802.1X RADIUS failed

MAKA
New here

802.1X RADIUS failed

My users are getting intermittent 802.1X RADIUS failed errors every so often throughout the day.

disconnect last 1-2 secs enough to drop a call or lose internet connection..

anyone experience these types of issues?

 

6 Replies 6
RaphaelL
Kind of a big deal
Kind of a big deal

Hi ,


We are missing a lot of info here.

 

What version are you running ?

What firmware version are you running ?

What AP models ?

SSID Configurations ?

802.11r enabled ?

Any logs from Wireless health ?

What version are you running ?  MR 29.4.1

What firmware version are you running ?

What AP models ? MR 44 

SSID Configurations ? 802.1X with radius

802.11r enabled ?

Any logs from Wireless health ?  

Client xxxxxxx had a failed connection to SSID XXXX during authentication because the auth server rejected the auth request.
802.11 REASON (CODE 23)
802.1X RADIUS failed

PhilipDAth
Kind of a big deal
Kind of a big deal

A RADIUS failure is usually related to ether the RADIUS server or the device.

 

What does the RADIUS server log say?  Did it see the request?  Did it decline the request, and if so, what reason did it give?

What does the client event log say?

Event 5400 Authentication failed
Failure Reason 15039 Rejected per authorization profile
Resolution Authorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results.
Root cause Selected Authorization Profile contains ACCESS_REJECT attribute

 

even tho we get the message above, user reconnects within seconds - issue is that the disconnect happens frequent throughout the day 

 

we are looking at increasing timeout setting to 5 secs from 1 sec.

PhilipDAth
Kind of a big deal
Kind of a big deal

I wouldn't worry about the timeouts while your RADIUS server is saying it is refusing the connection.  What about your authorization profile is causing it to reject the connection?

 

What is your RADIUS server?  Cisco ISE?  Something else?

We use Cisco ISE, as for the auth profile we only have one for all our internal users.

 

The weird thing is that the user actually is able to connect but randomly gets disconnected a few times throughout the day. The disconnect is 2-3 secs  

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels