跟现场确认,现场认证的账号是从通用LDAP服务器同步过来的,配置的是PEAP-GTC认证。让现场反馈认证时的UAM调试日志和抓包;首先分析UAM调试日志如下:
%% 2017-12-05 16:04:30.091 ; [LDBG] ; [11196] ; LAN ; 2017011@****.cn ; 1 ; 1593b1277566447c9b5a93c04581609c ; Received message from 10.252.11.84:
CODE = 1.///认证请求报文
ID = 168.
ATTRIBUTES:
User-Name(1) = "2017011@****.cn".
Service-Type(6) = 2.
Framed-Protocol(7) = 1.
NAS-Identifier(32) = "AC".
NAS-Port(5) = 33.
NAS-Port-Type(61) = 19.
NAS-Port-Id(87) = "VLANID=33;".
Calling-Station-Id(31) = "80-19-34-27-F8-1C".
Called-Station-Id(30) = "AC-74-09-67-**-**:eduroam".
Acct-Session-Id(44) = "00000004201712051603160000009016100482".
HW_NEW_USER_ATTRIBUTE_NAME(133) = "".
EAP-Message(79) = "02020019013230313730313140666a74636d2e6564752e636e".///01表示上传用户名
服务器随后根据服务器侧配置的接入策略名查询,发现该用户需要进行PEAP认证,并回应终端认证challenge。
%% 2017-12-05 16:04:30.092 ; [LDB