Hello
I have a network with 1 RADIUS server and 1 DHCP server not the same IP.
Some of my SSIDs have RADIUS Authentication, and others are WPA2 Personal authentication.
The ones with RADIUS authentication can't get an IP address in the selected VLAN.
The other SSIDs can get an IP on the right subnet.
Any ideias how I can make this work?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If the SSID is configured with Enterprise Security mode it will use dot1x/eap. This is a Layer 2 protocol and in case of RADIUS reject it will not allow any network connectivity in IP level so the end host will not be able to receive an IP address from DHCP.
You have to check the logs in the RADIUS server and find the reason of this rejection as a first step.
After that if you are using dynamic VLAN assignment from RADIUS attributes you have to make sure that the VLAN is created under SSID configuration.
Sorry for taking so long to awnser, the RADIUS server logs are completely fine, it shows the request and is authenticated as it should be, no problems there. The DHCP server never recieves any request. I used wireshark to help with the troubleshooting but no awnsers still.
The RADIUS and DHCP relay servers are correct. I have no idea what could be happening.
I saw a post similar to mine and the solution was enabling DTLS, but there aren't any VPN.
Are you using "Dynamic VLAN assignment" in SSID configuration or you have configured the IP and DHCP relay directly to the SSID?
To isolate the problem you can check if the WiFi host is getting permitted in the network and have the appropriate VLAN assigned:
# diagnose wireless-controller wlac -c sta
or set the IP manually on that host (corresponding to the configured network) to check if there is network connectivity and only the DHCP is failing.
If everything is configured correctly, I've seen a similar case that after restarting the WLC daemon the DHCP starts working you may give it a try: # execute wireless-controller restart-acd
I'm gonna try that, once I do i would let you know.
Thanks for your help!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1030 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.