Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Devilmac
Explorer

Smartconsole Access problem after Hotfix

Hello Checkmates!

 

I am having a problem with all our MDS, currently I have installed R80.40 JHF 156, due to some problems TAC requested us to apply JHF 176/180.

After we apply this hotfix we notice that we are not able to login with our TACACS users.

Doing some troubleshooting we notice the traffic is not following the correct route.

 

RADIUS Server is IP  21.22.23.220

"add aaa tacacs-servers priority 1 server 21.22.23.220 key ***** timeout 5"

MDS Mgmt 1.2.3.4

MDS eth1 21.22.13.200

[Expert@MDS:0]# ip r

default via 1.2.3.1 dev Mgmt proto 7

21.22.23.0/24 via 21.22.13.1 dev eth1 proto 7

 

After applying the hotfix, the radius traffic goes out through the Mgmt interface. (Trying to access to Smartconsole)

EDIT: The traffic goes out through the right interface, eth1 but with the IP of the mgmt interface.

[Expert@MDS:0]# tcpdump -nni any host 21.22.23.220

IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS

IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS

IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS

 

But when accesing to SSH(TACACS port) follows the right route.

[Expert@MDS:0]# tcpdump -nni any host 21.22.23.220

IP 21.22.13.200.54379 > 21.22.23.220.49 

IP 21.22.23.220.49 > 21.22.13.200.54379 

IP 21.22.13.200.54379 > 21.22.23.220.49 

 

Any ideas what could be happening? How does the Smartconsole login works that trows the conection via Mgmt and not by the interface that the static route indicates?

 

Every idea is welcome!

 

 

 

 

 

0 Kudos
9 Replies
the_rock
Legend
Legend

Hm, thats really unfortunate. Just a suggestion, any idea you can remove it and test again? If that works, then you know 100% it was indeed the fix they provided. At that point, TAC would need to investigate further as to why. Based on what you posted, seems like you did an excellent job in figuring out whats going on.

Ok, I know this may sound silly what I will say now, but would you mind confirming nothing changed as far as routing/topology AFTER applying that fix?

Andy

0 Kudos
Devilmac
Explorer

Hello, thanks for the help

No routing/topology has been changed. And yes, uninstalling hotfix solves the issue. 

0 Kudos
the_rock
Legend
Legend

Ok, so that clearly 100% tells us its hotfix issue, so sounds like TAC case would be needed to investigate it further. Sorry, wish I could give any other suggestions, but cant think of any at this time. They may suggest debugs when issue is there, but Im not so sure those would tell you anything, as it does not appear there is specific process thats broken, it simply takes wrong path to get where its going.

0 Kudos
Lesley
Leader Leader
Leader

Hello,

Did you now installed Jumbo take 176 or 180? The reason I ask this is because I cannot find take 176 anymore maybe it has been pulled offline? Issue started after take 176 or 180? 

 

Second what I see is that you TCPdump on ANY interface. So there is no way for me to see what routing it takes. Because it can be either MGMT or eth1. 

If you want to be sure regarding routing capture with interface filter:

 tcpdump -nni eth1 host 21.22.23.220

 tcpdump -nni Mgmt host 21.22.23.220

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Devilmac
Explorer

Sorry, not 176... we tried both 173 and 180. Both of the times uninstalling reverting the hotfix solved the issue.

 

For SSH Athentication, traffic goes through eth1 

[Expert@MDS:0]# tcpdump -nni eth1 host 21.22.23.220

IP 21.22.13.200.54379 > 21.22.23.220.49 

IP 21.22.23.220.49 > 21.22.13.200.54379 

IP 21.22.13.200.54379 > 21.22.23.220.49 

 

But here comes the fancy traffic, for Smartconsole login traffic, 

The inital traffic goes to the Tacacs Server through eth1 but with the Mgmt IP

[Expert@MDS:0]# tcpdump -nni eth1 host 21.22.23.220

IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS

 

Maybe is taking the IP defined in the /etc/hosts?

 

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Radius has the concept of a NAS-IP have you defined this in your GAiA config?

CCSM R77/R80/ELITE
0 Kudos
Devilmac
Explorer

Hello! 

Chris, NAS IP description seems to fit perfectly with out problem. But after i have confiured it with the desired interface. I am having the same behauviour, the request goes with the hostname ip.

0 Kudos
Devilmac
Explorer

Hello,

Doyou know if the NAS IP defined work for TACACS authentication?

0 Kudos
D_W
Advisor

Maybe same issue like here https://community.checkpoint.com/t5/Security-Gateways/Breaking-Gaia-RADIUS-Change-in-R81-10-T79/m-p/... .

try to remove the radius setting and set it again.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events