Firmware Version : Build 5.01-B09
Hardware Version : 3A1
При попытке авторизовать MAC по 802.1x, коммутатор отправляет запросы RADIUS серверу с задержкой 2 секунды перед каждым запросом. Схема сети стандартная - клиент-свитч-radius.
192.168.2.3 - DES3526.
192.168.2.100 - RADIUS.
Код:
17:07:08.406152 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x5c length: 200
17:07:08.414947 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x5c length: 80
17:07:10.420404 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x5d length: 205
17:07:10.421295 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x5d length: 64
17:07:12.424695 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x5e length: 296
17:07:12.472588 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x5e length: 1090
17:07:14.443978 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x5f length: 205
17:07:14.444501 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x5f length: 1086
17:07:16.453267 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x60 length: 205
17:07:16.453741 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x60 length: 544
17:07:18.463553 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x61 length: 407
17:07:18.484223 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x61 length: 123
17:07:20.472844 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x62 length: 205
17:07:20.473409 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x62 length: 101
17:07:22.482130 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x63 length: 279
17:07:22.483113 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x63 length: 133
17:07:24.492419 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x64 length: 343
17:07:24.505253 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Challenge (11), id: 0x64 length: 149
17:07:26.491716 IP 192.168.2.3.8021 > 192.168.2.100.1812: RADIUS, Access Request (1), id: 0x65 length: 279
17:07:27.492172 IP 192.168.2.100.1812 > 192.168.2.3.8021: RADIUS, Access Reject (3), id: 0x65 length: 44
Как видно из дампа пакетов, каждый запрос от свитча приходит через 2 секунды после ответа RADIUS'а. 802.1x supplicant - xsupplicant @ linux и WinXP SP2.
При этом, например, на DWL-2100AP авторизация проходит мгновенно.
Вот конфиг DES-3526 по части 802.1x:
Код:
# 8021X
enable 802.1x
config 802.1x auth_mode mac_based
config 802.1x auth_protocol radius_eap
config radius add 1 192.168.2.100 key testing123 auth_port 1812 acct_port 1813
config 802.1x capability ports 1-2,4-26 none
config 802.1x capability ports 3 authenticator
config 802.1x auth_parameter ports 1-2,4-26 direction both port_control force_auth quiet_period 60 tx_period 30 supp_timeout 30 server_timeout 30 max_req 2 reauth_period 3600 enable_reauth disable
config 802.1x auth_parameter ports 3 direction both port_control auto quiet_period 5 tx_period 30 supp_timeout 30 server_timeout 30 max_req 2 reauth_period 60 enable_reauth disable