Friday, 2014-05-09

*** coolacid has quit (Ping timeout: 252 seconds)01:50
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid01:52
*** coolacid has quit (Ping timeout: 252 seconds)04:11
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid04:13
*** coolacid has quit (Ping timeout: 252 seconds)04:30
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid04:50
*** Qasker has quit (Ping timeout: 252 seconds)06:57
*** Qasker (ask@gateway/shell/elitebnc/session) has joined #wikid06:57
*** Qasker has quit (Changing host)06:57
*** Qasker (ask@gateway/shell/elitebnc/x-lvsllogjfcftssoe) has joined #wikid06:57
*** coolacid has quit (Ping timeout: 258 seconds)09:06
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid09:14
*** coolacid has quit (Ping timeout: 258 seconds)09:33
*** coolacid (~CoolAcid@unaffiliated/coolacid) has joined #wikid09:36
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid13:07
*** nowen has quit (Quit: Leaving.)14:28
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid14:44
*** nowen has quit (Ping timeout: 252 seconds)17:09
*** nowen (~nowen@99-174-92-191.lightspeed.tukrga.sbcglobal.net) has joined #wikid17:25
*** mark____ (8f74fa7d@gateway/web/freenode/ip.143.116.250.125) has joined #wikid17:40
mark____Hello everyone17:41
nowenHi mark____17:41
mark____can you guess why i am here17:41
noweni hope it's something good17:41
mark____so we are working on getting our new domain to work17:41
mark____its not17:42
nowenok17:42
nowenlet me check the dns17:42
mark____we have setup the network clients in the domain pointing to our virtual Ip's17:42
mark____no that part works17:42
nowenok17:42
mark____it is the radius authetnication piece not working17:43
mark____so i register a new user with no issues17:43
mark____go to the juniper login page17:43
mark____enter username and 2FA code17:43
mark____and for some reason on the wikid side it keeps trying to reach back to the other domain17:43
nowenis the IP different for the new network client?17:44
nowenhmm  - you already said it's a virtual IP17:44
mark____yes we created two virtual ip's on the two juniper devices it could hit17:45
mark____and we see it hitting17:45
mark____and when it hits it shows the right domain17:45
mark____but when wikid tries to authenticate it is trying to authenticate to the wrong ip not using the virtual IP17:46
nowenif you run 'tcpdump port radius' on the WiKID server does it show the virtual IP?17:47
mark____i sent you what we are seeing in the logs via encrypted email and how we have it configured17:49
mark____Let me get someone to run that for me17:49
nowenok17:50
nowenthe 253 IP is the virtual IP?17:50
mark____no it is not17:51
mark____and that is what has us stumped17:51
nowenhuh17:54
nowenI'm guessing then that the juniper is not sending the traffic from the virtual ip17:54
mark____okay let me talk to our network guy17:58
nowenthe tcpdump would show that17:58
nowenI got to make a phone call - biab18:02
mark____ok18:12
mark____working on the tcpdump18:12
nowenok18:12
nowencall was delayed18:12
mark____[root@hsvwikidp1 ~]# tcpdump port radius tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes  0 packets captured 0 packets received by filter 0 packets dropped by kernel18:36
mark____i see nothing useful there Nick?18:36
mark____Nick are you still here18:42
mark____do you know the port it is using18:42
nowensorry - back18:56
nowenyeah - did you try to login  while doing it?18:57
mark____no19:14
mark____i can coordinate that though19:14
nowenstill there should be a lot of radius traffic on there, right?19:14
mark____probably not19:14
mark____right now only a few employees using it19:15
mark____would say maybe 10 log event per day19:15
nowenok19:15
mark____so i need to have them run it when i am trying to login19:15
nowenyes19:16
mark____Our network guy thinks it is something on the Juniper side19:16
mark____and he is waiting to hear back form them19:16
mark____from19:16
mark____i just wanted to make sure it was not something on the wikid side is all19:16
nowenwell, I have seen this before - radius relies on the IP of the radius client in it's logic, so that's what I suspect.  could be other things too19:21
mark____okay we will keep troubleshooting it19:42
nowenok19:42
nowenlet me know19:42
mark____ok19:45
*** mark____ has quit (Ping timeout: 240 seconds)21:42
*** nowen has quit (Quit: Leaving.)21:51

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!