3. Troubleshooting Functional Failures in Operation

3.12.3Communication Failure on Using MAC Authentication

For MAC authentication failure, isolate the problem according to the failure analysis method described in "Table 3-53: Failure Analysis Method for MAC Authentication."

For confirming Web authentication configuration and accounting information, isolate the problem according to the failure analysis method described in "Table 3-54: Checking MAC Authentication Configuration" and "Table 3-55: MAC Authentication Failure Analysis Method."

Table 3-53: Failure Analysis Method for MAC Authentication

No.

Troubleshooting Steps and Command

Action

 

 

 

1

Check to see if the terminal can communicate.

If authentication in Local authentication method failed, go to No. 2.

 

 

If authentication in RADIUS authentication method failed, go to

 

 

No.3.

 

 

Otherwise, go to No.5.

 

 

 

2

Check to see if MAC address and VLAN ID are

If MAC address is not registered yet, set MAC address and VLAN

 

registered by the show mac-authentication

ID by the set mac-authentication mac-address

 

mac-address command.

command.

 

 

Otherwise, go to No. 5.

3

Check to see the status of communication with

When "TxTotal" of [Account frames] indicates 0, confirm all of the

 

RADIUS server by the show

settings by configuration commands (aaa accounting

 

mac-authentication statistics

web-authentication default start-stop group

 

command.

radius, radius-server host, and

 

 

mac-authentication radius-server host) are correct.

 

 

For IP8800/S3600 and IP8800/S2400 models, even though the dead

 

 

interval lets RADIUS server get recovered from no-response state

 

 

and become able to communicate, the system is not able to collate

 

 

with the RADIUS server during a period of time specified by

 

 

configuration command authentication radius-server

 

 

dead-interval. As a result, an authentication error occurs.

 

 

In this case, if the period of time is too long for the system to wait for

 

 

an authentication error response, change the set value of

 

 

configuration command authentication radius-server

 

 

dead-interval or execute the clear

 

 

web-authentication dead-interval-timer command.

 

 

Authentication action against the first RADIUS will be taken again.

 

 

Otherwise, go to No. 4.

 

 

 

4

Check to see if MAC address and password are

If MAC address has not been registered as a User ID for RADIUS

 

registered in RADIUS server.

Server yet, register it.

 

 

If you use MAC address as a password, set the same value as in MAC

 

 

address.

 

 

Once you registered common values to the RADIUS servers as a

 

 

password, check to see if the password is the same as one registered

 

 

by the configuration command mac-authentication

 

 

password.

 

 

Otherwise, go to No.5.

 

 

 

97

Page 159
Image 159
NEC IP8800/S6300 manual Communication Failure on Using MAC Authentication, Failure Analysis Method for MAC Authentication

IP8800/S6700, IP8800/S3600, IP8800/S6600, IP8800/S6300, IP8800/S2400 specifications

The NEC IP8800 series comprises a range of advanced networking solutions designed for various applications ranging from enterprise networking to service provider environments. This series includes models such as the IP8800/S2400, IP8800/S3600, IP8800/S6300, IP8800/S6600, and IP8800/S6700, each with its unique set of features and capabilities aimed at delivering robust performance, security, and scalability.

The IP8800/S2400 is an entry-level switch tailored for small to medium enterprises. It features a compact design and high port density, making it ideal for network edge applications. The model supports both Layer 2 and Layer 3 switching capabilities, enabling efficient traffic management. With its robust security features, including access control lists and support for VLANs, the IP8800/S2400 ensures secure connectivity.

Moving to the IP8800/S3600, this switch is designed for data center environments and offers high throughput with advanced routing capabilities. It is equipped with high-capacity 10G and 40G Ethernet ports, facilitating faster data transfer rates. The S3600 supports various protocols such as MPLS and Segment Routing, enhancing its ability to manage complex network architectures. Its energy-efficient design also helps reduce operational costs.

The IP8800/S6300 is tailored for high-performance networking scenarios, featuring a flexible architecture that supports both traditional and cloud-based services. With extensive QoS capabilities, the S6300 optimizes traffic flow and manages bandwidth efficiently, ensuring high-quality service delivery. Its virtualization support allows for easier integration into modern, software-defined networking environments.

The IP8800/S6600 provides a comprehensive solution for service providers and large enterprises, boasting high scalability and modularity. This model supports advanced features such as network slicing and the ability to handle high-density 100G interfaces. Its robust management tools, including centralized control and automation capabilities, simplify network operations significantly.

Finally, the IP8800/S6700 represents the pinnacle of the series, designed for mission-critical applications requiring the utmost reliability and performance. It supports advanced analytics, AI-driven insights, and comprehensive telemetry, enabling proactive network management. With high availability features and extensive redundancy options, the S6700 ensures continuous operation, making it ideal for core network functions.

In summary, the NEC IP8800 series offers a versatile range of switches that combine advanced technologies, high performance, and robust security features, catering to various networking needs across different industries. Each model is designed to provide not only superior connectivity but also the flexibility and scalability required in today’s fast-paced digital landscape.