If the configurations of the AR2200-S and the authentication server are correct, go to step 5.
Step 5
Run the
display mac-authen
interface
interface-type interface-number
command on the
AR2200-S to check whether the number of online MAC address authentication users has reached
the maximum.
If the number of online MAC address authentication users has reached the maximum, the
AR2200-S does not trigger authentication for subsequent users, and they cannot go online.
Step 6
If the fault persists, collect the following information and contact Huawei technical support
personnel:
l
Results of the preceding troubleshooting procedure
l
Configuration file, log file, and alarm file of the AR2200-S
----End
Relevant Alarms and Logs
Relevant Alarms
l
1.3.6.1.4.1.2011.5.25.171.2.1
Relevant Logs
None.
10.3.3 MAC Address Bypass Authentication of a User Fails
In MAC address bypass authentication, a user terminal first sends an Address Resolution
Protocol (ARP) packet or a Dynamic Host Control Protocol (DHCP) packet to the AR2200-S
to trigger 802.1x authentication. If the AR2200-S does not receive 802.1x packet from the
terminal within 30 seconds, the AR2200-S sends the MAC address of the terminal as the user
name and password to the authentication server.
After MAC address bypass authentication is configured, the AR2200-S starts MAC address
authentication automatically after a user fails to pass the 802.1x authentication. 802.1x
authentication and MAC address authentication cannot be enabled on the same interface. If
802.1x authentication is enabled on the interface, the system displays an error message when
you attempt to enable MAC address authentication. You can enable MAC address bypass
authentication by using the
dot1x mac-bypass
command. In MAC address bypass
authentication, the terminal MAC address is used as the user name and password. The process
of MAC address bypass authentication is the same as the process of MAC address authentication.
The troubleshooting procedure for MAC address bypass authentication failure is similar to the
troubleshooting procedure for MAC address authentication failure. For details, see
Address Authentication of a User Fails
10.4 Firewall Troubleshooting
10.4.1 SYN Flood Attacks Are Detected on a Network
Due to resource restriction the TCP/IP protocol stack permits only a certain number of TCP
connections.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
305