RE: DHCP problem in .1x



Hi,
I checked switch config that is ok.But when i sniffed my network by
ethereal,ı saw something about RADIUS frame packet.When the authentication
attempt successfull and the RADIUS sent a packet of RADIUS ACCEPT for
authentication then the client takes IP address from DHCP.I saw on log
regarding request of DHCP.
But when the authentication attemp fails then IAS sent a packet of RADIUS
REJECT for authenticaton then the trigger of DHCP on the client doesn't
trigger the DHCP server.So the client doesn't take an IP.

I think my switch and IAS cannot negotiate with client that has an failed
authentication attempt.
What is the problem?
Why the client request an IP adress when the authentication fails?



"john" wrote:

I will check our switch config.

thank you.

"john" wrote:



"rt-seb" wrote:

Hello,

"john" wrote:

The switch puts the client ports to Unauth-vlan very quickly but the Xp
client doesn't take an IP afterwards the operation.

I was waiting 10 minutes for DHCP trigger.but the client doesn't gain an IP
address.
When ı trigger network connections manually,the client takes an IP.
I think the client doesn't receive EAP-success frames when the
authenticatioin fails.
Futhermore for the successfull authentication attemps ,the client takes an
IP address everytime.I haven't a problem on success authentication attempts..

How ı change DHCP services times on the client?

I don't think that changing the DHCP timing will help you.
The problem is that the DHCP service must know when to request a new
IP address. Usually, this is done if a physical link is detected.
But in your case the physical link is already there. You might take a look
at the configuration options of your switch.
Some switches are capable of sending EAP-Sucess messages after a VLAN
change. Some switches might emulate a link-down-up sequence in order to
signal the client the need for an IP renewal.

Sebastian



"rt-seb" wrote:

Hello,

"john" wrote:

hi,
I use IAS,HP 2650 and Windows xp sp2 for our .1x system.
I have a problem about re-authentication afterwards the computer
authentication.The machine authenticates successfully by the computer
certificate then it leases an IP from DHCP server.when the user logons on the
computer the re-authentication starts.The user doesn't have an user
certificates so it doesn't authenticate the system.I see an error on IAS log
that is related re-authentication.But we have a problem about DHCP lease on
the computer.I think the computer should leave an IP address on wrong scope
then it requests an IP from unauth-VLAN scop of the DHCP server.But the
computer doesn't leave the IP adress of wrong scope. Then I repair network
connection manually,the computer takes an IP adress of unauth-VLAN DHCP scope.

My problem that the computer doesn't take an IP adress of unauth-VLAn scope
when the authentication attempt fails.I want that the computer should take an
IP address automaticly when the aunthentication attempt fails.

Is the problem related windows xp supplicant of .1x,isn't it?

How long does it take until the computer is put into the "unauhth" VLAN?
Does the switch sends an EAP-Success to the clients after the clients
was put into the unauth-VLAN?
Usually, this EAP-Success frame makes the 1x supplicant trigger the
DHCP client service for an IP renewal. Maybe the DHCP services times
out (typically 60 seconds) because it took too much time to gain
network access.

Sebastian
.



Relevant Pages

  • Re: 802.1x howto ias computer only authentication
    ... Windows XP because no dhcp can be found. ... User authentication based on certificates works ok but thats not ... access permission by your remote access policy. ... the way the 802.1X switch works is to ...
    (microsoft.public.internet.radius)
  • Re: Windows Server 2003 DHCP server - Does not release IP Addresses
    ... on the SWITCH or the ROUTER. ... the clients will not know which server to go for DHCP REQUEST. ... And, if that Switch had some issues, how will the other DHCP server ... This error is usually received when the client booting up via PXE is ...
    (microsoft.public.windows.server.general)
  • Re: 802.1x authentication issue
    ... There was nothing wrong with the switch port, ... Yes, we are using IAS for PEAP authentication, I analyzed IAS logs but didn't ... I ended up switching the machine to a NON .1x port, disjoining the Domain, ... If the machine has an APIPA address it means it can't contact the DHCP ...
    (microsoft.public.windows.server.networking)
  • Re: 802.1x howto ias computer only authentication
    ... I have a Cisco 2960 switch and MS IAS Radius configured and the ... the authentication happen there - now the switch isn't changing the vlan it ... Windows XP because no dhcp can be found. ... access permission by your remote access policy. ...
    (microsoft.public.internet.radius)
  • RE: DHCP problem in .1x
    ... I will check our switch config. ... I was waiting 10 minutes for DHCP trigger.but the client doesn't gain an IP ... IP address everytime.I haven't a problem on success authentication attempts.. ...
    (microsoft.public.internet.radius)