Troubleshooting guide

3. Troubleshooting Functional Failures During Operation
120
Check the following for the accounting of Web authentication.
Table 3-61: Checking the accounting of Web authentication
3.13.3 Communication failures occurring when MAC-based authentication is
used
If a failure occurs when MAC-based authentication is used, isolate the cause of the problem
according to the failure analysis method described in Table 3-62: Failure analysis method for
MAC-based authentication.
For details about checking the configuration and accounting of MAC-based authentication, see
Table 3-63: Checking the configuration of MAC-based authentication and
Table 3-64: Checking the accounting of MAC-based authentication, respectively, to isolate the
cause of the problem.
5 Check the configuration of the access filter for
authentication.
For fixed or dynamic VLAN mode, make sure the filter
conditions required for communication from unauthenticated
terminals to destinations outside the Switch have been set
correctly by using the
authentication ip access-group
and
ip access-list extended configuration commands.
6 Check the ARP relay configuration. For AX3800S, AX3600S, and AX2400S series switches, in
fixed or dynamic VLAN mode, make sure the
authentication arp-relay configuration command has
been set correctly so that unauthenticated terminals can send
ARP packets to devices outside the Switch.
No. Items to check Action
1 Check whether authentication result account
logs have been correctly recorded.
If no authentication state is displayed in the execution
result of the
show web-authentication login
command, see Table 3-59: Failure analysis method for
Web authenticationand take necessary action.
If the logs are not recorded on the accounting server, go to
No. 2.
If the logs are not recorded on the syslog server, go to No.
3.
2Use the
show web-authentication
statistics command to check the
communication status with the accounting
server.
If the value displayed for
TxTotal under [Account
frames] is 0, check whether the aaa accounting
web-authentication default start-stop group
radius or radius-server host configuration command
has been set correctly.
For other cases, check the Web authentication
configuration.
3 Check the syslog server configuration. Make sure the following configuration commands have been
set correctly.
Make sure that the syslog server has been set by the
logging host command.
Make sure that
aut has been set for the event type in the
logging event-kind command.
Make sure that the
web-authentication logging
enable command has been set.
No. Items to check Action