networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Mon Aug 06, 2012 4:05 am 
Offline
Member
Member

Joined: Wed May 11, 2011 8:04 pm
Posts: 181
Certs: CCNA
Does anyone know any software that could help to measure Authentication time between client and Radius serverr.


Top
 Profile  
 
PostPosted: Mon Aug 06, 2012 4:28 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1197
Location: West FL
Certs: CCNP, JNCIA, MCSA
If you're on a Cisco router/switch, do 'debug radius' from one TTY/console session and try to login to another. You'll then get syslogs showing you when the authentication request was sent and received with the times. Alternatively, you could go to the RADIUS server and look at the logs to see when the request was sent and authentication granted.


Top
 Profile  
 
PostPosted: Mon Aug 06, 2012 5:54 am 
Offline
Member
Member

Joined: Wed May 11, 2011 8:04 pm
Posts: 181
Certs: CCNA
Sorry but where from logs can we see I can see Access granted time there but not the time when request came.


Top
 Profile  
 
PostPosted: Mon Aug 06, 2012 6:28 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1197
Location: West FL
Certs: CCNP, JNCIA, MCSA
What RADIUS server do you have?


Top
 Profile  
 
PostPosted: Mon Aug 06, 2012 6:55 am 
Offline
Member
Member

Joined: Wed May 11, 2011 8:04 pm
Posts: 181
Certs: CCNA
Windows server 2003


Top
 Profile  
 
PostPosted: Mon Aug 06, 2012 7:22 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1197
Location: West FL
Certs: CCNP, JNCIA, MCSA
Event Viewer -> System log will show you when the request was accepted/denied. Otherwise, try going to IAS -> Remote Access Logging, double-click Local File, check all the boxes, try to authenticate, then head over to the directory to see what's logged.

I think the easiest way is to just run 'debug radius' on the router/switch and try it out. I just so happened to be working on a RADIUS issue this morning and have been using the debug command. Here's what I see:

Quote:
Aug 6 12:12:37.985 UTC: RADIUS/ENCODE(00001313): ask "Password: " <---This is saying that the switch has asked me for my password and is waiting for my input
Switch#
Aug 6 12:12:41.126 UTC: RADIUS/ENCODE(00001313):Orig. component type = EXEC <---I put in my password and hit Enter and the switch shows me this log
Aug 6 12:12:41.147 UTC: RADIUS(00001313): Received from id 1645/48 <---Several logs show up telling me the NAS port, port ID, etc, but this is the last one that shows up, at which point I'm sitting in Enable mode


These logs give me a good idea of how long it took the request to be accepted by the switch, sent to the RADIUS server, and for the RADIUS server to respond back granting or denying me access.


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 1:03 am 
Offline
Member
Member

Joined: Wed May 11, 2011 8:04 pm
Posts: 181
Certs: CCNA
YOu are using cisco Switch ?


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 5:34 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1197
Location: West FL
Certs: CCNP, JNCIA, MCSA
In my test, yes. But it doesn't matter.


Top
 Profile  
 
PostPosted: Mon Oct 01, 2012 1:06 pm 
Offline
Member
Member

Joined: Wed May 11, 2011 8:04 pm
Posts: 181
Certs: CCNA
Radping


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: astorrs, m4rtin, totaluser and 30 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group