<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21277#M883</link>
    <description>Mine looks something like this:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.4.5.6&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server key 2 $TF53PjpTMzl0XnwxIUtQMGldd3d3azB0dK3aWjlPMl1LfGd1a1M+IzosNlZoeCFZY0NMaDpVcSxMKG4/clBLXg==&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It is working.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Have you authorized the IP in NPS?&amp;nbsp; Have you debugged Radius?&amp;nbsp; Are you certain which IP the switch is using to communicate to NPS as its source?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Wed, 24 Jul 2019 19:27:19 GMT</pubDate>
    <dc:creator>netwizz</dc:creator>
    <dc:date>2019-07-24T19:27:19Z</dc:date>
    <item>
      <title>Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21276#M882</link>
      <description>&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;Looking for the SME out there that has the information regarding implementing Windows NPS as a small to medium scale version of RADIUS authentication. I have found snips here and there of pieces of the puzzle but they don't seem to be coming together correctly to properly authenticate. This is what I have so far:&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;-NPS Service is started and registered with AD&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;-RADIUS client is added with "friendly Name" and IP &lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;-Switch has the following aaa commands:&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;aaa authentication enable default&amp;nbsp;radius enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authorization exec default radius&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa accounting commands 0 default start-stop radius&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;radius-server x.x.x.x&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;radius-server key test&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;I have tried several Network policies and configurations that I found online, but nothing seems to be the key to the castle.&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;I am currently getting access denied statements from the switch and NPS logs are saying an unauthorized IP&amp;nbsp; is attempting to access the NPS with code 13 listed.&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;Any assistance is appreciated.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 19:07:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21276#M882</guid>
      <dc:creator>james_schena</dc:creator>
      <dc:date>2019-07-24T19:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21277#M883</link>
      <description>Mine looks something like this:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.4.5.6&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server key 2 $TF53PjpTMzl0XnwxIUtQMGldd3d3azB0dK3aWjlPMl1LfGd1a1M+IzosNlZoeCFZY0NMaDpVcSxMKG4/clBLXg==&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It is working.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Have you authorized the IP in NPS?&amp;nbsp; Have you debugged Radius?&amp;nbsp; Are you certain which IP the switch is using to communicate to NPS as its source?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 24 Jul 2019 19:27:19 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21277#M883</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2019-07-24T19:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21278#M884</link>
      <description>I built the switch as a RADIUS client in NPS, so when you say authorized the IP in NPS I'm not 100% certain what else there is to do in that aspect??&lt;BR /&gt;&lt;BR /&gt;When I check to logs it says the ssh is rejected when I try RADIUS, but it will still fail over to local credentials. I can reach the switch via ssh on the same IP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did you need to build any NPS policies of any kind?</description>
      <pubDate>Wed, 24 Jul 2019 20:08:30 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21278#M884</guid>
      <dc:creator>james_schena</dc:creator>
      <dc:date>2019-07-24T20:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21279#M885</link>
      <description>Like Netwizz said,&amp;nbsp;Are you certain which IP the switch is using to communicate to NPS as its source?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;you should see the same client ip in the event log of nps and in the client you defined...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;you could force it with "ip radius source-interface" if its not the ip you expected.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 25 Jul 2019 12:26:10 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21279#M885</guid>
      <dc:creator>andr_boucher_5j</dc:creator>
      <dc:date>2019-07-25T12:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 2/3 switching: Trouble Implementing RADIUS via Windows NPS to 
authenticate login</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21280#M886</link>
      <description>I have verified the IP's on both ends and the logs in NPS confirmed the IP of the client is correct, but it says it is invalid IP.&amp;nbsp;</description>
      <pubDate>Thu, 25 Jul 2019 12:32:48 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/Layer-2-3-switching-Trouble-Implementing-RADIUS-via-Windows-NPS/m-p/21280#M886</guid>
      <dc:creator>james_schena</dc:creator>
      <dc:date>2019-07-25T12:32:48Z</dc:date>
    </item>
  </channel>
</rss>

