Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Fri Dec 01, 2023 12:52 am


Author Message
mandrei99
Post  Post subject: Junos: User 'remote' authenticated successfully but no local login-id configured  |  Posted: Mon Jan 26, 2015 12:04 pm

Joined: Tue Aug 04, 2009 9:16 am
Posts: 250

Offline
 

Junos: User 'remote' authenticated successfully but no local login-id configured

A common mistake when configuring Junos to authenticate from a radius server is to configure radius server, authentication-order, but not to define a "remtoe" account local to Junos. This "remote" user is used for Junos to map radius successfully authenticated users. Without it, the following logs appear in /var/log/messages:
Code:
Jan 26 15:57:25  R1 sshd[12941]: Connection closed by 10.1.1.54 [preauth]
Jan 26 15:57:25  R1 inetd[1175]: /usr/sbin/sshd[12941]: exited, status 255
Jan 26 15:57:27  R1 sshd[12950]: User 'remote' authenticated successfully but no local login-id configured.
Jan 26 15:57:27  R1 sshd[12948]: error: PAM: unknown user for andrei from 10.1.1.54
Jan 26 15:57:27  R1 sshd: SSHD_LOGIN_FAILED: Login failed for user 'andrei' from host '10.1.1.54'


This can be overcome if the radius server sends a vendor specific radius attribute "Juniper-Local-User-Name". More details at Juniper Networks Vendor-Specific RADIUS Attributes.

How to configure Junos radius authentication:


Code:
# set system authentication-order radius
# set system radius-server 10.1.1.2 secret "<SECRET>"
# set system authentication-order radius
# set system authentication-order password
# set system login user remote class operator


More information at Juniper KB: SRX Getting Started - Configure RADIUS





Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "Junos: User 'remote' authenticated successfully but no local login-id configured"
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. Junos - How to use loopback IP address as source for local originated packets (ssh/telnet)

admin

1

10453

Mon Jul 16, 2012 4:29 am

Harespok View the latest post

There are no new unread posts for this topic. Junos tacacs plus authentication for restricted privileges user with ping restrictions

admin

1

6098

Wed Jun 26, 2013 9:52 am

admin View the latest post

There are no new unread posts for this topic. Junos restricted user disallow "ping rapid" and "ping size" operational commands

mandrei99

0

2891

Wed Jun 26, 2013 6:02 pm

mandrei99 View the latest post

There are no new unread posts for this topic. MTR / My traceroute in Junos

mandrei99

1

7144

Mon Oct 10, 2016 5:54 am

barrel View the latest post

There are no new unread posts for this topic. Juniper - Junos 11.4R8 based Olive

mandrei99

1

5735

Tue Jun 18, 2013 5:36 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to show uncommitted changes and cancel them

mandrei99

1

37251

Wed Sep 25, 2013 7:31 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to list routing table IDs

admin

0

3650

Sat Jan 17, 2015 3:53 pm

admin View the latest post

There are no new unread posts for this topic. Juniper SRX / Junos rescue configuration is not set

mandrei99

0

8307

Mon Feb 16, 2015 11:42 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos - How to limit arguments to ping CLI command

mandrei99

1

2815

Thu Jun 27, 2013 4:04 am

admin View the latest post

There are no new unread posts for this topic. Junos: ping: invalid routing instance `RI0'

mandrei99

0

5096

Fri Jan 03, 2014 10:11 am

mandrei99 View the latest post

 

Who is online
Users browsing this forum: No registered users and 0 guests
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
cronNews News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO