You have recently configured a switch for 802.IX authentication with HPE Aruba Networking ClearPass. A security admin is seeing events with the following description in ClearPass Event Viewer.
RADIUS authentication attempt from unknown NAD (10.10.1.10:1812)'
Which command should you us to identify the configuration issue?
The ClearPass Event Viewer message 'RADIUS authentication attempt from unknown NAD (10.10.1.10:1812)' indicates that ClearPass received a RADIUS request from the IP address 10.10.1.10, but this IP is not configured as a trusted Network Access Device (NAD) in ClearPass's network device list, or the shared secret doesn't match. The first step in troubleshooting on the switch side is to verify which source IP address the switch is actually using to send these RADIUS requests.
RADIUS Source IP: AOS-CX switches can be configured to use a specific source IP address for RADIUS packets, often using the ip source-interface radius [vrf <vrf-name>] command. This is important if the switch has multiple IP interfaces or uses VRFs.
Analysis of Commands:
A . show ip source-interface radius: This command directly displays the configured source interface and IP address used for RADIUS communications, allowing comparison with the IP configured in ClearPass.
B . show aaa authentication-server radius: Shows server group configuration, not the source IP used by the switch.
C . show radius-server shared-secret: Not a standard command; secrets are usually masked in other commands.
D . show radius-server detail: Shows configured RADIUS server details but doesn't explicitly show the source IP the switch is using to originate packets.
Conclusion: To identify why ClearPass sees requests from an 'unknown NAD' IP (10.10.1.10), the first step on the switch is to confirm which source IP it's using. show ip source-interface radius provides this crucial information.
Currently there are no comments in this discussion, be the first to comment!