New Posts  All Forums:Forum Nav:

RADIUS

post #1 of 17
Thread Starter 
Having problems with access points connected to NPS, w2k8 r2.
There are total of 7 AP's in network. 6 of them are Engenius EAP3660 PoE devices. HP procurve switches. 1 of them is Edimax low end cheap-o device.
Two WiFi network configured across 6 engeniu AP's. One is WAP (LAN1 172.x.x.x guest network) and second is 802.1x (LAN2 192.x.x.x) with AD based auth.
From time to time these 2 will stop authenticate users on 802.1x network. When this happens I still can connect to LAN1 and have access to web and lan. It won't drop clients that are already connected and authenticated with 802.1x, it will stop for new clients.
There are no warning or error event with NPS. Temp fix is just to reboot device.

On top of that there is Edimax device. I had there some cheap 3com switch. Instead of just stopping authenticate clients it would kill network on every single device connected to that switch. Now with hp 1810 it will kill only itself. No ping to device.


Some logs from AP:
Quote:
Can't connect to network
Aug 15 16:19:44 (none) daemon.info hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.11: associated
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: PMKID found from PMKSA cache
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: event 1 notification
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: start authentication
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: PMK from PMKSA cache - skip IEEE 802.1X/EAP
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: start authentication
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: sending 1/4 msg of 4-Way Handshake
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: received EAPOL-Key frame (2/4 Pairwise)
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: sending 3/4 msg of 4-Way Handshake
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: received EAPOL-Key frame (4/4 Pairwise)
Aug 15 16:19:44 (none) daemon.info hostapd: ath1: STA 38:e7:d8:8e:20:86 WPA: pairwise key handshake completed (RSN)
Aug 15 16:19:44 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: authorizing port
Aug 15 16:19:44 (none) daemon.info hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: authenticated
Aug 15 16:19:44 (none) daemon.debug setup.cgi[30800]: main: process ./html/CM_LogList.htm takes 500 ms
Aug 15 16:19:50 (none) daemon.debug hostapd: ath1: STA 88:c6:63:e2:d6:73 IEEE 802.1X: EAP timeout
Aug 15 16:19:50 (none) daemon.debug hostapd: ath1: STA 88:c6:63:e2:d6:73 IEEE 802.1X: aborting authentication
Aug 15 16:19:50 (none) daemon.debug hostapd: ath1: STA 88:c6:63:e2:d6:73 IEEE 802.1X: unauthorizing port
Quote:
Working
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 RADIUS: Received RADIUS packet matched with a pending request, round trip time 0.00 sec
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: using EAP timeout of 30 seconds (from RADIUS)
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: decapsulated EAP packet (code=1 id=5 len=43) from RADIUS server: EAP-Request-PEAP (25)
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: STA 38:e7:d8:8e:20:86 IEEE 802.1X: received EAP packet (code=2 id=5 len=80) from STA: EAP Response-PEAP (25)
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: RADIUS Sending RADIUS message to authentication server
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: RADIUS Next RADIUS client retransmit in 3 seconds
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: RADIUS Received 143 bytes from RADIUS server
Aug 15 16:23:40 (none) daemon.debug hostapd: ath1: RADIUS Received RADIUS message
Quote:
Log from NPS when I couldn't connect
192.168.101.152,user,08/19/2012,12:43:58,IAS,TD-DC1,4,192.168.101.152,5,0,30,00-02-6F-A9-C5-C5:DOMAIN,31,38-E7-D8-8E-20-86,12,1400,61,19,77,CONNECT 11Mbps 802.11b,4108,192.168.101.152,4116,0,4128,AP - Main Door,4154,Secure Wireless Connections,4155,1,4129,DOMAIN\user,4130,DOMAIN\user,4149,Secure Wireless Connections,25,311 1 192.168.100.11 08/13/2012 04:41:02 15005,8136,1,4132,Microsoft: Secured password (EAP-MSCHAP v2),8111,0,8153,0,4127,11,4136,1,4142,0
192.168.101.152,user,08/19/2012,12:43:58,IAS,TD-DC1,25,311 1 192.168.100.11 08/13/2012 04:41:02 15005,4132,Microsoft: Secured password (EAP-MSCHAP v2),4127,11,8100,0,4108,192.168.101.152,4116,0,4128,AP - Main Door,4120,0x015444524F52,4154,Secure Wireless Connections,4155,1,4129,domain\user,4130,DOMAIN\user,4149,Secure Wireless Connections,8136,1,7,1,6,2,8111,0,8153,0,4136,2,4142,0

What do you think?

P.S. Before you say devices are bad and need to be replaced think about edimax and TPlink (that was in edimax place and did same thing).
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #2 of 17
What events are you seeing on the NPS? Is it even showing a connection? All the clients are defined in the NPS, or did you do an IP range and radius shared secret? Is it only 1 radius server or 2?
 
Home server
(13 items)
 
 
CPUMotherboardGraphicsRAM
Phenom II x3 720 ASUS M4N98TD EVO SLI Galaxy GTX 460 768MB GC G Skill Cheapo DDR3 10666  
Hard DriveHard DriveOptical DriveCooling
OCZ Solid 3 Seagate Sony IDE DVD-RW Corsair A-50 
OSMonitorKeyboardPower
Windows 7 Pro  Samsung T240HD  Logitech G15 Corsair TX750 
CaseMouseMouse PadAudio
Cooler Master HAF 932 Logitech G5  Steel Series Orange Giant Cloth Pad Logitech G35 
CPUMotherboardGraphicsRAM
AMD Phenom X4 9500 Asus M3N78 Pro On board Corsair XMS2 DDR2 800 
Hard DriveHard DriveHard DriveHard Drive
Western Digital Velociraptor Samsung Sata Hitatchi Samsung 
Optical DriveCoolingOSPower
Polaroid USB DVD ROM Thermaltake TR2-R1 CentOS6 x86_64 Ultra 600W 
Case
Ultra X-Blaster 
  hide details  
Reply
 
Home server
(13 items)
 
 
CPUMotherboardGraphicsRAM
Phenom II x3 720 ASUS M4N98TD EVO SLI Galaxy GTX 460 768MB GC G Skill Cheapo DDR3 10666  
Hard DriveHard DriveOptical DriveCooling
OCZ Solid 3 Seagate Sony IDE DVD-RW Corsair A-50 
OSMonitorKeyboardPower
Windows 7 Pro  Samsung T240HD  Logitech G15 Corsair TX750 
CaseMouseMouse PadAudio
Cooler Master HAF 932 Logitech G5  Steel Series Orange Giant Cloth Pad Logitech G35 
CPUMotherboardGraphicsRAM
AMD Phenom X4 9500 Asus M3N78 Pro On board Corsair XMS2 DDR2 800 
Hard DriveHard DriveHard DriveHard Drive
Western Digital Velociraptor Samsung Sata Hitatchi Samsung 
Optical DriveCoolingOSPower
Polaroid USB DVD ROM Thermaltake TR2-R1 CentOS6 x86_64 Ultra 600W 
Case
Ultra X-Blaster 
  hide details  
Reply
post #3 of 17
Thread Starter 
Quote:
Originally Posted by herkalurk View Post

What events are you seeing on the NPS? Is it even showing a connection? All the clients are defined in the NPS, or did you do an IP range and radius shared secret? Is it only 1 radius server or 2?

When this happens there are no events in event viewer. Apart from that there are 6273 (The user attempted to use an authentication method that is not enabled on the matching network policy.), 4400 (A LDAP connection with domain controller Dc1.domain.local for domain DOMAIN is established.)
Accounting is configured, last quote is from that log.
Is it even showing a connection as in successful log? Nope, only failures are logged.
All clients in the NPS are defined + manual shared secret. Triple checked, recreated. As it was my first guess smile.gif
Just one radius server.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #4 of 17
This might seem stupid, but are the RADIUS server and other devices configured with a static IP? And did you test all the relevant physical connections (the wires)?
Server
(10 items)
 
  
CPUMotherboardRAMHard Drive
Intel Xeon E3110 ASUS P5Q Premium 8GB G.Skill DDR2-800 2TB Caviar Green 
Hard DriveCoolingOSCase
1TB Caviar Black Prolimatech Megahalems VMWare ESX CM Stacker STC-T01 
OtherOther
LSI 9280-16i4e RAID Card Intel Pro/1000 PT Quad-Port Gigabit NIC 
  hide details  
Reply
Server
(10 items)
 
  
CPUMotherboardRAMHard Drive
Intel Xeon E3110 ASUS P5Q Premium 8GB G.Skill DDR2-800 2TB Caviar Green 
Hard DriveCoolingOSCase
1TB Caviar Black Prolimatech Megahalems VMWare ESX CM Stacker STC-T01 
OtherOther
LSI 9280-16i4e RAID Card Intel Pro/1000 PT Quad-Port Gigabit NIC 
  hide details  
Reply
post #5 of 17
Thread Starter 
Quote:
Originally Posted by Manyak View Post

This might seem stupid, but are the RADIUS server and other devices configured with a static IP? And did you test all the relevant physical connections (the wires)?

Yes to all.
And devices are ping'able + it serves clients that are connected with WAP2 instead of 802.1x... so it works and cables do too smile.gif
And clients that are connected with AD are still fine, they won't connect back if they disconnect from that network.

Must think out of the box.
All 3 devices have 2 switches in common.

BackBone switch
Goes to 12 48port switches.
AP1 <- FloorSwitch -> AP2
~40 pc's + "bunker" switch +WiFi devices, totals avg. 70 devices going through this one
Switch in "Bunker" -> Edimax AP
~10 PC's +those devices on WiFi
Something like this. Enabled granular logging on that switch and waiting when something happens to see if maybe there is something wrong with it.
Actually double checked ports too, nothing is affecting them. No fancy DoS protection or overflow, nothing.
It's like these AP's receive some code from super-mega-hacker that deactivates them biggrin.gif
And it kills every cheap switch. Not in the "loop" way, but the way when connected devices can't contact anything and gets APIPA IP.
Edited by DiNet - 10/25/12 at 7:34am
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #6 of 17
I can't think of what would cause random dropouts like this other than maybe a faulty switch (or just a buggy one). I had a buggy Cisco AP once, which according to googling had a common issue where it just "didn't like" certain switches. Some things you could try:

- monitor the network (do a port mirror from the AP and server ports and monitor it) and see if there's anything specific that happens at the same time that it stops. Maybe a specific packet, or sudden high traffic, or something.

- reset the switch's settings and reconfigure it

- Use a different switch

And, of course, make sure your NPS server isn't losing connection to your DC.
Server
(10 items)
 
  
CPUMotherboardRAMHard Drive
Intel Xeon E3110 ASUS P5Q Premium 8GB G.Skill DDR2-800 2TB Caviar Green 
Hard DriveCoolingOSCase
1TB Caviar Black Prolimatech Megahalems VMWare ESX CM Stacker STC-T01 
OtherOther
LSI 9280-16i4e RAID Card Intel Pro/1000 PT Quad-Port Gigabit NIC 
  hide details  
Reply
Server
(10 items)
 
  
CPUMotherboardRAMHard Drive
Intel Xeon E3110 ASUS P5Q Premium 8GB G.Skill DDR2-800 2TB Caviar Green 
Hard DriveCoolingOSCase
1TB Caviar Black Prolimatech Megahalems VMWare ESX CM Stacker STC-T01 
OtherOther
LSI 9280-16i4e RAID Card Intel Pro/1000 PT Quad-Port Gigabit NIC 
  hide details  
Reply
post #7 of 17
Thread Starter 
Quote:
Originally Posted by Manyak View Post

I can't think of what would cause random dropouts like this other than maybe a faulty switch (or just a buggy one). I had a buggy Cisco AP once, which according to googling had a common issue where it just "didn't like" certain switches. Some things you could try:
- monitor the network (do a port mirror from the AP and server ports and monitor it) and see if there's anything specific that happens at the same time that it stops. Maybe a specific packet, or sudden high traffic, or something.
- reset the switch's settings and reconfigure it
- Use a different switch
And, of course, make sure your NPS server isn't losing connection to your DC.

Fun fact: When you try monitor something that doesn't work properly it fixes the problem for time you are monitoring.

Well, yea, monitoring edimax and it works like a charm... At least I found 1 "old" semi-admin PC that had nmap and generated lots of traffic smile.gif
Still monitoring it and waiting for it to drop out.
Also I have some weird traffic in wireshark. From one PC, that looks like some network monitoring software, but there is nothing on that computer. It is also trying to authenticate itself on AP with default credentials admin/1234.

Can you maybe help me to decipher wireshark capture log? I could upload them or maybe send you an e-mail?
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #8 of 17
Post here, I'd be interested to see.
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
    
CPUMotherboardGraphicsGraphics
Intel Core i7 860 Asus P7P55D-E Pro MSI GTX560 Ti TwinFrozr II SLI MSI GTX560 Ti TwinFrozr II SLI 
RAMHard DriveHard DriveHard Drive
Corsair 8GB DDR3 1600MHz CL9 XMS3 (2 x 4GB) OCZ Vertex 3 SSD Western Digital Caviar Black 1TB 7200RPM 64MB C... Western Digital Caviar Green 1TB ~5900RPM 64MB ... 
Optical DriveCoolingOSMonitor
Lite-On 24x DVD-RW CoolerMaster V8 Windows 7 Professional SP1 3 x Samsung S22B350H 
KeyboardPowerCaseMouse
Ducky Shine II Corsair HX850 CoolerMaster Storm Enforcer Logitech M500 
Mouse PadAudio
Razer Goliathus Microsoft LifeChat LX 3000 
  hide details  
Reply
post #9 of 17
Thread Starter 
log.zip 1055k .zip file

In 30.10-1.11 file there's 192.168.100.37 which had nmap and winpcap installed and running in background.
In 1.11-4.11 there's 192.168.100.89 that is laptop without any monitoring soft on it. Had it checked with mbam, rogue killer and Spybot + Nod32 is running 24/7, updated and with self protection + admin password.

In my tests I found that same traffic is generated from spiceworks without credentials.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
post #10 of 17
Thread Starter 
06.11.zip 823k .zip file

Same packets from x.x.x.89 followed by 6 ARP's and device dropped out and port on switch turned off mirroring.
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
MyCrap v1.2
(19 items)
 
  
CPUMotherboardGraphicsGraphics
i7 950 Rampage III Formula Evga 470 PNY 470 
RAMHard DriveCoolingOS
G.Skill 2x4GB DDR3 1600Mhz Ares Dual Channel C... Crucial m4 NH-D14 Win 7 Ultimate 
MonitorKeyboardPowerCase
LG Scarlet 42LH70YR LCD G15 TX950 HAF 932 
MouseAudioAudioAudio
G500 Marantz SR5006 B&W 804D Musical Fidelity M6i 
Other
KRK10S sub 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security