Troubleshooting guide
3. Troubleshooting Functional Failures During Operation
124
3 Execute the
show fense server command to
check the operating status of the authentication
VLAN.
• If VAA NAME is not set (i.e.,
- is displayed), the fense
vaa-name command is not set in the configuration. Set the
fense vaa-name command in the configuration.
• If
disable is displayed for Status of VAA IDs, the
authentication VLAN is not operating. Check the
configuration.
• For other cases, go to No. 4.
4 Execute the show fense server command to
check the connection status to the
authentication server.
• If the IP address of the authentication server is not
displayed for
Server Address of VAA IDs,
communication with the authentication server is not
possible. That is also the case if the TCP port number of the
authentication server is not displayed for
Port of VAA
IDs. Check the configuration.
• If a value other than
CONNECTED is displayed for Agent
Status of VAA IDs, the VLAN is not connected to the
authentication server. Check the status and settings of the
authentication server.
• For other cases, go to No. 5.
5 Execute the
show fense server command
with the
detail parameter to check the setting
of the fense vlan configuration.
• If no VLAN ID is displayed for VAA IDs or incorrect
information is displayed, there is no VLAN to be switched
after authentication of terminals. Check the configuration.
• For other cases, go to No. 6.
6 Execute the
show fense statistics
command multiple times to check the
connection status to the authentication server.
• If the values of
Connect Failure Count and Timeout
Disconnect Count increase for VAA IDs, the connection
to the authentication server is unstable. Check the status of
the network between the authentication server and
authentication VLAN.
• If the network status is normal, make sure that the
alive-time value set by the fense alive-timer
configuration command and the setting parameters
(
HCinterval and RecvMsgTimeout) for the
authentication server meet the following conditions.
alive-time >= HCinterval + 5
RecvMsgTimeout >= HCinterval + 5
• If the authentication VLAN repeats connecting and
disconnecting to the authentication server, use the
restart vaa command to restart the authentication
VLAN. Furthermore, restart VLANaccessController on the
authentication server as well as the respective functions of
the authentication VLAN.
• For other cases, go to No. 7.
7 Execute the
show fense statistics
command, and make sure communication with
the MAC VLAN functionality is operating
normally.
• If the
Request count of VLANaccessAgent Recv
Message of VAA IDs does not match the Request count
of
Terget-VLAN Registration, an internal
inconsistency has occurred. Use the restart vaa
command to restart the authentication VLAN.
• For other cases, go to No. 8.
No. Items to check and commands Action