Community discussions

MikroTik App
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

User-Manager Radius Timeout problem

Sun Jan 30, 2011 6:09 pm

Hi all,

I have a setup that was on another router, the router is not 100% and needed replacing. I have since replaced it with another router, and taken the exact same setup to the new router.

I now have a problem with radius authentication, all local radius requests from the router with userman installed get radius timeout response both on hotspot and pppoe connections, but other mikrotik devices are able to authenticate on the exact same router.

I have had this problem once before, where the mikrotik rb600 with v3.30 installed, would not authenticate requests from itself, was able to correct by redoing the setup several times, but it's not working now.

I have attached an export
You do not have the required permissions to view the files attached to this post.
Last edited by winagain on Sun Jan 30, 2011 8:04 pm, edited 3 times in total.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: User-Manager Radius Timeout problem

Sun Jan 30, 2011 6:27 pm

Instead of using your ether1 address for internal authentication, use 127.0.0.1. Also set up 127.0.0.1 as a NAS within User Manager.
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

Re: User-Manager Radius Timeout problem

Sun Jan 30, 2011 6:49 pm

I have tried this with no success. Still does the same thing!
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

Re: User-Manager Radius Timeout problem

Sun Jan 30, 2011 9:13 pm

I have the old router setup so I can match the settings, both, are setup exactly the same, yet new RB600 has radius timeout.

I can get it to work for pppoe, by removing hotspot, and ip addresses associated to the hotspot interfaces, then radius responds again.

What can cause this.
 
SurferTim
Forum Guru
Forum Guru
Posts: 4636
Joined: Mon Jan 07, 2008 10:31 pm
Location: Miramar Beach, Florida

Re: User-Manager Radius Timeout problem

Sun Jan 30, 2011 11:52 pm

Do you have radius logging enabled?
/system logging
add topics=radius action=memory
You are certain the secret is correct?
In User Manager, the Router section for 127.0.0.1 is entered correctly?
http://wiki.mikrotik.com/wiki/User_Mana ... ame_router
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

Re: User-Manager Radius Timeout problem

Mon Jan 31, 2011 12:05 am

Yes, and have found the reason for it not working.

It came down to a firewall rule:

/ip/firewall/nat/

1 chain=srcnat action=masquerade

I removed the above rule and added one with src-address, and it worked, but for every network I have to add a separate rule, never had to do this before.

Discovered this by setting up each section bit by bit and checked when the failure occurs, and as soon as I included the masquerade rule without src-address, failure!

Well it's at least working now :-)
 
SurferTim
Forum Guru
Forum Guru
Posts: 4636
Joined: Mon Jan 07, 2008 10:31 pm
Location: Miramar Beach, Florida

Re: User-Manager Radius Timeout problem

Mon Jan 31, 2011 12:08 am

I use a masquerade like this:
/ip firewall nat
add chain=srcnat action=masquerade out-interface=ether1
This should masquerade only when needed (out the wan interface). If ether1 is not the wan, change that.
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

Re: User-Manager Radius Timeout problem

Mon Jan 31, 2011 12:50 am

will try that, busy with tests at the moment as no one is active on my network at this time of the morning 1am.
 
User avatar
winagain
Member Candidate
Member Candidate
Topic Author
Posts: 254
Joined: Sat Jul 15, 2006 10:18 pm
Location: Botswana
Contact:

Re: User-Manager Radius Timeout problem

Mon Jan 31, 2011 12:58 am

It works to access the internet, but when I connect to wireless I can then not access the other routers on the network, only the main one.

Whereas with individual routes I can access them, and with the the old way src-nat masquerade rule, when it was working like on the older routerboard, I can access all routers on the network.

Thanks.

Who is online

Users browsing this forum: No registered users and 13 guests