Run the
display mac-authen
command to check whether MAC address authentication is enabled
globally or on the user-side interface. If
MAC address authentication is enabled
is not
displayed, MAC address authentication is not enabled. Run the
mac-authen
command to enable
MAC address authentication globally and on the user-side interface.
CAUTION
802.1x authentication and MAC address authentication cannot be enabled on the same interface.
If 802.1x authentication is enabled on the interface, the system displays an error message when
you run the
mac-authen
command.
Step 2
Check the configuration of the user name for MAC address authentication.
Run the
display this
command in the interface view to check the configuration of MAC address
authentication on the interface. If MAC address authentication is not configured on the interface,
the global configuration is used. Run the
display mac-authen
command to check the
configuration of global MAC address authentication.
MAC address authentication supports two user name formats: fixed user name and MAC
address.
l
If the user MAC address is used as the user name, the AR2200-S sends the MAC address of
the user terminal as the user name and password to the authentication server. The
authentication domain is configured by the
mac-authen domain
command. If no
authentication domain is configured, the default domain is used.
l
When the fixed user name contains a domain name, this domain is used as the authentication
domain. If the fixed user name does not contain a domain name, the default domain is used
as the authentication domain.
NOTE
A MAC address may contain or not contain the delimiter (-). By default, a MAC address does not contain
the delimiter. You can use the
mac-authen username macaddress format with-hyphen
command to add
delimiters to a MAC address. During authentication, ensure that the format of the MAC address you entered
is the same as the MAC address format configured on the AR2200-S.
Check the authentication server template and AAA schemes bound to the authentication domain.
Go to step 3.
Step 3
Check the AAA configuration.
1.
Check the configuration of the authentication server template bound to the domain. Ensure
that the IP address and port of the authentication server are set correctly in the template,
and that the user name format and shared key specified in the template are the same as those
on the authentication server.
2.
Check the authentication scheme applied to the user domain on the AR2200-S.
l
If RADIUS or HWTACACS authentication is configured for the user domain, check
whether the user account and the user attributes are created on the authentication server.
For details on RADIUS troubleshooting and HWTACACS troubleshooting, see
and
10.1.2 HWTACACS Authentication Fails
details on checking the authentication server, go to step 4.
l
If local authentication is configured for the user domain, run the
display local-user
command to check whether the local user name and password are created on the
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
303