Skip to main content

 

Cisco Meraki Documentation

Troubleshooting Recent 802.1X Failure Alert

Overview 

clipboard_eb00d326deeb3a7a2632fbcddbf7c4f34.png

This guide explains the Recent 802.1X Failure alert on Cisco Meraki devices and provides troubleshooting instructions for resolving RADIUS server connectivity issues on MR access point (AP) and MS switch networks. 

A node displays the Recent 802.1X Failure alert when the RADIUS testing feature is enabled and the node does not receive a reply from one or more configured RADIUS servers. The alert may indicate that the device did not receive a reply from the server due to a temporary network condition. Use the following sections to determine whether the alert reflects a temporary issue or a persistent failure. 

Understanding RADIUS testing feature

When the RADIUS testing feature is enabled, Meraki devices periodically send Access-Request messages to the configured RADIUS servers using the identity meraki_8021x_test to ensure that the RADIUS servers are reachable. All RADIUS servers are tested by every node at least once every 24 hours.

A test is considered successful when the Meraki device receives any legitimate RADIUS response from the server — Access-Accept, Access-Reject, or Access-Challenge. Nodes display the Recent 802.1X Failure alert when they do not receive a reply from one or more configured RADIUS servers within a 10-second timeout period, and when there were no successful 802.1X authentications in the last 10 minutes. If the device does not receive a reply from a RADIUS server during regular testing, but a client successfully authenticated within the last 10 minutes, the alert does not display — even if the test failed.

If a RADIUS test fails for a given node, the node will be tested again every hour until a passing result occurs. A passing result marks the server as reachable, clears the alert, and returns the node to the 24-hour testing cycle.

Adding or removing a node from a network invalidates previous tests. Changing the dashboard configuration of the RADIUS servers also invalidates previous tests.

For a wireless 802.1X configuration, the alert is generated only when the association requirement for network access is set to WPA2-Enterprise with a custom RADIUS server. The alert is not triggered for splash pages using a RADIUS server when there is an 802.1X failure.

The Transport Layer Security (TLS) version used by the MR to test RADIUS is determined by the firmware version: 

MR 26.x uses TLS 1.0 

MR 27.x uses TLS 1.2 

Environment

  • Devices: Meraki MR access points, Meraki MS switches, Meraki MX WAN appliances
  • Feature: RADIUS testing
  • Firmware: MR 26.x (uses TLS 1.0), MR 27.x (uses TLS 1.2)
  • Wireless configuration: WPA2-Enterprise with a custom RADIUS server

Configuring RADIUS testing

RADIUS testing configuration is available in the following locations, depending on the product:

MR 

Wireless > Configure > Access control > SSID (select name) > RADIUS

Enabling RADIUS testing for wireless 802.1x SSID

MS

Switching > Configure > Access policies

Configuring RADIUS servers for MS

MX

The MX does not include an option to enable or disable the RADIUS testing feature. When a RADIUS server is configured under per-port VLAN settings or wireless settings, a RADIUS test runs automatically under the conditions described in the Understanding RADIUS testing feature section.

Security & SD-WAN > Configure > Addressing & VLANs > RoutingPer-port VLAN Settings.

Configuring RADIUS servers for MX

 

Security & SD-WAN > Configure > Wireless settings

Configuring RADIUS server for an SSID in wireless MX

Troubleshooting Recent 802.1x failure alert

When you see the Recent 802.1x Failure alert, that doesn't necessarily mean the users are experiencing a problem. It may only mean that the node didn't get a reply from at least one of the configured RADIUS servers within 10 seconds.

Troubleshooting steps

MR networks

To verify if this is a widespread problem on MR networks, follow the steps below:

1. Review whether the alert has affected users or whether it may be a minor problem. Navigate to Wireless > Monitor > Overview > Network service health > RADIUS success. A result of 100% indicates that all clients successfully connected to resources that use a RADIUS server, and the alert reflects a minor issue. 

Network service health

If the result is below 100%, select RADIUS success and review the RADIUS failure reason codes. A RADIUS timeout result indicates that clients cannot connect because the server is unreachable. Continue the troubleshooting steps to determine why the server is unreachable. 

2. From the same screen, select RADIUS success, then use the RADIUS Server IP drop-down to view the servers tested by the APs. Note the server addresses. 

Selecting a RADIUS server IP for investigation

3. Navigate to Wireless > Monitor > Access points, open one of the alerting AP's page, then select the Tools tab and verify whether the AP can ping the servers:

clipboard_e44c72280c6a7024c484f5159518531cf.png

  • If pings are unsuccessful, investigate why the APs cannot reach the RADIUS server. 

  • If pings are successful, check the RADIUS server logs and investigate why the RADIUS server is not responding to the APs' RADIUS tests. 

For a more detailed explanation about how to troubleshoot RADIUS problems, refer to the RADIUS Issue Resolution Guide.

MS networks

 When you see the Recent 802.1X Failure alert on an MS switch, follow the steps below. 

1. Note the RADIUS server(s) IP addresses configured in any APs (Switching > Configure > Access policies). 

2. Navigate to Switching > Monitor > Switches, open one of the alerting switches' page, then select the Tools tab and verify whether the switch can ping the RADIUS servers.

  • If pings are unsuccessful, investigate why the switches cannot reach the RADIUS server. 
  • If pings are successful, check the RADIUS server logs and investigate why the RADIUS server is not responding to the switches' RADIUS tests. 

For a more detailed explanation about how to troubleshoot RADIUS problems, refer to the RADIUS Issue Resolution Guide.