802.1x / Radius: Can't reject a user!

Good afternoon,
I have been struggling on this problem for a while. Basically my Radius server (Linux based Freeradius, not Cisco ACS) send a Reject packet but the switch (WS-3750-24PS) somehow OVERWRITE the result and authorized the port!! The following is the debug on the switch:
*Mar  1 00:02:49.877: %LINK-3-UPDOWN: Interface FastEthernet1/0/5, changed state to up
*Mar  1 00:02:50.884: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet1/0/5, changed state to up
IDF.100#
*Mar  1 00:02:54.063: %DOT1X-5-FAIL: Authentication failed for client (0014.22fd.dd98) on Interface Fa1/0/5 AuditSessionID AC11FE640000000400028FD9
IDF.100#
*Mar  1 00:02:54.063: %AUTHMGR-7-RESULT: Authentication result 'fail' from 'dot1x' for client (0014.22fd.dd98) on Interface Fa1/0/5 AuditSessionID AC11FE640000000400028FD9
... (Repeated for another 2 times)
*Mar  1 00:02:57.117: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0014.22fd.dd98) on Interface Fa1/0/5 AuditSessionID AC11FE640000000400028FD9
*Mar  1 00:02:57.117: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (0014.22fd.dd98) on Interface Fa1/0/5 AuditSessionID AC11FE640000000400028FD9
I also captured the packets and I will attach it here as well.
I do know that it hasn't finished a full EAP (I am using PEAP for Win XP clients) cycle and rejected it a little bit earlier. However based on the RFC 3579 the switch should reject the request upon receiving a Reject:
"Reception of a RADIUS Access-Reject packet MUST result in the NAS denying access to the authenticating peer" (Section 2.1 on page 5)
I have also tried firmware 12.2(50) and 12.2(52) and I am currently running the newest 12.2(53) but they behave the same...
Any ideas why it would do that and will there be a fix?
Thank you!
Difan

Hi zhaodifan, Cisco Guys,
I can confirm the bug, we have following switch and portconfig:
Switch Ports Model              SW Version            SW Image                
*    1 52    WS-C3560G-48PS     12.2(53)SE2           C3560-IPSERVICESK9-M
interface GigabitEthernet0/39
switchport mode access
authentication event server dead action authorize vlan 9
authentication event no-response action authorize vlan 9
authentication event server alive action reinitialize
authentication port-control auto
authentication periodic
authentication timer reauthenticate 10
dot1x pae authenticator
dot1x timeout tx-period 5
no cdp enable
spanning-tree portfast
spanning-tree bpduguard enable
end
So, if dot1x is not supported by the client, or the radius server is down the client sould be put in vlan 9!
But sometimes this happens:
Aug 31 12:23:20 172.16.0.24 183428: Aug 31 10:23:20.472: %DOT1X-5-SUCCESS: Authentication successful for client (0016.cbaa.0fcb) on Interface Gi0/39 AuditSessionID AC1000180000276A14BBFD2E
Aug 31 12:23:22 172.16.0.24 183430: Aug 31 10:23:21.496: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0016.cbaa.0fcb) on Interface Gi0/39 AuditSessionID AC1000180000276A14BBFD2E
Aug 31 12:23:51 172.16.0.24 183431: Aug 31 10:23:51.133: %DOT1X-5-FAIL: Authentication failed for client (0016.cbaa.0fcb) on Interface Gi0/39 AuditSessionID AC1000180000276A14BBFD2E
Aug 31 12:23:53 172.16.0.24 183433: Aug 31 10:23:52.164: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0016.cbaa.0fcb) on Interface Gi0/39 AuditSessionID AC1000180000276A14BBFD2E
Aug 31 12:23:53 172.16.0.24 183434: Aug 31 10:23:52.164: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (0016.cbaa.0fcb) on Interface Gi0/39 AuditSessionID AC1000180000276A14BBFD2E
This "Override" results in the client to be put in the vlan it was before the "Authentication failed" and even worse:
It stays there forever! No reauthentificate takes place after the "Override" whatsoever.
What does %DOT1X-5-RESULT_OVERRIDE mean? How and why is it triggered?!
Cisco, take this serious!

Similar Messages

  • I can't get my me mail to work on iCloud keeps rejecting my user id nothing works on the pad or pod either to do with mobile me aaaaaaaaaaaargh

    I can't get my me mail to work on iCloud keeps rejecting my user id nothing works on the pad or pod either to do with mobile me aaaaaaaaaaaargh
    Apple - please please let us know what is going on

    ewaller wrote:
    fazio96,
    Could I prevail upon you to come up with a better thread title?  I resisted my first inclination to move the thread to "Dustbin"; but I will say the title does little to inspire us to help.   You may wan to read the article linked in my signature.
    Thanks.
    I'll change it now. I just realized it sounds rough, but I was mad because I couldn't get it work, it isn't anyone's fault, sorry
    EDIT: I got it to work at an usable state! By using the 8192cu driver on the AUR and the suggestions in the comments about disabling power-save, I got it to be usable. It now has up to 8% packet loss, not 30-40% like before, and the ping spikes are now 300-400 ms and less frequent, not 1000-1200ms. It's not working really well but now I can at least surf the web. Thank you all for the patience.
    EDIT 2: after testing more I realized it still disconnects every few seconds when I'm far from the AP. However, when connected, I still have very strong signal. If I use it on windows or another distro it doesn't disconnect. I tried compiling the driver from realtek by myself using the istructions in the second post but I don't know how to fix some compile errors, so I decided I'll stick with my usb dongle. Maybe someone will find a better solution.
    Last edited by fazo96 (2013-09-30 16:08:10)

  • 802.1x Radius, how to return allowed ssid(s)

    How does one setup the Radius server to return the allowed SSID for that user.
    In this case FreeRadius will be used.
    Cisco suggested that to avoid VLAN hopping, one should have the 802.1X RADIUS server return a list of permissible SSIDs for each authenticated user.
    I have read documention for how to setup the RADIUS user attributes for VLAN ID assignment but have not found any docs for the Radius SSID assignments.
    Suggestions are welcome,
    Rene

    To prevent client devices from associating to the access point using an unauthorized SSID, create a list of authorized SSIDs that clients must use on your RADIUS server.For more refer the following URL
    http://www.cisco.com/en/US/products/ps5853/products_configuration_guide_chapter09186a008043ac56.html#wp1054061

  • How to reject the user logon in ECC600 system?

    Hi all,
    I want to do a maintenance on my ECC600 system. So I would like to reject the user logon except admin during the maintenance. How can I do this. Whether has the setting can be implementted in system? Thanks in advance!
    Best Regards,
    Simon Shen

    hi,
    I got this error message, when I run the TP command,
    tp returncode summary:
    TOOLS: Highest return code of single steps was: 0
    ERRORS: Highest tp internal error was: 0232
    tp finished with return code: 232
    meaning:  connect failed
    The contents of My Transport Profile as below, is it correct or have to add some entries.
    TRANSDIR            = E:\usr\sap\trans
    DUM/CTC             = 0
    DUM/DUMMY           = 1
    DUM/NBUFFORM        = 1
    DUM/TP_VERSION      = 266
    TR1/CTC             = 0
    TR1/DBHOST          = cneusr01
    TR1/DBNAME          = TR1
    TR1/DBTYPE          = mss
    TR1/NBUFFORM        = 1
    TR1/TP_VERSION      = 266
    Best Regards,
    Simon Shen

  • Radius connection being rejected by server

    From my Cisco 881 k9 router I run test aaa group radius server 10.20.1.10 username password legacy - -and I get user authentication request was rejected by server -- 
    using windows 2008 as Radius server -- the IP address of Cisco Router is configured as client on server end -- Are the AAA parameters supposed to be set a certain way for access to an external Radius server for authentication?

    Mar  5 09:41:05.184: RADIUS: Pick NAS IP for u=0x8524DF98 tableid=0 cfg_addr=10.20.1.250
    Mar  5 09:41:05.184: RADIUS(00000000): Config NAS IPv6: ::
    Mar  5 09:41:05.184: RADIUS: ustruct sharecount=1
    Mar  5 09:41:05.184: Radius: radius_port_info() success=0 radius_nas_port=1
    Mar  5 09:41:05.184: RADIUS(00000000): Send Access-Request to 10.20.1.10:1645 id 1645/25, len 58
    Mar  5 09:41:05.184: RADIUS(00000000): Sending a IPv4 Radius Packet
    Mar  5 09:41:05.184: RADIUS(00000000): Started 5 sec timeout
    Mar  5 09:41:05.188: RADIUS: Received from id 1645/25 10.20.1.10:1645, Access-Reject, len 20
    Mar  5 09:41:05.188: RADIUS: saved authorization data for user 8524DF98 at 0

  • I updated to Lion, and all of my events show up, but I cannot "add invitees" to any event. I can accept/reject invites, but cannot create them myself.

    Help!  updated to Lion, and all of my events show up, but I cannot "add invitees" to any event. I can accept/reject invites, but cannot create them myself.

    Purplehiddledog wrote:
    I do backup with iCloud.  I can't wait until the new iMac is available so that I can once again have my files in more than 1 location without needing to rely solely on the cloud. 
    I also rely on iTunes and my MacBook and Time Machine as well as backing up to iCloud. I know many users know have gone totally PC free, but I chose to use iCloud merely as my third backup.
    I assume that the restore would result in my ability to open Pages and Numbers and fix the problem with deleting apps, but this would also mean that if my Numbers documents still exist solely within the app and are just not on iCloud for some reason that they would be gone forever.  Is that right?
    In a word, yes. In a little more detail.... When you restore from an iCloud backup, you must erase the device and start all over again. There is no other way to access the backup in iCloud without erasing the device. Consequently, you are starting all over again. Therefore, it would also be my assumption that Pages and Numbers will work again and that the deleting apps issues would be fixed as well.
    If the documents are not in the backup, and you do not have a backup elsewhere, the documents could be gone forever.

  • How can I have multiple users on iTunes (in order to connect to a shared office iPad)?

    How can I have multiple users on iTunes (in order to connect to a shared office iPad)? Currently each of us has our own iTunes account, so I've made an "all office" Apple ID. However, I can't seem to get two different accounts (my personal and the office) to work on my machine. Even when I login as "the office", my personal library is still showing. Additionally, when I try to setup with a first-time use in iTunes, I get an error that I don't meet the minimum age requirement - no matter what birthdate I enter!

    The library exists regardless of which user is logged in.
    The only way around that is to create different user accounts on the computer.
    There is no way to have 20 unique iTunes users access a shared iTunes under a single login on the computer.

  • How do you use Time Machine to restore a specific users account?  I can't do it from the user screen because I am not allowed.  I can't do it from the admin because I can't see other users in Time machine.

    I can't restore my user account from the users screen because I get an alert that Mac OS needs something.  I can't restore in TimaeMachine from the Admin screen because I can't see other users home folders.  What can I do?

    See Pondini's TM FAQs for starters.

  • Can not list all user in Sun Iplant Directory Server5.0

    wls61sp1 sun directory server5.0
    when I config the LDAP v1 Realm,
    can only get the users from one user dn
    such as "o=NetscapeRoot,ou=beagz,cn=group1"
    but if group1 include another group group1-1,
    and a user include in group1-1,such user can not
    be see in the wls admin console.
    how can I see all users or all groups in the
    user dn?

    Hi, Eric:
    What are your LDAP configuration settings? Is the "Group Is Context"
    flag set to false?
    - Jim
    Jim Brown
    Developer Relations Engineer
    BEA Support
    "Eric.Nie" wrote:
    >
    wls61sp1 sun directory server5.0
    when I config the LDAP v1 Realm,
    can only get the users from one user dn
    such as "o=NetscapeRoot,ou=beagz,cn=group1"
    but if group1 include another group group1-1,
    and a user include in group1-1,such user can not
    be see in the wls admin console.
    how can I see all users or all groups in the
    user dn?

  • How can I get all users associated with my VSO

    I see here: https://www.visualstudio.com/en-us/integrate/api/shared/profiles that I can get my profile info from the API, but can I get all users associated with an account?

    Hello!
    If you want to see all of that in a single mailbox, you can create a Smart Mailbox from the "file" menu in the top left corner of your screen. It's a bit of trial and error before you get the rules correct, perhaps, but that will work.

  • I have multiple devices (imacs, lap tops and ipads) all connected to a NAS server.  Can I create a user for myself and one for my wife, and each have our own apple ID, and Itunes accounts, but all share the same media on NAS drives?

    I have multiple devices (iMacs, Lap tops, Ipads) all connected to a Nas Drive.  Can I create a user for myself and one for my wife and we each have our own apple ID's, Itunes etc, but share the same data on the hard drives?  So when she logs in, and sync's her ipads, they will sync with her stuff and when I do the same under my user account, on the same device, my ipads will sync with my stuff?

    You can share the same Apple ID for purchasng form the iTunes and app stores without any problems, but you should all used separate iCloud accounts with separate Apple IDs.  (You are not required to use the same ID for iCloud and other services as you do for the iTunes store.)  This will prevent you from ending up with merged data.  You should also use separate Apple IDs for iMessage and FaceTime or you will end up getting each other's text messages and FaceTime calls.
    This article may be of interest: http://www.macstories.net/stories/ios-5-icloud-tips-sharing-an-apple-id-with-you r-family/, as well as this video: http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l.

  • How can I have multiple users on one apple id?

    How can I have multiple users on one apple ID?
    ie: I have my apple ID with my own credit, how can I set up credit for my son under the same apple ID, so that he can still access the same apps I've already downloaded and paid for?

    I've been trying to figure out a clean way to do this too. I think you may need more than one Apple ID – one that is shared and used to purchase "sharable" items and then "individual" Apple IDs for you and your son. That's the idea that I'm pursuing for the moment.
    It seems that there must be a way to do this, App Store purchases for the Mac are licensed across multiple machines. iPhone app purchases have "all your devices" licensing. Makes me think that Apple has a process in mind for sharing an account (or associating a device with multiple accounts).
    Other things I've learned:
    - Apparently you can't merge Apple ID accounts. I asked about this once at an Apple Store and was told that there was no way to do it.
    - If you share an Apple ID the Messages app behaves in a somewhat surprising manner. It must use your Apple ID to decide where messages should be sent because all users get all messages. This can make it very hard to organize a surprise party :-)

  • TS5223 can I have multiple users use one apple account?

    can I have multiple users use one apple account?

    I interpreted his post to mean that he meant multiple human users, not multiple devices.  Hopefully, he'll clarify.

  • How can I allow other users on my macbook to view my iphoto library when th

    How can I allow other users on my macbook to view my iphoto library when they are logged in. I do not have a network, and the users (my family) all log in seperately when they use the computer. Does anyone know? Thank you.

    rdoss
    Welcome to the Apple Discussions.
    If you want others to be able to see the pics, but not add to, change or alter your library, then enable Sharing in your iPhoto (Preferences -> Sharing), leave iPhoto running and use Fast User Switching to open the other account(s). In the other account(s), enable 'Look For Shared Libraries'. Your Library will appear in their source pane.
    Remember iPhoto must be running in both accounts for this to work.
    Regards
    TD

  • Can I allow multiple users on a blog?

    I would like to have remote users who can update and add pages to a blog in iweb.  Is this possible?

    You can't have multiple users manage an iWeb blog.  That's because you need the domain file that's in your Users/Home/Library/Application Support/iWeb folder to be able to do that.  That would mean all of them would have to have access to the same file and all be running on Macs with the same version of iWeb.
    I suggest you create your blog on one of the online blogging sites, embed it into your iWeb page like in this demo page, Embed a Site Within an iWeb Page, and then give those you want to have access the username and password for managing the blog.  This way you can update the blog from any computer anywhere and from many mobile devices.
    OT

Maybe you are looking for

  • O2C PIP with Microsoft SQL Server Based Siebel server

    Hi, We are trying to install AIA 2.2 with PIP for Order to Cash cycle. This integrates Siebel with Oracle for O2C cycle. We have done installation till AIA foundation pack successfully. Now when I looked at PIP installation guide it asks for Siebel d

  • How do I create a line chart direct from xml or convert xml to ArrayCollection

    The xml is simple: <data> <row name="Q1"> <expenses>64</expenses> <revenue>98</revenue> <profit>34</profit> </row> <row name="Q2"> <expenses>44</expenses> <revenue>28</revenue> <profit>64</profit> </row> <row name="Q3"> <expenses>14</expenses> <reven

  • Cant copy and paste text or move by paragraph in email compose window

    Hi, win8, heaps of memory, TB 24.6.0, various add-ons The copy and paste just stops functioning sometime - when I select ctrl+c then ctrl+v nothing happens. Also, ctrl+ left /right arrows will move by word, but up/down arrows do nothing. Both the cop

  • Aperture 3 and Artifacting

    I currently use Aperture 3 Version 3.1.2.  I use a Canon EOS 5D Mark 2 and only shoot in RAW. I find that if I for any reason use 'Presets' in Adjustments, Aperture introduces artifacting into my photographs.  Retouch Brushes also seem to do the same

  • Account assignment objects are incorrect. No substitution is possible

    Account assignment objects are incorrect. No substitution is possible. Message no. 3G209 Diagnosis The account assignment object check showed that, from the point of view of CO, the specified account assignment is not valid, and cannot be replaced by