Hi, we have some new IoT devices that claim to support 802.1x. And unfortunately these appear to be a cheap chipset that supports 802.11g only and have an extremely limited interface to configure them. We have configured them to access our 802.1x network using EAP-PEAP (Clearpass is our authentication server) and they look to authenticate fine with the Clearpass logs confirming this. From here though they never connect and looking at the tracebuf log it appears that after authenticating they fail the 4 way handshake and either start authentication again or look to be stuck in a loop
The network is in use by multiple other devices with no problems so it looks like it is a client issue
I have included a portion of the log below. Any ideas on what the issue could be?
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 128 59
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 128 59
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 79 314 10.x.x.51
Dec 1 15:04:49 rad-accept <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 79 259
Dec 1 15:04:49 eap-success <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 128 4
Dec 1 15:04:49 eap-start -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 - -
Dec 1 15:04:49 wpa2-key1 <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 - 117
Dec 1 15:04:49 eap-id-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 129 5
Dec 1 15:04:49 eap-id-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 129 17 test_ct_wifi
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 153 230 10.x.x.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 153 88
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 130 6
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 130 64
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 86 319 10.x.x.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 86 1124
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 131 1034
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 131 6
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 38 261 10.x.x.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 38 1120
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 132 1030
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 132 6
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 141 261 10.x.x.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 141 1120
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 133 1030
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 133 6
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 92 261 10.x.x.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 92 1120
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 134 1030
Dec 1 15:04:49 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 134 6
Dec 1 15:04:49 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 115 261 10.60.47.51
Dec 1 15:04:49 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 115 346
Dec 1 15:04:49 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 135 262
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 135 348
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 41 605 10.x.x.51
Dec 1 15:04:50 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 41 167
Dec 1 15:04:50 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 136 85
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 136 6
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 212 261 10.x.x.51
Dec 1 15:04:50 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 212 141
Dec 1 15:04:50 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 137 59
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 137 75
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 142 330 10.x.x.51
Dec 1 15:04:50 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 142 173
Dec 1 15:04:50 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 138 91
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 138 123
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 250 378 10.x.x.51
Dec 1 15:04:50 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 250 189
Dec 1 15:04:50 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 139 107
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 139 59
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 69 314 10.x.x.51
Dec 1 15:04:50 rad-resp <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 69 141
Dec 1 15:04:50 eap-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 140 59
Dec 1 15:04:50 eap-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 140 59
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 254 314 10.x.x.51
Dec 1 15:04:50 user repkey change * 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 65535 - 001a1e04891000000687aa94
Dec 1 15:04:50 macuser repkey change * 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 65535 - 20:f8:5e:35:8c:30
Dec 1 15:04:50 rad-accept <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84/CLEARPASS_VIP_RADIUS 254 259
Dec 1 15:04:50 eap-success <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 140 4
Dec 1 15:04:50 wpa2-key1 <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 - 117
Dec 1 15:04:50 eap-start -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 - -
Dec 1 15:04:50 eap-id-req <- 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 141 5
Dec 1 15:04:50 eap-id-resp -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 141 17 test_ct_wifi
Dec 1 15:04:50 rad-req -> 20:f8:5e:35:8c:30 18:64:72:5d:6d:84 215 230 10.x.x.51
------------------------------
Stewart Smith
------------------------------