Documente Academic
Documente Profesional
Documente Cultură
Troubleshooting
Release: 4.1 Document Revision: 01.01
www.nortel.com
NN47215-700
.
324605-A
Ethernet Routing Switch 2500 Series Release: 4.1 Publication: NN47215-700 Document status: Standard Document release date: 06 May 2008 Copyright 2008 Nortel Networks All Rights Reserved. Sourced in Canada The information in this document is subject to change without notice. The statements, configurations, technical data, and recommendations in this document are believed to be accurate and reliable, but are presented without express or implied warranty. Users must take full responsibility for their applications of any products specified in this document. This document is protected by copyright laws and international treaties. All information, copyrights and any other intellectual property rights contained in this document are the property of Nortel Networks. Except as expressly authorized in writing by Nortel Networks, the holder is granted no rights to use the information contained herein and this document shall not be published, copied, produced or reproduced, modified, translated, compiled, distributed, displayed or transmitted, in whole or part, in any form or media. Sourced in Canada, the United States of America, and India. *Nortel, the Nortel logo, and the Globemark are trademarks of Nortel Networks. All other trademarks are the property of their respective owners.
ATTENTION: Before troubleshooting the Ethernet Routing Switch 2500 Series, ensure you read the legal statements in the first chapter of this guide.
Contents
Legal information
Restricted rights legend 5 Statement of conditions 5 Nortel Networks software license agreement
13 15 17
21 23 25
Initial troubleshooting
Gather information 23
28
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Troubleshooting hardware
Check power 41 Check cables 44 Check port 45 Check fiber port 47 Replace unit 50
39
Troubleshooting ADAC
IP phone is not detected 56 Correct filtering 57 Reload ADAC MAC in range table 58 Reduce LLDP devices 60 Auto configuration is not applied 61 Correct auto configuration 62 Check status and number of devices 64
55
Troubleshooting authentication
EAP client authentication 68 Restore RADIUS connection 70 Enable EAP on The PC 72 Apply the method 73 Enable EAP globally 74 EAP multihost repeated re-authentication issue Match EAP-MAC-MAX to EAP users 76 Set EAPOL request packet 78 EAP RADIUS VLAN is not being applied 79 Configure VLAN at RADIUS 80 Configure switch 82 Configured MAC is not authenticating 87 Configure the switch 87 NEAP RADIUS MAC not authenticating 92 Configure switch 93 RADIUS server configuration error 96 NEAP MHSA MAC is not authenticating 97 Configure switch 98 EAP-NEAP unexpected port shutdown 102 Configure switch 103
67
76
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Legal information
Restricted rights legend
Use, duplication, or disclosure by the United States Government is subject to restrictions as set forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013. Notwithstanding any other license agreement that may pertain to, or accompany the delivery of, this computer software, the rights of the United States Government regarding its use, reproduction, and disclosure are as set forth in the Commercial Computer Software-Restricted Rights clause at FAR 52.227-19.
Statement of conditions
In the interest of improving internal design, operational function, and/or reliability, Nortel Networks reserves the right to make changes to the products described in this document without notice. Nortel Networks does not assume any liability that may occur due to the use or application of the product(s) or circuit layout(s) described herein. Portions of the code in this software product may be Copyright 1988, Regents of the University of California. All rights reserved. Redistribution and use in source and binary forms of such portions are permitted, provided that the above copyright notice and this paragraph are duplicated in all such forms and that any documentation, advertising materials, and other materials related to such distribution and use acknowledge that such portions of the software were developed by the University of California, Berkeley. The name of the University may not be used to endorse or promote products derived from such portions of the software without specific prior written permission. SUCH PORTIONS OF THE SOFTWARE ARE PROVIDED "AS IS" AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
6 Legal information
In addition, the program and information contained herein are licensed only pursuant to a license agreement that contains restrictions on use and disclosure (that may incorporate by reference certain limitations and notices imposed by third parties).
destruction. Nortel Networks may audit by remote polling or other reasonable means to determine Customers Software activation or usage levels. If suppliers of third party software included in Software require Nortel Networks to include additional or different terms, Customer agrees to abide by such terms provided by Nortel Networks with respect to such third party software. 2. Warranty. Except as may be otherwise expressly agreed to in writing between Nortel Networks and Customer, Software is provided "AS IS" without any warranties (conditions) of any kind. NORTEL NETWORKS DISCLAIMS ALL WARRANTIES (CONDITIONS) FOR THE SOFTWARE, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nortel Networks is not obligated to provide support of any kind for the Software. Some jurisdictions do not allow exclusion of implied warranties, and, in such event, the above exclusions may not apply. 3. Limitation of Remedies. IN NO EVENT SHALL NORTEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE LIABLE FOR ANY OF THE FOLLOWING: a) DAMAGES BASED ON ANY THIRD PARTY CLAIM; b) LOSS OF, OR DAMAGE TO, CUSTOMERS RECORDS, FILES OR DATA; OR c) DIRECT, INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING LOST PROFITS OR SAVINGS), WHETHER IN CONTRACT, TORT OR OTHERWISE (INCLUDING NEGLIGENCE) ARISING OUT OF YOUR USE OF THE SOFTWARE, EVEN IF NORTEL NETWORKS, ITS AGENTS OR SUPPLIERS HAVE BEEN ADVISED OF THEIR POSSIBILITY. The foregoing limitations of remedies also apply to any developer and/or supplier of the Software. Such developer and/or supplier is an intended beneficiary of this Section. Some jurisdictions do not allow these limitations or exclusions and, in such event, they may not apply. 4. General If Customer is the United States Government, the following paragraph shall apply: All Nortel Networks Software available under this License Agreement is commercial computer software and commercial computer software documentation and, in the event Software is licensed for or on behalf of the United States Government, the respective rights to the software and software documentation are governed by Nortel Networks standard commercial license in accordance with U.S. Federal Regulations at 48 C.F.R. Sections 12.212 (for non-DoD entities) and 48 C.F.R. 227.7202 (for DoD entities). Customer may terminate the license at any time. Nortel Networks may terminate the license if Customer fails to comply with the terms and conditions of this license. In either event, upon termination, Customer must either return the Software to Nortel Networks or certify its destruction.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
8 Legal information
Customer is responsible for payment of any taxes, including personal property taxes, resulting from Customers use of the Software. Customer agrees to comply with all applicable laws including all applicable export and import laws and regulations. Neither party may bring an action, regardless of form, more than two years after the cause of the action arose. The terms and conditions of this License Agreement form the complete and exclusive agreement between Customer and Nortel Networks. This License Agreement is governed by the laws of the country in which Customer acquires the Software. If the Software is acquired in the United States, then this License Agreement is governed by the laws of the state of New York.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Stacking
The ERS 2500 Series software release v4.1 has the capability to stack up to eight units in a stack. Stacking functionality is available through two methods. First, by purchasing a stack enabled device. These devices have the rear ports set to stacking mode as default in the factory. These devices do not use or require a license for the feature. Second, a standalone unit can have the stacking feature enabled through the use of a Stacking License Kit that includes a license certificate and a License Authorization code (LAC) for use on the Nortel Licensing Portal. It is important to note that stack enabled switches can be stacked regardless of the method the stacking was enabled on them. The stack enabled units are identifiable through CLI, JDM, or WebUI.
Stacking licensing
There are four variants of Stacking License Kits that are available for standalone switches. Each kit contains a license certificate and LAC. The license file management and generation is through the Nortel Licensing Portal. The license file is generated, downloaded and installed on each standalone ERS 2500 Series device that requires stacking functionality. The instructions are located on the license certificate. The license file unlocks stacking functionality and allows the ports on the rear of the switch to be set to Stacking Mode. License files can be added and removed from the switch. Should you set a non stack enabled device to default, the license file is removed. There are two cases that may be encountered. First, when the stack is reset to default (#boot default) the switches continues to function in stack indefinitely. Second, when the licenses are removed (#clear license) the stack continues to work until the second reset.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Stack License Kits are available for 1, 10, 50, or 100 devices. The ERS 2500 Series licensing has a more intuitive LAC schema. The memo field in the license is also populated as part of the license file generation on the licensing portal.
Figure 1 License Schema
Each ERS 2500 Series device ships with a 46 cm (1.5 ft) stacking cable. The stacking cable is a black Cat5E cable. Spare stacking cables are available on the price list for additional purchase. Also available for purchase are additional cables of 1.5 m (5 ft) and 3 m (10 ft) and are similar to stack return cables, You are permitted to use your own cables and longer lengths up to 100m. This is at your own risk and is not officially supported by GNTS.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
In NNCLI, under PrivExec mode, you can use the following commands:
default rear-ports mode [unit <1-8>] {standalone | stacking} to set the operating mode. The default is standalone. show rear-ports mode displays the operating mode of the rear ports.
Under JDM, the rear ports are be grayed out and not selectable in the switch view if the ports are in stacking mode.
Figure 3 ERS 2500 JDM display
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
13
Introduction
This document is the first troubleshooting guide for the ERS 2500 series software Release v4.1. This document :
Describes the diagnostic tools and utilities available for troubleshooting the Nortel ERS 2500 Series products including the Nortel Networks Command Line Interface (NNCLI) and Java Device Manager (JDM).. Guides you through some common problems to achieve a first tier solution to these situations Advises you what information to compile prior to troubleshooting or calling Nortel for help.
Have basic knowledge of networks, ethernet bridging, and IP routing. Are familiar with networking concepts and terminology. Have experience with Graphical User Interface (GUI). Have basic knowledge of network topologies.
Troubleshooting Tools The ERS 2500 Series products support a range of protocols, utilities, and diagnostic tools that you can use to monitor and analyze traffic, monitor laser operating characteristics, capture and analyze data packets, trace data flows, view statistics, and manage event messages. Certain protocols and tools are tailored for troubleshooting specific ERS 2500 Series network topologies. Other tools are more general in their application and can be used to diagnose and monitor ingress and egress traffic.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
14 Introduction
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
15
Troubleshooting planning
There are some things you can do to minimize the need for troubleshooting and to plan for doing it as effectively as possible. First, use the Ethernet Routing Switch 2500 Series Documentation Roadmap to familiarize yourself with the documentation set, so you know where to get information when you need it. Second, make sure the system is properly installed and maintained so that it operates as expected. Third, make sure you gather and keep up to date the site map, logical connections, device configuration information, and other data that you will require if you have to troubleshoot.
A site network map identifies where each device is physically located on your site, which helps locate the users and applications that are affected by a problem. You can use the map to systematically search each part of your network for problems. You must know how your devices are connected logically and physically with virtual local area networks (VLAN). You should maintain online and paper copies of your device configuration information. Ensure that all online data is stored with your sites regular data backup for your site. If your site has no backup system, copy the information onto a backup medium and store the backup offsite. Store passwords in a safe place. It is a good practice to keep records of your previous passwords in case you must restore a device to a previous software version. You need to use the old password that was valid for that version. It is a good practice to maintain a device inventory, which list all devices and relevant information for your network. Use this inventory to easily see the device types, IP addresses, ports, MAC addresses, and attached devices. If your hubs or switches are not managed, you must keep a list of the MAC addresses that correlate to the ports on your hubs and switches.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
16 Troubleshooting planning
Maintain a change-control system for all critical systems. Permanently store change-control records. It is a good practice to store the details of all key contacts, such as support contacts, support numbers, engineer details, and telephone and fax numbers. Having this information available during troubleshooting saves you time.
Fourth, understand the normal network behavior so you can be more effective at troubleshooting problems.
Monitor your network over a period of time sufficient to allow you to obtain statistics and data to see patterns in the traffic flow, such as which devices are typically accessed or when peak usage times occur. Use a baseline analysis as an important indicator of overall network health. A baseline view of network traffic as it typically is during normal operation is a reference that you can compare to network traffic data that you capture during troubleshooting. This should speed the process of isolating network problems.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
17
Troubleshooting tools
These are the available troubleshooting tools and their applications.
Port Mirroring
ERS 2500 Series switches have a port mirroring feature that helps you to monitor and analyze network traffic. The port mirroring feature supports both ingress (incoming traffic) and egress (outgoing traffic) port mirroring. When port mirroring is enabled, the ingress or egress packets of the mirrored (source) port are forwarded normally and a copy of the packets is sent from the mirrored port to the mirroring (destination) port. You can observe and analyze packet traffic at the mirroring port using a network analyzer. A copy of the packet can be captured and analyzed. Unlike other methods that are used to analyze packet traffic, the packet traffic is uninterrupted and packets flow normally through the mirrored port.
Ingress mode (XRX or ->Port X) Egress mode (XTX or Port X ->) Ingress and Egress Mode (XRX or XTX or <->Port X)
There are limitations to the Egress mode. While as a standalone or a stack, port-mirroring mode XTX mirrors egress traffic on the mirrored port but does not mirror control packets generated by the switch. The monitor port does not receive copies of the generated control packets that egress from the mirrored port. There are also limitations on Ingress and Egress modes. First, the same limitation on the XTX portion also applies to this mode. Second, in a stack, both the monitor and mirror port should be on the same unit.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
18 Troubleshooting tools
Port statistics
Use port statistics commands to display information on received and transmitted packets at the ports. The ingress and egress counts occur at the MAC layer.
System logs
You can use the syslog messaging feature of the ERS 2500 Series products to manage event messages. The ERS 2500 Series syslog software communicates with a server software component named syslogd that resides on your management workstation. The daemon syslogd is a software component that receives and locally logs, displays, prints, or forwards messages that originate from sources that are internal and external to the workstation. For example, syslogd software concurrently handles messages received from applications running on the workstation, as well as messages received from an ERS 2500 Series device running in a network accessible to the workstation.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
19
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
20 Troubleshooting tools
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
21
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Each mode provides a specific set of commands. The command set of a higher-privilege mode is a superset of a lower-privilege mode. That is, all lower-privilege mode commands are accessible when using a higher-privilege mode. The command modes are as follows:
User EXEC mode: The User EXEC mode (also referred to as exec mode) is the default CLI command mode. User EXEC is the initial mode of access when the switch is first turned on and provides a limited subset of CLI commands. This mode is the most restrictive CLI mode and has few commands available. Privileged EXEC mode: The Privileged EXEC mode (also referred to as privExec mode) enables the user to perform basic switch-level management tasks, such as downloading software images, setting passwords, and booting the switch. privExec is an unrestricted mode that allows you to view all settings on the switch, and if you are logged in with write access, it also allows you to access all configuration modes and commands that affect operation of the switch (such as downloading images, rebooting, etc.). Global configuration mode: The Global Configuration mode (also referred to as config mode) enables the user to set and display general configurations for the switch such as IP address, SNMP parameters, Telnet access, and VLANs. Interface configuration mode:The Interface Configuration mode (also referred to as config-if mode) enables the user to configure parameters for each port or VLAN, such as speed, duplex mode, and rate-limiting.
It is possible to move between command modes on a limited basis. This is explained in the Common Procedures section of this document.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
23
Initial troubleshooting
The types of problems that typically occur with networks involve connectivity and performance. It is usually best to follow the Open System Interconnection (OSI) network architecture layers. Confirm that the physical environment, such as the cables and module connections, is operating without any failures before moving up to the network and application layers. As part of your initial troubleshooting, Nortel recommends that you check the Knowledge and Solution Engine on the Nortel web site for known issues and solutions related to the problem you are experiencing.
Gather information
Before contacting Nortel Technical Support, you must gather information that can help the Technical Support personnel. This includes the following information:
Default and current configuration of the switch. To do this, you can use the show running-config command. System status: Displays technical information about system status and information about the hardware, software, and switch operation output from the show sys-info command. For more detail, use the show tech command. Information about past events. To do this, review the log files using the show logging command. The software version that is running on the device. To do this, use the show sys-info or show system verbose commands to display the software version. A network topology diagram: Get an accurate and detailed topology diagram of your network that shows the nodes and connections. Your planning and engineering function should have this diagram. Recent changes: Find out about recent changes or upgrades to your system, your network, or custom applications (for example, has configuration or code been changed?). Get the date and time of the changes, and the names of the persons who made them. Get a list of
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
24 Initial troubleshooting
events that occurred prior to the trouble, such as an upgrade, a LAN change, increased traffic, or installation of new hardware.
Connectivity information: When connectivity problems occur, get information on at least five working source and destination IP pairs and five IP pairs with connectivity issues. To do this, use these commands: show tech show running-config show port-statistics <port>
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
25
Navigation
"Corruption of flash" (page 26) "Incorrect PVID" (page 27) "Uplink ports not tagged to VLAN" (page 28) "SNMP" (page 30) "Stack " (page 33)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Corruption of flash
Corruption of the switch configuration file can sometimes occur due to power outage or environmental reasons makes the configuration of the box corrupt and non-functional. Initializing of the flash is one way to clear a corrupted configuration file and is required before an RMA.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Incorrect PVID
27
Incorrect PVID
An issue can occur where clients cannot communicate to critical servers when their ports are put in wrong VLAN. If the server is plugged in VLAN-3 and the PVID of the port is 2 then loss of communication can occur. This can be verified by checking the PVID of the ports.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Uplink ports not tagged to VLAN Figure 7 Uplink ports not tagged to VLAN
29
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
SNMP
SNMP failure may be the result of an incorrect configuration of the management station or its setup. If you can reach a device but no traps are received, verify the trap configurations (the trap destination address and the traps configured to be sent).
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
31
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Stack
33
Stack
Stack failure can be the result of a communication error between the individual units due to configuration or cabling. Failures can also arise when there are multiple bases configured.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Stack
35
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Stack
37
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
39
Troubleshooting hardware
Complete hardware troubleshooting specific to the ERS 2500 series.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Check power" (page 41) "Check cables" (page 44) "Check port" (page 45)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Check power 41
Check power
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Correcting voltage source" (page 43) "Ensuring power cord is installed" (page 43) "Observing error report on console" (page 43) "Reloading agent code" (page 43) "Returning unit for repair" (page 43)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Check power 43
Procedure Steps
Step
1 2
Action View console information and note any details for the RMA. Note the LED status for information:
Status LED blinking amber: Power On Self Test (POST) failure Power LED blinking: corrupt flash
--End--
CAUTION
Ensure you have adequate backup of your configuration prior to reloading software. Know the current version of your software before reloading it. Loading incorrect software versions may cause further complications.
Procedure Steps
Step
1 2
Action Use the show sys-info command view the software version. Refer to the Nortel Ethernet Routing Switch 2500 Series Configuration System (NN47215-500) for software installation.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
44 Troubleshooting hardware
Check cables
Confirm the stacking cables are correctly connected.
Navigation
"Confirming cables are correct type" (page 44) "Reviewing configuration documentation" (page 45)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Check port 45
Check port
Confirm the port and ethernet cable connecting the port are in proper configuration.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Viewing port information" (page 46) "Enabling the port" (page 47) "Confirming the cables are working" (page 47) "Confirming the cables are working" (page 47)
Procedure Steps
Step
1
Action Use the show interfaces <port> command to display the port information.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Procedure Steps
Step
1 2 3 4
Action Go to interface specific mode using the interface fastethernet <port> command. Use the no shutdown command to change the port configuration. Use the show interfaces <port> command to display the port. Note the port administrative status.
--End--
Procedure Steps
Step
1 2 3 4
Action Go to interface specific mode using the interface fastethernet <port> command. Use the no shutdown command to change the port configuration. Use the show interfaces <port> command to display the port. Note the operational and link status of the port.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
48 Troubleshooting hardware
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Viewing fiber port information" (page 49) "Enabling port" (page 49) "Confirming cables working" (page 49) "Returning unit for repair" (page 50)
Procedure Steps
Step
1 2
Action Use the show interfaces <port> command to display the port information Note the port status.
--End--
Enabling port
Ensure the port on the ERS 2500 series device is enabled.
Procedure Steps
Step
1 2 3
Action Use the no shutdown command to change the port configuration. Use the show interfaces <port> command to display the port information. Note the port status.
--End--
Procedure Steps
Step
1
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
50 Troubleshooting hardware 2 3
Use the show interfaces <port> command to display the port. Note the port operational and link status.
--End--
Replace unit
Remove defective unit and insert the replacement.
CAUTION
Due to physical handling of the device and your physical proximity to electrical equipment, review and adhere to all safety instructions and literature included with device and in Nortel Ethernet Routing Switch 2500 Series Regulatory Information (NN47215-100).
The Auto Unit Replacement (AUR) feature allows replacement of a failed unit in a stack with a new unit, while retaining the configuration of the previous unit. The stack power must be on during unit replacement. In order for AUR to function properly, the new unit and the existing units in the stack must all be running the same version of software (Release 4.1 software or later). AUR is not designed for the situation of removing and reinserting the same switch (with the same MAC address). For detailed information regarding AUR refer to Nortel Ethernet Routing Switch 2500 Series Configuration System (NN47215-500) Auto Unit Replacement section.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
51
Navigation
"Removing failed unit" (page 52) "Verifying software version is correct on new device" (page 52) "Obtaining correct software version" (page 52) "Placing new unit" (page 52) "Connecting stacking cables" (page 52) "Powering on unit" (page 53) "Returning unit for repair" (page 53)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
52 Troubleshooting hardware
Procedure Steps
Step
1 2
Action Maintain power to the stack. Do not power down stack. Remove the failed device.
--End--
Procedure Steps
Step
1 2
Action Connect the new device to the console, independent of stack connection. Use the show sys-info command view the software version.
--End--
CAUTION
Ensure you have adequate backup of your configuration prior to reloading software. Know the proper version of your software before loading it. Loading incorrect software versions may cause further complications.
Procedure Steps
Action Refer to the Nortel Ethernet Routing Switch 2500 Series Configuration System (NN47215-500) for software installation.
Replace unit
53
Procedure Steps
Step
1
Action Review the stacking section in Nortel Ethernet Routing Switch 2500 Series Configuration System (NN47215-500) for cabling details. Connect the cables in accordance with physical stack requirements.
--End--
Powering on unit
Energize the unit once it is connected and ready to integrate. There is no requirement to reset the entire stack. The single device being replaced is the only device having such action placed on it.
Procedure Steps
Step
1 2 3
Action Connect the power to the unit. Allow time for the new unit to join the stack. The configuration of the failed unit to be replicated on the new unit. Confirm that the new unit has reset itself. This confirms that replication has completed.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
54 Troubleshooting hardware
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
55
Troubleshooting ADAC
Automatic Detection and Automatic Configuration (ADAC) may can encounter some detection and configuration errors that can be easily corrected.
ADAC clarifications
ADAC VLAN settings are dynamic and are not saved to nonvolatile memory. When ADAC is enabled, all VLAN settings manually made by user on ADAC uplink or telephony ports are dynamic and are not saved to non-volatile memory. When the unit is reset, these settings are lost. ADAC redetects the ports and re-applies the default settings for them. There is no requirement to create a voice VLAN manually. You do not manually create a VLAN to be used as the voice VLAN and then try to set this VLAN as ADAC voice VLAN using the command adac voice-vlan x. ADAC automatically creates the voice VLAN when needed. You only have to reserve or set the VLAN number used by ADAC with the adac voice-vlan x command. Once the VLAN number is reserved for ADAC voice-vlan with the adac voice-vlan x command, even if ADAC admin status is disabled or ADAC is in UTF mode, the VLAN number cannot be used by user in regular VLAN creation. If you enable the LLDP detection mechanism for telephony ports, then LLDP itself has to be enabled on the switch. Otherwise ADAC wont detect any phone.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"IP phone is not detected" (page 56) "Auto configuration is not applied" (page 61)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
57
Navigation
"Correct filtering" (page 57) "Reload ADAC MAC in range table" (page 58) "Reduce LLDP devices" (page 60)
Correct filtering
Configure the VLAN filtering allow ADAC.
Navigation
"Confirming port belongs to at least one VLAN" (page 57) "Disabling VLAN filter unregistered frames" (page 58)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
58 Troubleshooting ADAC
Action Use the show vlan interface info <port> command to view the details. Note the VLANs listed with the port.
--End--
Action Use the vlan ports <port> filter-unregistered-fram es enable command to view the details. Ensure no errors after command execution.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
59
Navigation
"Disconnecting and reconnecting phone" (page 59) "Disabling and enabling the port" (page 59)
Action Follow local procedure to disconnect the phone. Follow local procedures to reconnect the phone.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
60 Troubleshooting ADAC
Action Use the no adac enable <port> command to disable ADAC. Use the adac enable <port> command to enable ADAC.
--End--
Navigation
"Viewing LLDP information" (page 61) "Reducing LLDP enabled devices" (page 61)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
61
Action Use the show lldp port 1 neighbor command to identify the LLDP devices. Note if there are more than 16 LLDP enabled devices on the port.
--End--
Action Use the no adac enable <port> command to disable ADAC. Use the adac enable <port> command to enable ADAC.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Correct auto configuration" (page 62) "Check status and number of devices" (page 64)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
63
Navigation
"Viewing ADAC global status" (page 63) "Configuring another CS/UP" (page 64) "Replacing Unit" (page 64)
Action Use the show adac command to display the ADAC information.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
64 Troubleshooting ADAC 2
Action Use the adac uplink-port <port> command to assign the uplink port. Use the adac call-server-port <port> command to assign the call server port.
--End--
Replacing Unit
Replace unit to replicate configuration is AUR is enabled. Procedure Steps Step
1 2
Action Follow the replacement guidelines in the Nortel Ethernet Routing Switch 2500 Series System Configuration (NN47215-500). Refer to the unit replacement section in the Troubleshooting Hardware section in this document.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Auto configuration is not applied Figure 24 Check status and number of devices
65
Navigation
"Viewing ADAC port status" (page 65) "Reducing the number of devices" (page 66) "Disabling and enabling the port." (page 66)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
66 Troubleshooting ADAC
Action Use the show adac in <port> command to display the ADAC information for the port. Note if the oper state is disabled and the number of devices connected.
--End--
Action Follow local procedures and SOP to reduce the number of devices connected. Use the show adac in <port> command to display the ADAC information for the port to ensure there are less than 32 devices connected.
--End--
Action Use the no adac enable <port> command to disable ADAC. Use the adac enable <port> command to enable ADAC.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
67
Troubleshooting authentication
Authentication issues can interfere with device operation and function. The following work flow contains some common authentication problems.
Navigation
"EAP client authentication " (page 68) "EAP multihost repeated re-authentication issue" (page 76) "EAP RADIUS VLAN is not being applied " (page 79) "Configured MAC is not authenticating" (page 87)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
68 Troubleshooting authentication
"NEAP RADIUS MAC not authenticating" (page 92) "NEAP MHSA MAC is not authenticating" (page 97) "EAP-NEAP unexpected port shutdown" (page 102)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
69
Navigation
"Restore RADIUS connection" (page 70) "Enable EAP on The PC" (page 72)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
70 Troubleshooting authentication
"Apply the method" (page 73) "Enable EAP globally" (page 74)
Navigation
"Getting correct RADIUS server settings for the switch" (page 71) "Viewing RADIUS information" (page 71)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
71
"Configuring the RADIUS server settings" (page 71) "Pinging the RADIUS server" (page 72)
Action Obtain network information for the RADIUS server from the Planning and Engineering documentation. Follow vendor documentation to set the RADIUS authentication method MD5.
--End--
Action Use the show radius-server command to view the RADIUS server settings. Refer to the vendor documentation for server configuration.
--End--
72 Troubleshooting authentication 2
Action Use the ping <server IP> command to ensure connection. Observe no packet loss to confirm connection.
--End--
Navigation
73
Action Reference vendor documentation for PC and network card. Ensure card is enabled. Ensure card is configured to support EAP.
--End--
Navigation
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
74 Troubleshooting authentication
Action Obtain Network information for Radius Server from Planning and Engineering. Save the information for reference.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
75
Navigation
"Enabling EAP globally" (page 75) "Viewing EAPOL settings" (page 75) "Setting EAPOL port administrative status to auto" (page 75)
Action Use the eapol enable command to enable EAP globally on the ERS 2500 series device. Observe no errors after command execution.
--End--
Action Use the show eapol port <port#> command to display the information. Observe the output.
--End--
Action Use the eapol status auto command to change the port status to auto. Observe no errors after the command execution.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
76 Troubleshooting authentication
Navigation
"Match EAP-MAC-MAX to EAP users" (page 76) "Set EAPOL request packet" (page 78)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
77
Navigation
"Identifying number users at allowed max" (page 77) "Lowering EAP max MAC" (page 77)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
78 Troubleshooting authentication
Action Use the eapol multihost eap-mac-max command to set the mac-max value. Observe no errors after execution.
--End--
Navigation
"Setting EAPOL request packet globally" (page 78) "Setting EAPOL request packet per port" (page 79)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
79
Action Use the eapol multihost eap-packet-mode unicast command to set the EAPOL request packet to unicast. Observe no errors after execution.
--End--
Action Enter the interface configuration mode. Use the eapol multihost eap-packet-mode unicast command to set the EAPOL request packet to unicast for the interface.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
"Configure VLAN at RADIUS " (page 80) "Configure switch" (page 82)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
EAP RADIUS VLAN is not being applied Figure 35 Configure VLAN at RADIUS
81
Navigation
"Getting correct RADIUS server settings" (page 81) "Viewing RADIUS information" (page 82) "Configuring RADIUS" (page 82)
Action Obtain network information from Planning and Engineering documentation locate server information
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
82 Troubleshooting authentication 2
Configuring RADIUS
Configure the RADIUS server with the correct VLAN information. Use vendor documentation to make the required changes. There are three attributes that the RADIUS server sends back to the NAS(switch) for RADIUS assigned VLANs. It is the same for all RADIUS vendors.
Configure switch
The VLAN has to be configured correctly on the ERS 2500 series device.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
EAP RADIUS VLAN is not being applied Figure 36 Configure switch task
83
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
84 Troubleshooting authentication
Navigation
"Showing EAPOL multihost" (page 84) "Enabling use of RADIUS assigned VLANs" (page 85) "Showing EAPOL multihost interface" (page 85) "Showing VLAN config control" (page 85) "Changing VLAN config from strict to flexible" (page 86) "Showing spanning tree" (page 86) "Adding RADIUS assigned VLAN to desired STG" (page 86)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
85
Action Use the show eapol multihost command to display the multihost information. Note the state of Allow Use of RADIUS Assigned VLANs.
--End--
Action Use eapol multihost use-radius-assigned-vlan command to allow the use of VLAN IDs assigned by RADIUS. Observe no errors after execution.
--End--
Action Use the show eapol multihost interface <port#> command to display the interface information. Note the status of ALLOW RADIUS VLANs.
--End--
Action Use the show vlan config control command to display the information.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
86 Troubleshooting authentication 2
Action Use the vlan config control flexible command to set the VLAN config control to flexible. Observe no errors after execution.
--End--
Action Use the show spanning-tree stp <1-8> vlans command to display the information. Identify if RADIUS assigned VLAN and original VLAN are in the same STG.
--End--
Action Use the spanning-tree stp <1-8> vlanscommand to make the change.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
87
Navigation
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
89
Navigation
"Showing EAPOL port" (page 89) "Setting global EAP enabled and port at eap-auto" (page 90) "Showing EAPOL multihost" (page 90) "Enabling allow Non-EAPOL clients" (page 90) "Showing EAPOL multihost interface " (page 91) "Enabling multihost status and allow non-EAPOL clients " (page 91) "Showing EAPOL multihost non-eap-mac interface " (page 91) "Ensuring MAC in the list" (page 92)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
90 Troubleshooting authentication
Action Use the command show eapol port <port> to display the port information. Note that EAP is to be enabled globally, and port at EAP is set to auto.
--End--
Action Use the eapol enable command to enable EAP globally. Use the eapol status auto command to change port status to auto.
--End--
Action Enter the show eapol multihost command to display the information. Note that Allow Non-EAPOL clients is enabled.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
91
Action Enter the show eapol multihost interface <port#> command to display the information. Note that Allow Non-EAPOL clients is enabled. Note that Multihost status is enabled.
--End--
Action Use the eapol multihost allow-non-eap-enable command to enable. Use the eapol multihost enable command to enable multihost status.
--End--
Action Enter the show eapol multihost non-eap-mac interface <port> command to display the information. Note the MAC is in the list.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
92 Troubleshooting authentication
Action Use the show eapol multihost non-eap-mac status <port> command to view mac addresses. Use the eapol multihost non-eap-mac <H.H.H> <port> command to add a mac address to the list.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
93
Navigation
"Configure switch" (page 93) "RADIUS server configuration error" (page 96)
Configure switch
Correct switch configuration to correct issue with RADIUS MAC.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
94 Troubleshooting authentication
Navigation
"Displaying EAPOL port" (page 94) "Setting global eap enabled and port at eap-auto" (page 95) "Displaying EAPOL multihost" (page 95) "Enabling RADIUS to authenticate non-EAPOL clients" (page 95) "Formatting non-EAPOL RADIUS password attribute" (page 96) "Displaying EAPOL multihost interface" (page 96) "Enabling RADIUS To Auth Non-EAP MACs" (page 96)
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
95
Action Enter the show eapol port <port#> command to display the information. Note the global eap is enabled and port is eap-auto.
--End--
Action Use the eapol enable command to enable EAP globally. Use the eapol status auto command to change port status to auto.
--End--
Action Enter the show eapol port multihost command to display the information. Note the following:
Use RADIUS To Authenticate NonEAPOL Clients is enabled Non-EAPOL RADIUS Password Attribute Format: IpAddr.MACAddr.PortNumber
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
96 Troubleshooting authentication
Action Enter the show eapol multihost interface <port#> command to display the information Verify the following:
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
NEAP MHSA MAC is not authenticating Figure 41 RADIUS server configuration error
97
Navigation
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Navigation
Configure switch
Configure the switch to enable MHSA.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
99
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
100
Troubleshooting authentication
Navigation
"Showing EAPOL port" (page 100) "Setting global EAP enabled and port at eap-auto" (page 101) "Showing EAPOL multihost" (page 101) "Formatting non-EAPOL RADIUS password attribute" (page 101) "Showing EAPOL multihost interface" (page 102) "Enabling RADIUS to auth non-EAP MACs" (page 102)
101
Action Enter the show eapol port <port#> command to display the information. Note the global eap is enabled and port is eap-auto.
--End--
Action Use the eapol enable command to enable EAP globally. Use the eapol status auto command to change port status to auto.
--End--
Action Enter the show eapol port multihost command to display the information. Note the following:
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
102
Troubleshooting authentication
Action Enter the show eapol multihost interface <port#> command to display the information. Note the following:
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
103
Navigation
Configure switch
Configure ports to allow more unauthorized clients.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
104
Troubleshooting authentication
Navigation
"Showing Logs" (page 104) "Showing EAP-NEAP clients on port" (page 105) "Showing EAPOL port information" (page 105) "Making changes" (page 105)
Showing Logs
Display log information for detailed information to provide any additional information.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
105
Action Use the show logging command to display the log. Observe the log output and note any anomalies.
--End--
Action Use the show mac-address-table command to show the clients on the port. Observe the log output and note any anomalies.
--End--
Action Use the show mac-address-table command to show the clients on the port. Observe the log output and note any anomalies.
--End--
Making changes
This section provides troubleshooting guidelines for changing the EAP settings. It may clean up old MACs.
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
106
Troubleshooting authentication
Action Use the eap-force-unauthorised command to set the administrative state of the port to forced unauthorized. Use the eapol status auto command to change to eap-auto to start. Use the shut/no shut commands in the Interface Exec Mode.
--End--
Ethernet Routing Switch 2500 Series Troubleshooting NN47215-700 01.01 Standard 30 April 2008
Copyright 2008 Nortel Networks
Troubleshooting
Copyright 2008 Nortel Networks All Rights Reserved. Printed in Canada Release: 4.1 Publication: NN47215-700 Document status: Standard Document revision: 01.01 Document release date: 06 May 2008 To provide feedback or to report a problem in this document, go to www.nortel.com/documentfeedback. www.nortel.com The information in this document is subject to change without notice. The statements, configurations, technical data, and recommendations in this document are believed to be accurate and reliable, but are presented without express or implied warranty. Users must take full responsibility for their applications of any products specified in this document. This document is protected by copyright laws and international treaties. All information, copyrights and any other intellectual property rights contained in this document are the property of Nortel Networks. Except as expressly authorized in writing by Nortel Networks, the holder is granted no rights to use the information contained herein and this document shall not be published, copied, produced or reproduced, modified, translated, compiled, distributed, displayed or transmitted, in whole or part, in any form or media. Sourced in Canada, the United States of America, and India. *Nortel, the Nortel logo, and the Globemark are trademarks of Nortel Networks. All other trademarks are the property of their respective owners.