NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Damon_C's avatar
Damon_C
Follower
May 09, 2016

Port Authentication w/RADIUS


Hi,
I've got a number of GS728TP managed switches which I am in the process of setting up Port Authentication. I've got a Windows Server 2012 R2 system running Network Policy Server, and one of the GS728TP switches as I'm using as a test switch.

I've got the computer side of things authenticating properly, however we've got Samsung SMT-i5230's that I cannot get to authenticate.

I've given the phone, a username and password (which works on a test laptop), however on the phone it doesn't work. I've got the following information from Samsung:

----------------------------------
The system supports VLan Tagging 802.1Q and 802.1P

The authentication protocol EAP-PEAP is supported by the SMT-i5243,authentication protocol EAP-MD5 is supported by all of the SMT type IP Phones,
The configuration for the 802.1x feature is in the 802.1x submenu in the network configuration menu of the IP Phone.

802.1p allows for a Class of Service 0-7 to be assigned

The switch port that the handset connects to also needs to support 802.1Q/p

----------------------------------

I've checked the manual for the switch, and have confirmed that it supports 802.1Q and 802.1p.. However I'm wondering if I've missed something in the switch itself. I've included part of the log file below:

----------------------------------
09 May 2016 13:15:01%SEC-W-SUPPLICANTUNAUTHORIZED: MAC f4:d9:fb:53:25:d6 was rejected on port g16 due to wrong user name or password in Radius server
09 May 2016 13:15:01%STP-W-PORTSTATUS: g16: STP status Forwarding
09 May 2016 13:14:56%LINK-I-Up: g16
-----------------------------------

I was using the same port to test my laptop, which was able to authenticate and I've got unauthorised clients setup to go onto a VLAN.

From what I have described, would there be a configuration that I am missing somewhere?

3 Replies

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Hi Damon_C,

     

    Welcome to the community! :) 

     

    Not sure if this will help.  Kindly access the article below if ever you have not yet came across with it:

     

    Dynamic VLAN assignment using RADIUS

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Hi Damon_C,

     

    Just want to follow-up if the article I provided has helped.

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

  • JohnRo's avatar
    JohnRo
    NETGEAR Employee Retired

    Hello Damon_C, 

     

    We’d greatly appreciate hearing your feedback letting us know if the information we provided has helped resolve your issue or if you need further assistance.
    If your issue is now resolved we encourage you to mark the appropriate reply as the “Accepted Solution” so others can be confident in benefiting from the solution. The Netgear community looks forward to hearing from you and being a helpful resource in the future!

     

    Thanks, 

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More