<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved] in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99376#M7024</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an ICX7250-48P (version SPR 8095m) that is exhibiting some strange behavior with RADIUS and I am unsure if it is my configuration or if this is how MAC Auth is expected to work on the ICX line. For reference, I have configured RADIUS before and am currently using another server for a few wireless access points we have. For testing purposes, I was going to point all clients to the default guest VLAN (50) using the DEFAULT in RADIUS. The ICX receives this and changes the port over but then immediately terminates the session which thrashes the clients back and forth between the blackhole VLAN (default: 666) and the default guest VLAN (50). This basically makes the switch unusable since no traffic can get through. I will post my auth config, logs, and RADIUS config below as well. It would be much appreciated if there was anyone out there that could provide any bit of help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;RADIUS config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;# Default to VLAN 50&lt;BR /&gt;DEFAULT Auth-Type := Accept&lt;BR /&gt;Tunnel-Type = "VLAN",&lt;BR /&gt;Tunnel-Medium-Type = "IEEE-802",&lt;BR /&gt;Tunnel-Private-Group-Id = "50",&lt;BR /&gt;Reply-Message = "Hello, %u"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run auth&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authentication&lt;BR /&gt;auth-order mac-auth dot1x&lt;BR /&gt;auth-default-vlan 666&lt;BR /&gt;max-sessions 1024&lt;BR /&gt;reauth-timeout 0&lt;BR /&gt;mac-authentication enable&lt;BR /&gt;mac-authentication enable ethe 1/1/12 ethe 1/1/48&lt;BR /&gt;mac-authentication password-format xx:xx:xx:xx:xx:xx&lt;BR /&gt;mac-authentication dot1x-disable&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;show logging&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Nov 12 20:36:10:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:10:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:10:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: &lt;STRONG&gt;authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;/STRONG&gt;&lt;BR /&gt;Nov 12 20:36:09:N:MAC Authentication succeeded for [c8f7.50fb.0ec4 50] on port 1/1/12&lt;BR /&gt;Nov 12 20:36:09:N:FLEXAUTH: Port 1/1/12 is deleted from Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:09:N:FLEXAUTH: Port 1/1/12 is added into Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:09:N:MACAUTH: Port 1/1/12 Mac c8f7.50fb.0ec4 - received AAA-ACCEPT&lt;BR /&gt;Nov 12 20:36:09:C:MACAUTH: RADIUS server 10.32.0.1 Accepted for c8f7.50fb.0ec4 with (U:50 )&lt;BR /&gt;Nov 12 20:36:09:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 666: Session is created&lt;BR /&gt;Nov 12 20:36:08:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:08:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:08:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;BR /&gt;Nov 12 20:36:07:N:MAC Authentication succeeded for [c8f7.50fb.0ec4 50] on port 1/1/12&lt;BR /&gt;Nov 12 20:36:07:N:FLEXAUTH: Port 1/1/12 is deleted from Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:07:N:FLEXAUTH: Port 1/1/12 is added into Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:07:N:MACAUTH: Port 1/1/12 Mac c8f7.50fb.0ec4 - received AAA-ACCEPT&lt;BR /&gt;Nov 12 20:36:07:C:MACAUTH: RADIUS server 10.32.0.1 Accepted for c8f7.50fb.0ec4 with (U:50 )&lt;BR /&gt;Nov 12 20:36:07:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 666: Session is created&lt;BR /&gt;Nov 12 20:36:05:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:05:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:05:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2024 00:00:25 GMT</pubDate>
    <dc:creator>scottshotgg</dc:creator>
    <dc:date>2024-11-13T00:00:25Z</dc:date>
    <item>
      <title>ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99376#M7024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an ICX7250-48P (version SPR 8095m) that is exhibiting some strange behavior with RADIUS and I am unsure if it is my configuration or if this is how MAC Auth is expected to work on the ICX line. For reference, I have configured RADIUS before and am currently using another server for a few wireless access points we have. For testing purposes, I was going to point all clients to the default guest VLAN (50) using the DEFAULT in RADIUS. The ICX receives this and changes the port over but then immediately terminates the session which thrashes the clients back and forth between the blackhole VLAN (default: 666) and the default guest VLAN (50). This basically makes the switch unusable since no traffic can get through. I will post my auth config, logs, and RADIUS config below as well. It would be much appreciated if there was anyone out there that could provide any bit of help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;RADIUS config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;# Default to VLAN 50&lt;BR /&gt;DEFAULT Auth-Type := Accept&lt;BR /&gt;Tunnel-Type = "VLAN",&lt;BR /&gt;Tunnel-Medium-Type = "IEEE-802",&lt;BR /&gt;Tunnel-Private-Group-Id = "50",&lt;BR /&gt;Reply-Message = "Hello, %u"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run auth&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authentication&lt;BR /&gt;auth-order mac-auth dot1x&lt;BR /&gt;auth-default-vlan 666&lt;BR /&gt;max-sessions 1024&lt;BR /&gt;reauth-timeout 0&lt;BR /&gt;mac-authentication enable&lt;BR /&gt;mac-authentication enable ethe 1/1/12 ethe 1/1/48&lt;BR /&gt;mac-authentication password-format xx:xx:xx:xx:xx:xx&lt;BR /&gt;mac-authentication dot1x-disable&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;show logging&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Nov 12 20:36:10:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:10:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:10:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: &lt;STRONG&gt;authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;/STRONG&gt;&lt;BR /&gt;Nov 12 20:36:09:N:MAC Authentication succeeded for [c8f7.50fb.0ec4 50] on port 1/1/12&lt;BR /&gt;Nov 12 20:36:09:N:FLEXAUTH: Port 1/1/12 is deleted from Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:09:N:FLEXAUTH: Port 1/1/12 is added into Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:09:N:MACAUTH: Port 1/1/12 Mac c8f7.50fb.0ec4 - received AAA-ACCEPT&lt;BR /&gt;Nov 12 20:36:09:C:MACAUTH: RADIUS server 10.32.0.1 Accepted for c8f7.50fb.0ec4 with (U:50 )&lt;BR /&gt;Nov 12 20:36:09:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 666: Session is created&lt;BR /&gt;Nov 12 20:36:08:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:08:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:08:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;BR /&gt;Nov 12 20:36:07:N:MAC Authentication succeeded for [c8f7.50fb.0ec4 50] on port 1/1/12&lt;BR /&gt;Nov 12 20:36:07:N:FLEXAUTH: Port 1/1/12 is deleted from Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:07:N:FLEXAUTH: Port 1/1/12 is added into Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:07:N:MACAUTH: Port 1/1/12 Mac c8f7.50fb.0ec4 - received AAA-ACCEPT&lt;BR /&gt;Nov 12 20:36:07:C:MACAUTH: RADIUS server 10.32.0.1 Accepted for c8f7.50fb.0ec4 with (U:50 )&lt;BR /&gt;Nov 12 20:36:07:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 666: Session is created&lt;BR /&gt;Nov 12 20:36:05:N:FLEXAUTH: Port 1/1/12 is deleted from Dynamic Vlan 50 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:05:N:FLEXAUTH: Port 1/1/12 is added into Auth-Default Vlan 666 as mac-vlan member&lt;BR /&gt;Nov 12 20:36:05:N:MACAUTH: port 1/1/12 mac c8f7.50fb.0ec4 vlan 50: authenticated Session is Cleared[Termination-Cause: Host-Moved]&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 00:00:25 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99376#M7024</guid>
      <dc:creator>scottshotgg</dc:creator>
      <dc:date>2024-11-13T00:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99377#M7025</link>
      <description>&lt;P&gt;I have upgraded to SPS8095p and it is still exhibiting the same issues&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 01:07:23 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99377#M7025</guid>
      <dc:creator>scottshotgg</dc:creator>
      <dc:date>2024-11-13T01:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99387#M7026</link>
      <description>&lt;P&gt;For some reason it is also adding tagged traffic to the VLAN instead of untagged like I had expected. If I manually set untagged on a VLAN everything works fine.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 01:35:19 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99387#M7026</guid>
      <dc:creator>scottshotgg</dc:creator>
      <dc:date>2024-11-13T01:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99435#M7027</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;
&lt;P&gt;Based on the issue, could you let us know if there are 2 clients connecting on the interface, as in IP phone and a PC after the Phone ?&lt;/P&gt;
&lt;P&gt;And during the auth cycle, one of the devices get authenticated first but when the second one comes in the termination happens for connected peers ?&lt;/P&gt;
&lt;P&gt;Do let us know.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 11:11:55 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99435#M7027</guid>
      <dc:creator>jdryan</dc:creator>
      <dc:date>2024-11-14T11:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99442#M7029</link>
      <description>&lt;P&gt;Hi @jdryan,&lt;/P&gt;&lt;P&gt;Thank you for responding.&lt;/P&gt;&lt;P&gt;To answer - no, that port runs straight through to an ethernet port connected to a linux PC. I have also tried various other auth modes such as multi-host, multi-untagged, etc just to see if those would solve it&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 16:36:38 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99442#M7029</guid>
      <dc:creator>scottshotgg</dc:creator>
      <dc:date>2024-11-14T16:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7250 authenticated Session is Cleared[Termination-Cause: Host-Moved]</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99493#M7032</link>
      <description>&lt;P&gt;Multi-host works best when AP or Hub is connected. &lt;BR /&gt;Multi-untagged works best when IP phones are connected. &lt;/P&gt;
&lt;P&gt;Here single-untagged/single-host [ default ]&amp;nbsp; would be best mode to go on. &lt;BR /&gt;&lt;BR /&gt;This may need to be investigated further as its also observed on code 8095p. &lt;BR /&gt;Please do have the below debugs collected over console :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;skip &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show log &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;show tech&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;ptrace aaa&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;debug ip aaa &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;capture the issue state &amp;gt; &lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;no debug all / undebug all&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once these are collected do reach us out on the support front so that we can investigate this further. &lt;BR /&gt;Please do raise a case via here : &lt;A href="https://support.ruckuswireless.com/contact-us" target="_blank"&gt;https://support.ruckuswireless.com/contact-us&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 12:15:36 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7250-authenticated-Session-is-Cleared-Termination-Cause-Host/m-p/99493#M7032</guid>
      <dc:creator>jdryan</dc:creator>
      <dc:date>2024-11-15T12:15:36Z</dc:date>
    </item>
  </channel>
</rss>

