19.07.2013 Views

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

CCNP TSHOOT 6.0 - Cisco Learning Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>CCNP</strong>v6 <strong>TSHOOT</strong><br />

Login attempt with incorrect RADIUS ports specified on DLS1:<br />

DLS1#<br />

Dec 4 16:06:50.142: RADIUS/ENCODE(00000005): ask "Username: "<br />

DLS1#<br />

Dec 4 16:06:59.430: RADIUS/ENCODE(00000005): ask "Password: "<br />

DLS1#<br />

Dec 4 16:07:05.487: RADIUS/ENCODE(00000005):Orig. component type = EXEC<br />

Dec 4 16:07:05.487: RADIUS: AAA Unsupported Attr: interface [170] 4<br />

Dec 4 16:07:05.487: RADIUS: 74 74 [ tt]<br />

Dec 4 16:07:05.487: RADIUS/ENCODE(00000005): dropping service type, "radius-server<br />

attribute 6 on-for-login-auth" is off<br />

Dec 4 16:07:05.487: RADIUS(00000005): Config NAS IP: 0.0.0.0<br />

Dec 4 16:07:05.487: RADIUS/ENCODE(00000005): acct_session_id: 5<br />

Dec 4 16:07:05.487: RADIUS(00000005): sending<br />

Dec 4 16:07:05.487: RADIUS/ENCODE: Best Local IP-Address 10.1.50.252 for Radius<br />

-Server 10.1.50.1<br />

Dec 4 16:07:05.487: RADIUS(00000005): Send Access-Request to 10.1.50.1:1645 id<br />

1645/5, len 82<br />

Dec 4 16:07:05.487: RADIUS: authenticator B5 DF D2 00 81 8A C0 08 - 5E 68 DA A<br />

9 59 01 7A 00<br />

Dec 4 16:07:05.487: RADIUS: User-Name [1] 9 "raduser"<br />

Dec 4 16:07:05.487: RADIUS: User-Password [2] 18 *<br />

Dec 4 16:07:05.487: RADIUS: NAS-Port [5] 6 1<br />

DLS1#<br />

Dec 4 16:07:05.487: RADIUS: NAS-Port-Id [87] 6 "tty1"<br />

Dec 4 16:07:05.487: RADIUS: NAS-Port-Type [61] 6 Virtual<br />

[5]<br />

Dec 4 16:07:05.487: RADIUS: Calling-Station-Id [31] 11 "10.1.10.1"<br />

Dec 4 16:07:05.487: RADIUS: NAS-IP-Address [4] 6 10.1.50.252<br />

DLS1#<br />

Dec 4 16:07:10.370: RADIUS: Retransmit to (10.1.50.1:1645,1646) for id 1645/5<br />

DLS1#<br />

Dec 4 16:07:15.269: RADIUS: Retransmit to (10.1.50.1:1645,1646) for id 1645/5<br />

DLS1#<br />

Dec 4 16:07:20.403: RADIUS: Retransmit to (10.1.50.1:1645,1646) for id 1645/5<br />

DLS1#<br />

Dec 4 16:07:25.370: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.1.50.1:1645,1646 is<br />

not responding.<br />

Dec 4 16:07:25.370: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.1.50.1:1645,1646 h<br />

as returned.<br />

DLS1#<br />

Dec 4 16:07:25.370: RADIUS: No response from (10.1.50.1:1645,1646) for id 1645/<br />

5<br />

Dec 4 16:07:25.370: RADIUS/DECODE: parse response no app start; FAIL<br />

Dec 4 16:07:25.370: RADIUS/DECODE: parse response; FAIL<br />

DLS1#<br />

Dec 4 16:07:27.375: RADIUS/ENCODE(00000005): ask "Username: "<br />

The above example shows the exchange between the RADIUS client and server when the client is using port<br />

numbers that do not match the server. Note the retransmits and the server dead messages.<br />

Successful login from PC-B (using valid username raduser on the RADIUS server):<br />

All contents are Copyright © 1992–2010 <strong>Cisco</strong> Systems, Inc. All rights reserved. This document is <strong>Cisco</strong> Public Information. Page 12 of 22

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!