1

802.1x и FreeRADIUS

Пытаюсь настроить 802.1x на коммутаторе. DGS-1250 10.100.100.5, радиус на Centos 10.100.100.11, доменная авторизация.

Ручной режим ввода пароля (bux/pass)? результат - win 10 не проходит авторизацию, лог первый. Ubuntu все отлично работает, лог второй. Просьба уважаемым специалистам исправить мою ошибку.

Лог 1.

(0) Received Access-Request Id 82 from 10.100.100.5:8021 to 10.100.100.11:1812 length 175

(0) Framed-MTU = 1466

(0) NAS-IP-Address = 10.100.100.5

(0) NAS-Identifier = "Switch"

(0) User-Name = "bux"

(0) NAS-Port = 6

(0) NAS-Port-Id = "port6"

(0) NAS-Port-Type = Ethernet

(0) Service-Type = Framed-User

(0) Connect-Info = "CONNECT Ethernet 1000Mbps Full duplex"

(0) Calling-Station-Id = "C4-65-16-39-38-73"

(0) Called-Station-Id = "64-29-43-C4-77-F6"

(0) EAP-Message = 0x0201000801627578

(0) Message-Authenticator = 0xf65a3213f188306aced8312dbb07e39f

(0) # Executing section authorize from file /etc/raddb/sites-enabled/my_server

(0) authorize {

(0) [preprocess] = ok

(0) [mschap] = noop

(0) suffix: Checking for suffix after "@"

(0) suffix: No '@' in User-Name = "bux", looking up realm NULL

(0) suffix: No such realm "NULL"

(0) [suffix] = noop

(0) eap: Peer sent EAP Response (code 2) ID 1 length 8

(0) eap: EAP-Identity reply, returning 'ok' so we can short-circuit the rest of authorize

(0) [eap] = ok

(0) files: users: Matched entry DEFAULT at line 1

(0) [files] = ok

(0) } # authorize = ok

(0) Found Auth-Type = eap

(0) # Executing group from file /etc/raddb/sites-enabled/my_server

(0) authenticate {

(0) eap: Peer sent packet with method EAP Identity (1)

(0) eap: Using default_eap_type = PEAP

(0) eap: Calling submodule eap_peap to process data

(0) eap_peap: (TLS) PEAP -Initiating new session

(0) eap: Sending EAP Request (code 1) ID 2 length 6

(0) eap: EAP session adding &reply:State = 0x7b0916937b0b0fba

(0) [eap] = handled

(0) } # authenticate = handled

(0) Using Post-Auth-Type Challenge

(0) Post-Auth-Type sub-section not found. Ignoring.

(0) # Executing group from file /etc/raddb/sites-enabled/my_server

(0) session-state: Saving cached attributes

(0) Framed-MTU = 994

(0) Sent Access-Challenge Id 82 from 10.100.100.11:1812 to 10.100.100.5:8021 length 64

(0) EAP-Message = 0x010200061920

(0) Message-Authenticator = 0x00000000000000000000000000000000

(0) State = 0x7b0916937b0b0fba111614281557a256

(0) Finished request

Waking up in 4.9 seconds.

(0) Cleaning up request packet ID 82 with timestamp +26 due to cleanup_delay was reached

Ready to process requests

лог 2 следующем сообщении