Troubleshooting guide
3. Troubleshooting Functional Failures During Operation
54
as a VLAN after RADIUS authentication.
Specify a unique VLAN name. If the same VLAN name is used for two or more VLANs, the
smallest VLAN ID is allocated as the post-authentication VLAN in RADIUS authentication mode.
Do not specify a number at the beginning of the VLAN name. A number at the
beginning will be recognized as the VLAN ID, which might result in an
authentication failure.
If communication is not possible on a port or VLAN that uses IEEE 802.1X, isolate the
cause of the problem according to the failure analysis method described in the table below.
If the item in the table does not apply, see
3.5 Layer 2 network communication failures.
Table 3-26 Communication failure analysis method for IEEE 802.1X
No. Items to check and commands Action
1 Check whether the authenticated
terminal has moved to an
unauthenticated port in the same
VLAN.
If the terminal authenticated on the Switch has moved to an
unauthenticated port, communication is disabled until the
authentication information is cleared. Use the clear dot1x
auth-state operation command to clear the authentication
status of the terminal.
3.7.2 Communication failures occurring when Web authentication is used
If a failure occurs when Web authentication is used, isolate the cause of the problem
according to the failure analysis method described in the following table.
Table 3-27 Failure analysis method for Web authentication
No. Items to check and commands Action
1 Check whether the login page
appears on the terminal.
If the login page and logout page do not appear, go to No. 2.
If the login page appears in local authentication mode, go to
No. 5.
If the login page appears in RADIUS authentication mode, go
to No. 7.
2 Check whether the URLs specified
for login and logout are correct.
If incorrect URLs are specified for login or logout, use the
correct URLs.
If the Web authentication IP address has been set, make sure
the IP address for the VLAN (dynamic or fixed VLAN) for
which Web authentication is to be performed has been set by
the ip address configuration command.
If fixed VLAN mode or dynamic VLAN mode is set, go to No. 3.
For other cases, go to No. 9.
3 Check the setting of the Web
authentication IP address or URL
redirection in fixed VLAN mode
and dynamic VLAN mode.
[Fixed VLAN mode] [Dynamic VLAN mode]
Check whether the Web authentication IP address has been
set in the web-authentication ip address configuration
command or URL redirection has been enabled by the
web-authentication redirect enable configuration
command.
If URL redirection is enabled, make sure the IP address is set
for a VLAN that is authenticated in fixed VLAN mode or
dynamic VLAN mode by using the ip address configuration
command.
For other cases, go to No. 4.