GS2210-48p randomly stops sending Radius requests
So I've noticed this a few times now. Randomly on some of the 60+ switches I have had them become inaccessible from login (both webpage and SSH). I can usually go into radius and disable the client then proceed to SSH into switch with the local creds. But the only way to get the switch back to talking through Radius is to reboot the entire switch itself.
Logs on switch itself state that it does flip between the 2 radius servers I have configured then a no authentication message.
Logs on switch itself state that it does flip between the 2 radius servers I have configured then a no authentication message.
1 May 20 12:11:31 WA authentication: RADIUS Authentication - change RADIUS server from 1 to 2
2 May 20 12:10:04 NO authentication: SSH authentication failure [username: Name, IP address = 172.xxx.xxx.xxx]
Firmware Version - V4.50(AAHV.2) | 02/27/2018
I haven't tried the latest firmware yet, This switch has also been up for 357 days, but this shouldn't stop the radius server.
Anyone else having experience this issue? Is there a way to just restart the radius service without disrupting the site connected to this switch? The external logging server never actually shows a radius request leaving the switch until after the restart also.
2 May 20 12:10:04 NO authentication: SSH authentication failure [username: Name, IP address = 172.xxx.xxx.xxx]
Firmware Version - V4.50(AAHV.2) | 02/27/2018
I haven't tried the latest firmware yet, This switch has also been up for 357 days, but this shouldn't stop the radius server.
Anyone else having experience this issue? Is there a way to just restart the radius service without disrupting the site connected to this switch? The external logging server never actually shows a radius request leaving the switch until after the restart also.
0
All Replies
-
Hi @Kevin_FT
For starters, it's recommended to upgrade to latest 4.50(AAHV.3)C0 which includes the new bugfix.
As for your issue:
1. What is the frequency of the "stop sending" symptom?
2. May I know what RADIUS servers you are using?
3. Could you provide the config (including AAA setting) for us?
Zyxel_Lucious
0 -
1. No direct frequency as I'd have to pour through daily config downloads to find out when that stopped.
2. Microsoft NPS V10.0.17763.1
3.hostname "GS2210"time timezone -700time daylight-saving-timetime daylight-saving-time start-date second sunday march 2time daylight-saving-time end-date first sunday november 2timesync server 172.xx.xx.xxtimesync ntpsnmp-server version v3v2csnmp-server get-community XXXXXXXXsnmp-server set-community XXXXXXXXsnmp-server trap-community XXXXXXXXsnmp-server trap-destination 172.xx.xx.xxsnmp-server trap-destination 172.xx.xx.xx enable traps interface linkup linkdown lldp transceiver-ddm storm-control zuldsnmp-server trap-destination 172.xx.xx.xx enable traps switch mactableservice-control http 80 5remote-management 2remote-management 3remote-management 4remote-management 1 start-addr 172.xx.xx.xx end-addr 172.xx.xx.xx service telnet ftp http icmp snmp ssh httpsremote-management 2 start-addr 172.xx.xx.xx end-addr 172.xx.xx.xx service ftp icmp snmp ssh httpsremote-management 3 start-addr 172.xx.xx.xx end-addr 172.xx.xx.xx service ftp icmp snmp ssh httpsremote-management 4 start-addr 172.xx.xx.xx end-addr 172.xx.xx.xx service ftp icmp snmp ssh httpssyslogsyslog type systemsyslog type interfacesyslog type switchsyslog type aaasyslog type ipsyslog server 172.xx.xx.xx level 6aaa accounting system radius broadcastaaa accounting exec start-stop radius broadcastaaa accounting dot1x start-stop radius broadcastaaa accounting commands 0 stop-only tacacs+ broadcast
The one odd piece which leads me to believe that AAA requests are being sent is that SSH will accept the local logins with the radius client enabled, but no AD creds. The webpage will not accept the local creds, or AD creds until I disable the client on the radius server, which will enable the local logins only.0 -
@Kevin_FT
From your config I don't see config about authentication (in AAA setup) and RADIUS server.
Can you give me the complete config by PM?
0 -
@Kevin_FT
We've tested locally with 2 RADIUS servers working with GS2210 and seemed working fine when flipping between servers.
Maybe you should check if any abnormal log in the 2nd RADIUS server?0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight