Version 6 SuperStack 3 Switch 4400 Management Interface Reference Guide

Table Of Contents
Support - Problem Solving - RADIUS Problems
http://support.3com.com/infodeli/tools/switches/4400/DHA1720-3AAA08/htm/support/problemsolving/radiusproblems.htm[11/15/2010 3:44:14 PM]
RADIUS is enabled on the stack and the Web interface does not
load completely.
When RADIUS is enabled on a stack of units, if each unit has a
different IP address you must configure your RADIUS server to allow
access from each individual IP address. Otherwise the Web interface will
fail to load completely when you log in.
Example
You have a stack of 3 units. Unit 1's IP address is 10.1.120.1, unit 2's
IP address is 10.1.120.2 and unit 3's IP address is 10.1.120.3.
If you log into the Web interface using unit 2's IP address
(http://10.1.120.2/), you must also configure the IP addresses of the
other two units on your RADIUS server.
This is because each unit in the stack attempts to authenticate to the
RADIUS server using its own IP address as part of the process of
loading the Web interface.
Network Login authentication is never completed.
If you configure the RADIUS Retries settings via the Security > RADIUS
> Retries Web interface operation or security radius retries CLI
command, you must ensure that the timeout value multiplied by the
maximum attempts value does not exceed 30 seconds for Network
Login. For example, a timeout value of 5 seconds coupled with a
maximum attempts value of 7 would result in a total timeout of 35
seconds. A value less than 30 seconds must be used, but 25 seconds or
less is recommended.
If the timeout value exceeds 30 seconds, Network Login authentication
will never be completed, and you will not receive a positive or negative
confirmation of the authentication attempt.
There is no limit on the timeout value that you can use for Switch
Login. You could configure the timeout value of 10 seconds multiplied
by the maximum attempts value of 10 if you wished.
The message "Incorrect password" is displayed, even though the
password entered is correct.
The message "Incorrect password" may be displayed when an incorrect
password is not the cause of an authentication failure. For example,
during a check-list item failure, "Incorrect password" will be displayed
even though this is not the cause of the authentication failure.
The shared secret is not being recognised by the Switch or
RADIUS server.
You must configure the same shared secret value on both the RADIUS
server and the Switch. The minimum supported length on the Switch
for the RADIUS shared secret is 8 characters. The maximum supported
length on the Switch for the RADIUS shared secret is 128 characters.
The maximum supported length for the RADIUS shared secret is
different for each RADIUS server; refer to the documentation that
accompanies your RADIUS server for further information.
The maximum supported length on the Switch for the RADIUS
username and password is 64 characters each.
The Session History table displays two different login times for
the same username.