1. 程式人生 > >Receive a message from AAA of cutting user on華為設備

Receive a message from AAA of cutting user on華為設備

需求 pack ann 設備 receive 華為設備 down online scheme

Issue Description 問題描述
Customer configure radius service.After uplink connect to radius server is down,they found one issue.
There is a local user on device,When they login device using that user,they will be cut off by AAA and give below error:

Info: Receive a message from AAA of cutting user.

Alarm Information 報警信息

Info : Receive a message from AAA of cutting user.

Handling Process 處理過程
1、Check the configuration ,Customer use radius to provide authentication and accounting service.

aaa
authentication-scheme login
2、Analyze the service process,When user login device.first S5700 will try to send packet to radius server,If there is no reponse,S5700 will use local authentication ,But for accounting service,by default ,users cannot go online if accounting-start fails.That is why user is cut off by AAA module.Add below command and test it works fine.

accounting start-fail online

debugging aaa all
debugging radius all
debugging cm

僅做認證,無法下發權限,用戶認證通過後,登陸設備,以super password自助提前實現授權。
在新版本下,設備無super password配置,所以無法實現用戶需求的權限下發,非HW設備問題。

本地無法做計費,所以計費不用修改,但出現了異常提示認證失敗,若不配置計費屬性,用戶可以正常的認證上線。
此處本地無授權功能,但是設備仍會運行計費進程,發現本地無法提供該屬性。

Receive a message from AAA of cutting user on華為設備