Technical information

7
3
rd
Party Authentication and Accounting Software FAQs
Q9. RADIUS authentication is not working. How can I troubleshoot
RASExpress and RADIUS problems?
A9. If you are dialing into the CommPlete Server using a PPP dialer (such as Win95
Dial-Up Networking) try to dial in using a terminal program.
Dial into the rack using HyperTerminal (or any other terminal program). Log into
the RASExpress Server manually. If you can log in and get to a RASExpress
menu, the RASExpress Server is communicating with RADIUS. There could be
an incorrect setting in RADIUS that is not allowing the remote user to connect via
PPP, or possibly PAP authentication is turned off in RADIUS.
If dialing from a terminal program works, try to dial in using the Win95 dialer.
Before dialing in, change the Connection Settings so the Terminal Window will
appear after connection. Dial out using the Win95 dialer, but then type the
Username and Password manually. Then choose Option #1 (PPP Session) and
click the Continue button. If this works, there is a problem with PAP
authentication and RADIUS.
If this doesn't work, you may have an IP assignment problem. If you are using
DHCP IP addressing, try setting a static group of IP addresses in the
RASExpress Server. Telnet into the RASExpress Server and change the IP
assignment type to Address Pool. Configure the RASExpress pool to use 24 IP's
that are available on your network.
Make sure that you have RADIUS as the security type on your RASExpress
Server. Also be sure the Primary Server IP address is pointing to your RADIUS
server. The Secret password must match the password you have configured in
the RADIUS server. Also, make sure the IP address of the RASExpress Server
and the Key are in the RADIUS Clients file. The Client Name must be the IP
address of the RASExpress Server (not the server name). The Key must be the
Secret Password that you have set in the RASExpress Server security section
(case sensitive).
See also Q59.
Q10. My TACACS+ server is not authenticating. What could be the
problem?
A10. Make sure that TACACS+ is set as the Security Type in RASExpress. Also make
sure that TACACS+ Encryption is Enabled and the IP address of the Primary
Server is pointed towards your TACACS+ server.
If you are dialing into the CommPlete Server using a PPP dialer (such as Win95
Dial-Up Networking), try to dial in using a terminal program.
Dial into the rack using HyperTerminal (or any other terminal program). Log into
the RASExpress Server manually. If you can log in and get to a RASExpress
menu, the RASExpress
Server is communicating with TACACS+. There could be an incorrect setting in
TACACS+ that is not allowing the remote user to connect via PPP, or PAP
authentication may be turned off in TACACS+.










