[c-nsp] WLC & FreeRADIUS WPA

matthew zeier mrz at velvet.org
Tue Nov 28 14:57:33 EST 2006


Has anyone gotten a WLC authing WPA off FreeRADIUS?  I can web-auth just 
fine, but WPA spews eap debug and eventually fails.

If it matters, FreeRADIUS is grabbing data from LDAP but I don't suspect 
that's the problem since I can web-auth just fine.

As an example of what doesn't work -

rlm_ldap: user mzeier at mozilla.com authorized to use remote access
rlm_ldap: ldap_release_conn: Release Id: 0
   modcall[authorize]: module "ldap" returns ok for request 7
modcall: group authorize returns updated for request 7
   rad_check_password:  Found Auth-Type EAP
auth: type "EAP"
   Processing the authenticate section of radiusd.conf
modcall: entering group authenticate for request 7
   rlm_eap: Request found, released from the list
   rlm_eap: EAP/peap
   rlm_eap: processing type peap
   rlm_eap_peap: Authenticate
   rlm_eap_tls: processing TLS
   eaptls_verify returned 7
   rlm_eap_tls: Done initial handshake
   eaptls_process returned 7
   rlm_eap_peap: EAPTLS_OK
   rlm_eap_peap: Session established.  Decoding tunneled attributes.
   rlm_eap_peap: Received EAP-TLV response.
   rlm_eap_peap: Tunneled data is valid.
   rlm_eap_peap:  Had sent TLV failure, rejecting.
  rlm_eap: Handler failed in EAP/peap
   rlm_eap: Failed in EAP select
   modcall[authenticate]: module "eap" returns invalid for request 7
modcall: group authenticate returns invalid for request 7
auth: Failed to validate the user.


More information about the cisco-nsp mailing list