9-10
Cisco IOS Software Configuration Guide for Cisco Aironet Access Points
OL-11350-01
Chapter9 Configuring an Access Point as a Local Authenticator
Configuring a Local Authenticator
Username Successes Failures Blocks
nicky 0 0 0
jones 0 0 0
jsmith 0 0 0
Router#sh radius local-server statistics
Successes : 1 Unknown usernames : 0
Client blocks : 0 Invalid passwords : 0
Unknown NAS : 0 Invalid packet from NAS: 0
NAS : 100.0.0.53
Successes : 1 Unknown usernames : 0
Client blocks : 0 Invalid passwords : 0
Corrupted packet : 0 Unknown RADIUS message : 0
No username attribute : 0 Missing auth attribute : 0
Shared key mismatch : 0 Invalid state attribute: 0
Unknown EAP message : 0 Unknown EAP auth type : 0
Username Successes Failures Blocks
clients_aaa 1 0 0
The first section of statistics lists cumulative statistics from the local authenticator.
The second section lists stats for each access point (NAS) authorized to use the local authenticator. The
EAP-FAST statistics in this section include these stats:
Auto provision success—the number of PACs generated automatically
Auto provision failure—the number of PACs not generated because of an invalid handshake packet
or invalid username or password
PAC refresh—the number of PACs renewed by clients
Invalid PAC received—the number of PACs received that were expired, that the authenticator could
not decrypt, or that were assigned to a client username not in the authenticator’s database
The thirdsecond section lists stats for individual users. If a user is blocked and the lockout time is set to
infinite, blocked appears at the end of the stat line for that user. If the lockout time is not infinite,
Unblocked in x seconds appears at the end of the stat line for that user.
Use this privileged exec mode command to reset local authenticator statistics to zero:
AP# clear radius local-server statistics