
0-1
0
0

HW_Startup_Timestamp(26-59)
1
0
0
0

HW-IP-Host-Address(26-60)
1
0
0
0

HW-Up-Priority(26-61)
0
0-1
0
0

HW-Down-Priority(26-62)
0
0-1
0
0

HW-Primary-WINS(26-75)
0
0-1
0
0

HW-Second-WINS(26-76)
0
0-1
0
0

HW-Input-Peak-Burst-Size(26-77)
0
0-1
0
0

HW-Output-Peak-Burst-Size(26-78)
0
0-1
0
0

hw-Data-Filter(26-82)
0
0-1
0
0

HW-Primary-DNS(26-135)
0
1
0
0

HW-Secondary-DNS(26-136)
0
1
0
0

HW_Web_Proxy_Name(26-143)
0
0-1
0
0

HW_Port_Forward_Name(26-144)
0
0-1
0
0

HW_IP_Forwarding_Name(26-145)
0
0-1
0
0

HW-Service-Scheme(26-146)
0
0-1
0
0

HW-Access-Type(26-153)
1
0
0
0

HW-User-Addr-Network(26-241)
0
0-1
0
0

HW-DNS-Domain-Name(26-242)
0
0-1
0
0

HW-Auto-Update-URL(26-243)
0
0-1
0
0

HW-Reachable-Detect(26-244)
0-1
0
0
0

HW-Version(26-254)
1
0
0
0

HW-Product-ID(26-255)
1
0
0
0
属性
Accounting-Request (Start)
Accounting-Request (Interim-Update)
Accounting-Request (Stop)
Accounting-Response (start)
Accounting-Response(Interim-Update)
Accounting-Response (Stop)
表4 RADIUS计费报文中属性的支持情况
属性
Accounting-Request (Start)
Accounting-Request (Interim-Update)
Accounting-Request (Stop)
Accounting-Response (start)
Accounting-Response(Interim-Update)
Accounting-Response (Stop)

User-Name(1)
1
1
1
0
0
0

NAS-IP-Address(4)
1
1
1
0
0
0

NAS-Port(5)
1
1
1
0
0
0

Service-Type(6)
1
1
1
0
0
0

Framed-Protocol(7)
1
1
1
0
0
0

Framed-IP-Address(8)
1
1
1
0
0
0

Class(25)
0-1
0-1
0-1
0
0
0

Session-Timeout(27)
0
0
0
0-1
0-1
0

Called-Station-Id(30)
1
1
1
0
0
0

Calling-Station-Id(31)
1
1
1
0
0
0

NAS-Identifier(32)
1
1
1
0
0
0

Acct-Status-Type(40)
1
1
1
0
0
0

Acct-Delay-Time(41)
0
1
1
0
0
0

Acct-Session-Id(44)
1
1
1
0
0
0

Acct-Authentic(45)
1
1
1
0
0
0

Acct-Session-Time(46)
0
1
1
0
0
0

Acct-Terminate-Cause(49)
0
0
1
0
0
0

Event-Timestamp(55)
1
1
1
0
0
0

NAS-Port-Type(61)
1
1
1
0
0
0

NAS-Port-Id(87)
1
1
1
0
0
0

NAS-IPv6-Address(95)
0-1
0-1
0-1
0
0
0

HW_ConnectID(26-26)
1
1
1
0
0
0

HW-IP-Host-Address(26-60)
1
1
1
0
0
0

HW-Access-Type(26-153)
1
1
1
0
0
0

HW-Reachable-Detect(26-244)
0-1
0-1
0-1
0
0
0

HW-Tariff-Input-Octets(26-247)
0
0-1
0-1
0
0
0

HW-Tariff-Output-Octets(26-248)
0
0-1
0-1
0
0
0

HW-Tariff-Input-Gigawords(26-249)
0
0-1
0-1
0
0
0

HW-Tariff-Output-Gigawords(26-250)
0
0-1
0-1
0
0
0
属性号
COA REQUEST
COA ACK
COA NAK
DM REQUEST
DM ACK
DM NAK
表5 RADIUS动态授权报文(COA/DM)中属性的支持情况
属性号
COA REQUEST
COA ACK
COA NAK
DM REQUEST
DM ACK
DM NAK

User-Name(1)
0-1
0-1
0-1
0-1
0-1
0-1

NAS-IP-Address(4)
0-1
0-1
0-1
0-1
0-1
0-1

NAS-Port(5)
0-1
0
0
0-1
0
0

Framed-IP-Address(8)
0-1
0-1
0-1
0-1
0-1
0-1

Filter-Id(11)
0-1
0
0
0
0
0

Session-Timeout(27)
0-1
0
0
0
0
0

Calling-Station-Id(31)
0-1
0-1
0-1
0-1
0-1
0-1

NAS-Identifier(32)
0-1
0-1
0-1
0-1
0-1
0-1

Acct-Session-Id(44)
1
1
1
1
1
1

HW-Input-Peak-Information-Rate(26-1)
0-1
0
0
0
0
0

HW-Input-Committed-Information-Rate(26-2)
0-1
0
0
0
0
0

HW-Output-Peak-Information-Rate(26-4)
0-1
0
0
0
0
0

HW-Output-Committed-Information-Rate(26-5)
0-1
0
0
0
0
0

HW-Up-Priority(26-61)
0-1
0
0
0
0
0

HW-Down-Priority(26-62)
0-1
0
0
0
0
0

HW-Data-Filter(26-82)
0-1
0
0
0
0
0

HW-Service-Scheme(26–146)
0-1
0
0
0
0
0
stinby 发表于 2017-7-21 10:05
@AC产品规划经理53612   不知道能说明清楚了吗???   或者改成Calling-Station-Id可选 也行。
stinby 发表于 2017-7-20 21:31
简单的说,就是把原来获取Framed-IP-Address,  改为获取 Calling-Station-Id