Dell Powerconnect 35xx series features Radius Server behaviorfin

Hello Dell Community,

I'm not able to find out how 35xx series switches handle 'server radius deadtime' parameter as described below:

In the config of switch, I use two hosts(for redundancy) radius. The first has priority of '1' configured RADIUS, the second server is priority '2 '. So normally, if the first sever(priority 1) RADIUS online, auth requests switch are sent to this server all the time. And they really are.

Now, I have also configured the 'deadtimet 10 radius server', meaning to jump on the radius server does not respond. Does that mean exactly?

If the radius with priority 1 server is offline for a few seconds, the switch instantly consider this as dead radius server and sent no auth request it for the "period deadtime ' 10 minutes (depending on configuration)? How often switch check for the availability of the radius server host?

config swtich:

IP address Port port Prio time - Ret-dead-source IP. Its use
AUTH Acct Out rans times
--------------- ----- ----- ------ ------ ------ --------------- ----- -----
10.10.10.10 1812 1813 global Global Global Global 1 all the
10.10.10.20 1812 1813 global Global Global Global every 2

Global values
--------------

Waiting period: 2
Broadcast: 5
Deadtime: 10
Source IP: 0.0.0.0
Source IPv6:

Retransmission will say the switch many times in an attempt to authenticate to the RADIUS server before moving on to the second server. Timeout is indicative of the switch, the waiting time for a response. Deadtime will subsequently intervene in these two parameters have been exhausted.

Example config:

Server radius coverage of console (config) # 3

Console (config) # timeout 3 radius server

Deadtimet console (config) # 10 radius server

Result of config:

-The client tries to connect.

-switch attempts to authenticate the server 1.

-Switch means no RADIUS server 1 for 3 second.

-Switch waits 3 seconds.

-Switch attempts to authenticate to the RADIUS server 1 for the second time and does not return to server for 3 seconds.

-Switch waits 3 seconds.

-Switch attempts to authenticate to the RADIUS server 1 for the third time and does not return to server for 3 seconds.

-switch place RADIUS server, one in a State of low/dead for 10 minutes.

-switch attempts to authenticate to Server 2.

Tags: Dell Tech

Similar Questions

  • Dell PowerConnect 7048 P reference stack Questions

    Hello

    I have two switches in L3 7048P I want the battery but I'm not sure how it works. The two switches have the same firmware.

    1 must. the two have the same configuration running on both to make it work?

    2. in addition, I created a VLAN (3) voice on the first switch with an IP address of 10.0.3.254. I use the same IP address on the second switch in the VLAN 3 addresses or assign another?

    Thank you!

    There is a guide especially for stacking switch 7048 on the Dell page networking white papers:

    en.Community.Dell.com/.../2580.Networking-guides.aspx

    Just search "Dell PowerConnect 7000 Series Switches stacking".  Page 16 will tell you how to add a new Member to the battery with minimum interruptions. Both can present the same firmware in order to stack.  So the answer to question 1 is no, the configurations do not need correspond to stack them.  Once stacked, both will look like a single switch, and you use only the IP address of the master swtich to the whole stack.  Therefore, treat the two switches as a single switch during Setup.  The guide provides more information on how it works.

    Hope this has been helpful.

    -Victor

  • PowerConnect 6200 series interoperability with 3Com Switch 5500.

    Hi all

    We offer to our customer Dell PowerConnect 6224 and 6248 as they are expanding their network.

    Their existing network is 3Com Switch 5500 and the main switch is 5500G - EI. Of course, on their network, they have mutiple VLAN and switch 5500G - EI core will make the VIRTUAL LAN routing.

    I would like to know, is it questions about interoperability between 3Com Switch 5500 and Dell PowerConnect 6200 Series, especially on the VLAN routing?

    Know your opinion.

    Thank you and best regards,

    Syed.

    I'm not aware of any questions that you would see with the use of these switches together. On switches 62xx you set them VLAN, and then set the connection of 3Com in general or Trunk mode, allowing the VLANS on the connection.

    Create a VLAN

    Console (config) # vlan database

    VLAN console(config-VLAN) # 2

    VLAN console(config-VLAN) # 3

    VLAN console(config-VLAN) # 4

    output console(config-VLAN) #.

    Configure the interface in Trunk mode and allow for VLAN through it.

    console switchport mode trunk #.

    console # permit trunk switchport vlan add 2,3,4 tag

    You may need to set a static route on the 62xx switch so the traffic on the next hop.

    Console (config) # ip route 172.16.0.0 255.255.0.0 10.0.0.2

    Here are a few good white papers to look over. Not all of them concern the 62xx switch, but the information is always good.

    www.Dell.com/.../app_note_38.pdf

    www.Dell.com/.../app_note_2.pdf

    www.Dell.com/.../pwcnt_link_aggregation.pdf

    www.Dell.com/.../pwcnt_VLAN_interoperability.pdf

    www.Dell.com/.../app_note_4.pdf

    Thank you.

  • DHCP server press PowerConnect 28xx series / address pool by VLAN

    Hello

    I am reading the manual of the PowerConnect 2824.

    I am considering buying this switch, but I have a question related to the functionality of the DHCP server.

    Here my question: I want to have different VLAN and use the feature of DHCP server on each of them. Then can I have different address DHCP pools by VLAN?

    Example:

    1-16 ports VLAN1: IP subnet 192.168.1.0/24

    VLAN 2 ports 17-24: IP subnet 192.168.2.0/24

    The manual is not clear on this.

    Your help is welcome.

    Kind regards

    Tom

    Daniel,

    Thanks for the reply. Another question does this mean that the 28xx series switch DHCP server, recover the IP address (from the range configured) on all the VLANS configured? So if a device on VLAN 2 issued a request DHCP, it will get an IP address from the same pool as for example a device on VLAN 1.

    Kind regards

    Tom

  • Reference Dell PowerConnect 2848 OID for CPU time and memory

    Hi all

    This is my first post in this forum. I searched all the messages that can solve my problems, but I could not find so if there is already an existing post and I couldn't find it please guide me to it.

    My case is. We have a few Dell PowerConnect 28xx switches in our network. We want to monitor things like the CPU, the temperature, the use of the RAM usage. We use Solarwinds IpMonitor monitoring tool. I downloaded the MIB, I could find the download of Firmware from Dell drivers and downloads page. I went through the entire MIB, but I couldn't find an OID for the foregoing.

    So if anyone can help me please what OID is used for usage of CPU and RAM temperature it will really help me.

    Please let us know in case we need more information on my side.

    Thank you

    Frank Moreau

    I did use SNMP on the 28xx but here are some various sensor OID, I used for the N-series, as well as some older models Powerconnect.  I don't know if they will work for the 2xxx, but you can try one or two and see if they work.

    N - Series (FW 6.2 and later versions) temperature OID
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.8.1.5.1.0
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.8.1.5.1.1

    62xx (3.0.x.x firmware or later-, some may also work with 2.x firmware)
    Temperature OID
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.8.1.2
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.8.1.3
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.8.1.4

    Are the OID to use CPU for N-Series switches
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.1 (total free memory)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.2 (total memory)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.3 (table for the following...)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.3.1.1 (index)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.3.1.2 (name of the process using CPU)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.3.1.2 (% CPU used by the corresponding process)
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.4.0 (cumulation of all the activity of the CPU)
    1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.9 (CPU utilization shows 5 s, 60 s and 300s).

    OIDs memory
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.1
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.1.1.4.2
    Power supply OID
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.7.1.2
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.7.1.3
    OIDs of fan
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.6.1.2
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.6.1.3
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.6.1.4
    . 1.3.6.1.4.1.674.10895.5000.2.6132.1.1.43.1.6.1.5

    35xx (2.0.x.x or later firmware)
    Temperature OID
    . 1.3.6.1.4.1.89.53.15.1.9
    . 1.3.6.1.4.1.89.53.15.1.10
    OIDs of CPU
    . 1.3.6.1.4.1.89.1.6
    . 1.3.6.1.4.1.89.1.7
    . 1.3.6.1.4.1.89.1.8
    . 1.3.6.1.4.1.89.1.9
    OIDs memory
    . 1.3.6.1.4.1.89.29.11.1
    . 1.3.6.1.4.1.89.29.11.2
    P.S. The OID
    . 1.3.6.1.4.1.89.35.5.1.1.2
    . 1.3.6.1.4.1.89.83.1.2.1.2
    . 1.3.6.1.4.1.89.83.1.2.1.3
    . 1.3.6.1.4.1.89.83.1.2.1.4
    . 1.3.6.1.4.1.89.53.15.1.3
    . 1.3.6.1.4.1.89.53.15.1.3
    OIDs of fan
    . 1.3.6.1.4.1.89.83.1.1.1.2
    . 1.3.6.1.4.1.89.83.1.1.1.3
    . 1.3.6.1.4.1.89.53.15.1.4
    . 1.3.6.1.4.1.89.53.15.1.5
    . 1.3.6.1.4.1.89.53.15.1.6
    . 1.3.6.1.4.1.89.53.15.1.7
    . 1.3.6.1.4.1.89.53.15.1.8

    for old firmware - if the 35xx above does not work:
    Temperature
    1.3.6.1.4.1.674.10895.5000.2.89.53.15.1.9 (Celsius)
    1.3.6.1.4.1.674.10895.5000.2.89.53.15.1.10

    I hope this helps.

    B

  • Problem with routing/circuits between SG300-10 and Dell Powerconnect 5224

    Hello

    I just bought a SG300-10 switch and loaded new firmware 1.27 on it.  Configure my VLAN and trunks, but I have a weird problem that I can't seem to understand.  It may be something small, I'm missing, but no matter, I have been scratching at it all day and I kicked in the butt.  If anyone can point me in the right direction or maybe something that someone see in my config which is wrong, I can get the terminology/theory wrong, after all, I just spent my CCNA :)

    My configuration:

    I have the SG300-10 as my switch and changed over to L3, so it may be my core of my small network.  On port 1, vlan 200 is configured as my unidentified native PVID and I put it to 210(LAN network) to trunk VLANs, 220 (management vlan) on the tag to the Dell powerconnect 5224 24port switch.  On port 1 of the Dell switch, I install as a trunk it as well with the same configuration (vlan native of PVID unidentified 200, 210 and 220 tag trunking).

    I have installed virtual interfaces on the SG300 for each VLAN (vlan 210 = 192.168.210.1/24, vlan 220 = 192.168.220.1/24) and on the Dell, since this is a feature of L2, I changed the vlan 1 to 220 management and assign the IP 192.168.220.2/24.

    Now, since the SG300 web interface, I ping IP management Dell (192.168.220.2/24)successfully and vice versa, can ping from Dell web interface to one of the IP of the bridge VLAN (210.1 & 220.1) successfully so that test, to me, looks like the Dell communicates with the SG300.)  I also have the default gateway of the Dell 192.168.220.1 printer value.

    Server IP: 192.168.220.10/24

    Workstation IP: 192.168.210.80/24

    Now the dilemma:

    I have a server plugged into switch port Dell 2 (configured as 'hybrid' because there is no option to access, value 220 PVID, vlan, worth 220 Untagged) and from the server, I can ping IP management dell very well switch and can ping the IP of the gateway of great SG300 so.  On the SG300 switch, on port 2, I plugged in a workstation (configuration is in access mode, vlan 210 unidentified) who can not ping the server plugged into the dell switch.  The workstation, I can ping all the SG300 interfaces and also the IP management dell but I can't ping the server.

    Any ideas anyone can provide is much appreciated!

    Edition of VLAN.

    Lenell, thank you for the call tonight. It seems that we have found the problem. The SIN, although it is configured with a default gateway, the gateway that brings 0.0.0.0. We also checked the NAS works from the same subnet to connect but fails outside of the subnet. Conversely, we checked 2 computers have no problem to connect through the VLAN level 3.

    I hope we got the right direction.

    -Tom
    Please evaluate the useful messages

  • Difference between Dell Powerconnect N4032F and 8132F

    Hello!

    In the last days, the Dell PowerConnect 8100 disappeared from the Dell Web site and now, the M4000 series with the same characteristics are presented.

    It's just a change of name or these devices differ in some way? The M4000 firmwares is usable on 8100 switches in the future?

    Thank you

    Kind regards

    Stril

    Dell PowerConnect N4000 switches series both Dell Networking PC8100 series share the same version of the firmware of the image (for example, N4000v6.1.0.1.stk). The Dell Networking N4000 series switches can be stacked with switches Dell Networking PC8100 of the series with any battery necessary for the performance of 6.0.0.8 or later firmware (6.1.0.1). Dell Networking PC8100 switches can support the firmware both 5.x and 6.x versions, but Dell Networking N4000 can support only the 6.0.0.8 and later versions of firmware (6.1.0.1)

    I hope this helps.

    B

  • Reference Dell PowerConnect 6024F get mac by ip with arp and more option

    Hello in the DELL community.

    I hava a little question, and hoping to find some answers here ;) I'm writing a small script, and in this script, I need to get the mac address is to link to Ip address of the ARP command. I am using telnet to connect to DELL. But the show arp command displays a lot of information, a huge list of ip. I tried to analyze, with the '' option and press etc., but it's a very slow procedure.

    Two main issues:

    1. how to get the mac address and link it to the IP by ARP command

    2 how to get rid of the option ''. I mean show cli without

    I thank the of to get answers.

    P. S.

    ===========================

    Switch: Dell PowerConnect 6024F

    # See the worm
    SW version 2.0.0.19 (date may 5, 2008 time 16:33:30)
    Start the version 1.0.0.13 (August 13, 2003 time 15:28:31)
    HW version 00.01.64
    #

    Show arp? -> watch only

    Show arp

    Terminal Server? -> watch only

    Terminal Server
    history

    He might have an OID you can pole for this info. all the OIDS are in the MIB that are included in the download for the firmware.

    www.dell.com/.../DriversDetails

    If you do not find one in the MIB, you might try a SNMP walk on the switch to see if you can identify an OID that will provide you with this info.

  • Dell PowerConnect switches are prone to vulnerability of GNU Bash ShellShock?

    Hello

    I would like to know if the Dell PowerConnect switches are prone to vulnerability of GNU Bash ShellShock.

    CVE-2014-6271

    Best regards

    Marie Therese TR

    She will be registered there by the model number.

    PC8024/PC8024F, PC7000, PC8100, PC6200 series.

  • reset the password on a Dell PowerConnect M6220

    Hello, I'm trying to reset the password on a Dell PowerConnect M6220.  Can connect to the CMC via the https Web page, I don't see how to do it from there.

    Then I'll try to plug a USB serial cable into the console port and reset the password via a console session using teraterm but when I do that all I get is a white screen.

    Parameters of the series are:

    Cable: The Null Modem

    Bits per second: 115200

    Data bits: 8

    Parity: None

    Stop bits: 1

    Flow control: no

    Any ideas on how I can access telnet access to the device to reset the DDT successfully

    Thank you

    Kevin

    You can connect to the console port internal to the switch via the CLI of CMC

    Telnet to the CMC, then connect switch-a1 (a2 or b1 etc. etc.)

    This will give you the > invites, so either delet the startupconfig and recharge it, or put into you own username and password - remember that you can set on the schema of the interface of the band or band in slecting the appropriate interface

  • traffic on PowerConnect 28XX series

    Anyone know if there is any parameter to specify traffic on the Dell PowerConnect 2816 or 2824 manageable web?

    The 2800 is a low access of range switch.  It doesn't have the ability to limit traffic on a connection.  The CoS allows allows you to set priority on different traffic that's different levels.

    If that connection and traffic is not managed correctly you will need to look for a switch upgrade which has more than a full set of features that allows the specific traffic shaping.

  • Newbie question on access to the RADIUS server

    I've worked before on RADIUS servers running on Windows but not on Unix. I'm new to an environment without any documentation and I make sure I have access to the GANYMEDE/ACS config.

    I go to my config switch and I see that ' 10.0.0.1 radius-server.

    Then I ssh into ' 10.0.0.1' and I see the below after "method.

    From the bottom, you have an idea on how to access the configuration of the ACS in case I need to change any setting it? I tried http://10.0.0.1 but it does not work.

    -bash-3, $00 ls
    bin features core net sbin TT_DB
    Start the etc. opt system usr lib
    export of CDROM lost + found tftpboot var platform
    dev House Dem proc tmp flight-bash-3. $00 ls
    bin features core net sbin TT_DB
    Start the etc. opt system usr lib
    export of CDROM lost + found tftpboot var platform
    dev House Dem proc tmp flight

    Try http://10.0.0.1:2002 for ACS listening on port default 2002.

    Pete

  • switch 3750 EAPoL transmission RADIUS server

    I have a running version of the 3750 switch stack 12.2 (53) SE2 IPBASEK9-M. I have dot1x configured on the switch and a Windows 7 PC, connected with 802. 1 x configured on the interface. I see the EAPoL start message from the PC, but I do not see the packets from the switch to the RADIUS server RADIUS. I have a config simple dot1x just to try to make it work before adding additional features such as comments - vlan...

    Config and debug of attached file.

    I don't know if the configuration ip dhcp snooping and arp of inspection is cause a problem with that or not. I see the EAPoL packet received on the switch, as shown in the attachment of debugging, but I never see the RADIUS packet. I've defined both trust on the interface, but always the same result. I can't turn it off because there is a switch of production with a test interface.

    Any ideas?

    Thank you

    Mark

    I had the same problem and solved it is enough to configure the switch as authenticator instead of "supplicant". "Supplicant" means customer, "authenticator" means in fact the switch acts as an authenticator to pass through, it will forward the requests to the auth server, for example, host of RADIUS.

  • Primary/secondary RADIUS server

    Hey all,.

    I tried to find out for awhile how primary and secondary RADIUS servers work about WLC 4400 s. If the primary RADIUS server goes down, and the secondary image is used, when the controller will return to the primary once it is up? He waits until the secondary breaks down, or done immediately switch back to the primary when it becomes available?

    Thanks in advance!

    The f

    On versions 4.2 and earlier, if the principal fails, then the secondary image is used until the secondary level is not available. So if you want the main for the radius server to use purpose, restart the secondary image. Then the tertiary then back to the primary. 5.0 has a feature in which you can define a Dungeon alive so that when the primary comes back upward, the primary will be used again. 5.0 code not a version of good code, however.

  • RADIUS server for authentication

    Hello

    I want to configure the radius server, so whenever someone tries to connect to a cisco (Telnet) switch, I want the radius to authenicate them server. Is this possible?

    Yes it is possible as long as you configure your switches to authenticate to the Radius server. To achieve this, you must use a feature called AAA. This feature is compatible with the protocols such as Radius, GANYMEDE +, to name a few. The following link will give you an idea on how to set it up on switches IOS based specifically on the 3550:

    http://www.Cisco.com/en/us/partner/products/hw/switches/ps646/products_configuration_guide_chapter09186a00801a6b15.html

    Make sure that apply you the authentication list to the vty lines to ensure that telnet access is authenticated with the radius server. FOT based CatOS switches than the following link will be useful:

    http://www.Cisco.com/en/us/Partner/Tech/tk583/TK642/technologies_tech_note09186a0080094ea4.shtml

Maybe you are looking for

  • Can not install a hotspot with my Vista USB adapter

    Hello. I have a USB adapter with point characteristic access (hotspot), but he can never access the internet after a profile has been created. I can get a very good wireless networks, I can't set one up but it does not recognize some windows strange

  • How you can know if you want to compare materials is the problem between the processor and the memory when you have black screen!

    Hello If you have a black screen which can be if the processor is dead or memory is dead how you know if you do not reserve memory, the problem is the processor or memory? I tried this on my computer, I put on the CPU and I got black screen, I put in

  • Configuration of MRA with different domain name

    Hello We are ARM configuration with internal and external domain name different. internal domain is abc.local and external domain abc.com C exp, CUCM and IMP are in the area of the abc.local and Exp E found in domain abc.com. users using the [email p

  • error code 80070BC9 8 windows

    I am running windows 8 pro with media center and cannot install 3 updates due to the error code 80070BC9 what the updates are: KB2871690KB2802618KB2871777 One sometimes installs, but then when the Others2 fail it must be reinstalled. I tried a clean

  • VCOPS UI vs user interface Vsphere custom

    Hello score,This is my first question in the VMware communities, I hope I can get a clear answer to my question.As you know in VCenter Operations Manager is it customized user interface and the UI by default Vsphere, up to now, I can not know why the