Troubleshooting guide
3. Troubleshooting Functional Failures During Operation
115
failures.
Table 3-58: Communication failure analysis method for IEEE 802.1X
3.13.2 Communication failures occurring when Web authentication is used
If a failure occurs when Web authentication is used, isolate the cause of the problem according to
the failure analysis method described in Table 3-59: Failure analysis method for Web
authentication.
For details about checking the configuration and accounting of Web authentication, see
Table 3-60: Checking the configuration of Web authentication and Table 3-61: Checking the
accounting of Web authentication, respectively, to isolate the cause of the problem.
Table 3-59: Failure analysis method for Web authentication
No. Items to check and commands Action
1 Make sure that VLANs with a VLAN-based
authentication (static) setting and VLANs with
another setting are not set simultaneously for
the trunk port.
Communication is possible only for VLANs with a
VLAN-based authentication (static) setting. Set all those
VLANs for a port excluded from authentication, or set the
VLANs with a VLAN-based authentication (static) setting for
one port and the VLANs with another setting for another port.
2 Check whether the authenticated terminal has
moved to an unauthenticated port in the same
VLAN.
If the terminal authenticated on the Switch has moved to an
unauthenticated port, communication is disabled until the
authentication information is cleared. Use the
clear dot1x
auth-state command to clear the authentication status of the
terminal.
No. Items to check and commands Action
1 Check whether the login page appears on the
terminal.
• If the login page and logout page do not appear, go to No. 2.
• If the login page appears in local authentication method, go
to No. 5.
• If the login page appears in RADIUS authentication
method, go to No. 7.
• If the operation log message is displayed, go to No. 14.
2 Check whether the URLs specified for login
and logout are correct.
• If incorrect URLs are specified for login or logout, use the
correct URLs.
• If the login page or logout page is not displayed in fixed or
dynamic VLAN mode, check and modify the following
settings:
AX6700S, AX6600S, and AX6300S series switches:
Make sure that a Web authentication IP address has been
set with the
web-authentication ip address
configuration command. If URL redirection is used in
dynamic VLAN mode, check whether the
web-authentication redirect-vlan configuration
command has been set.
AX3800S, AX3600S, and AX2400S series switches:
Check whether the Web authentication IP address has
been set in the
web-authentication ip address
configuration command or URL redirection has been
enabled by the
web-authentication redirect enable
configuration command.
• For other cases, go to No. 3.