Hello Expert Community,
lately a CVE out for Radius and I try to follow microsoft solution (below)
Mircosoft Solution
but when apply the solution exactly in this step
Configure verification of the Message-Authenticator attribute in all Access-Request packets on the client
my switch cannot handle packet and I can’t log using my Ad account (when I remove the option I can log and manage switch correctly)
here is the debug from Switch CLI (from my home LAB)
Aug 18 10:25:49.935: RADIUS/ENCODE(00000014):Orig. component type = EXEC
Aug 18 10:25:49.935: RADIUS: AAA Unsupported Attr: interface [174] 5
Aug 18 10:25:49.939: RADIUS: 74 74 79 [tty]
Aug 18 10:25:49.939: RADIUS/ENCODE(00000014): dropping service type, "radius-server attribute 6 on-for-login-auth" is off
Aug 18 10:25:49.939: RADIUS(00000014): Config NAS IP: 192.168.174.132
Aug 18 10:25:49.943: RADIUS/ENCODE(00000014): acct_session_id: 20
Aug 18 10:25:49.943: RADIUS(00000014): sending
Aug 18 10:25:49.947: RADIUS(00000014): Send Access-Request to 192.168.174.130:1645 id 1645/28, len 96
QUBC1SW01#
Aug 18 10:25:49.951: RADIUS: authenticator 02 2F 01 A0 42 56 CB 4F - A7 2C B3 2A E7 41 4F C8
Aug 18 10:25:49.951: RADIUS: User-Name [1] 18 "[email protected]"
Aug 18 10:25:49.951: RADIUS: User-Password [2] 18 *
Aug 18 10:25:49.951: RADIUS: NAS-Port [5] 6 98
Aug 18 10:25:49.955: RADIUS: NAS-Port-Id [87] 7 "tty98"
Aug 18 10:25:49.955: RADIUS: NAS-Port-Type [61] 6 Virtual [5]
Aug 18 10:25:49.955: RADIUS: Calling-Station-Id [31] 15 "192.168.174.1"
Aug 18 10:25:49.959: RADIUS: NAS-IP-Address [4] 6 192.168.174.132
QUBC1SW01#
Aug 18 10:25:54.795: RADIUS: Retransmit to (192.168.174.130:1645,1646) for id 1645/28
QUBC1SW01#
Aug 18 10:25:59.131: %RADIUS-4-RADIUS_DEAD: RADIUS server 192.168.174.130:1645,1646 is not responding.
Aug 18 10:25:59.135: %RADIUS-4-RADIUS_ALIVE: RADIUS server 192.168.174.130:1645,1646 is being marked alive.
QUBC1SW01#
Aug 18 10:25:59.139: RADIUS: Retransmit to (192.168.174.130:1645,1646) for id 1645/28
QUBC1SW01#
Aug 18 10:26:03.619: RADIUS: Retransmit to (192.168.174.130:1645,1646) for id 1645/28
QUBC1SW01#
Aug 18 10:26:07.987: RADIUS: Fail-over to (192.168.174.130:1812,1813) for id 1645/28
QUBC1SW01#
Aug 18 10:26:12.431: RADIUS: Retransmit to (192.168.174.130:1812,1813) for id 1645/28
QUBC1SW01#
Aug 18 10:26:17.963: RADIUS: Retransmit to (192.168.174.130:1812,1813) for id 1645/28
QUBC1SW01#
Aug 18 10:26:22.567: RADIUS: Retransmit to (192.168.174.130:1812,1813) for id 1645/28
QUBC1SW01#
Aug 18 10:26:27.143: RADIUS: No response from (192.168.174.130:1812,1813) for id 1645/28
Aug 18 10:26:27.147: RADIUS/DECODE: No response from radius-server; parse response; FAIL
Aug 18 10:26:27.147: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response; FAIL
QUBC1SW01#
Aug 18 10:26:29.223: AAA/AUTHEN/LOGIN (00000014): Pick method list 'default'
Aug 18 10:26:29.231: RADIUS/ENCODE(00000014): ask "Password: "
Aug 18 10:26:29.231: RADIUS/ENCODE(00000014): send packet; GET_PASSWORD
QUBC1SW01#