<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with radius authentication on catalyst 2960 in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/problem-with-radius-authentication-on-catalyst-2960/m-p/2194056#M212786</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean wired 802.1X ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-top: solid windowtext 1.0pt; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: none; padding: 1.0pt 0in 1.0pt 0in; background: #E6E6E6; margin-left: 14.2pt; margin-right: 0in;"&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;dot1x system-auth-control&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 6 on-for-login-auth&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server vsa send authentication&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa authentication dot1x default group RADGR&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa authorization network default group RADGR&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa accounting dot1x default start-stop group RADGR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-top: solid windowtext 1.0pt; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: none; padding: 1.0pt 0in 1.0pt 0in; background: #E6E6E6; margin-left: 14.2pt; margin-right: 0in;"&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;int F0/x&lt;/P&gt;switchport mode access&lt;BR /&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;authentication host-mode multi-domain&lt;/P&gt;authentication port-control auto&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;dot1x pae authenticator &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Feb 2013 16:58:09 GMT</pubDate>
    <dc:creator>Peter Koltl</dc:creator>
    <dc:date>2013-02-27T16:58:09Z</dc:date>
    <item>
      <title>Problem with radius authentication on catalyst 2960</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/problem-with-radius-authentication-on-catalyst-2960/m-p/2194055#M212785</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem with radius authentication on catalyst 2960 with freeradius as radius-server. The Catalyst is behind a HP5412zl layer3-switch. The rest of the network are hp-layer2 switches, which do radius authentication to the same radius server. The ios on the catalyst is c2960-lanbasek9-mz.150-1.SE3.&lt;/P&gt;&lt;P&gt; Appaerntly there are no requests made to the radius-server, since I dont see any requests coming in. Port 0/7 is voice port with laptop behind , /port 0/8 access-port with laptop directly connected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 16&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mls qos trust device cisco-phone&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/8&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 1-3&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; switchport nonegotiate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; ip address 10.104.253.5 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip default-gateway 10.104.253.1&lt;/P&gt;&lt;P&gt;radius server radius&lt;/P&gt;&lt;P&gt; address ipv4 10.104.254.175 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt; key 7 045802150C2E&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the logs : (debug authentication, debug dotx11 after enabling authentication port-control auto on fa 0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Removed the default method from the interface&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Disabling dot1x in switch shim&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 0 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Client delete *ALL* from platform (2)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Ignoring delete *ALL* - previous pending&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Queued subblock to be destroyed&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Created Auth Manager SWSB (0x01EB4058)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Set port control (3-&amp;gt;2)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8) Enabling dot1x in switch shim&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.588: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Queued START&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Received internal event DELETE ALL&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Stopped 'inactivity' timer for client 0026.b99a.8f2f&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Signalling "pre" delete for client 0026.b99a.8f2f&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT: Enter auth_mgr_idc_client_deleted&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT: Enter auth_mgr_idc_remove_record&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-SYNC (Fa0/8) Syncing delete for context (0026.b99a.8f2f)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Sending DELETE to&amp;nbsp; (handle 0x7E00000B)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Freeing AAA-ID 0x0000001F for 0026.b99a.8f2f&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.596: AUTH-EVENT (Fa0/8) Signalling "post" delete for client 0026.b99a.8f2f in domain DATA&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Setting vlan to 0 on DATA Vlan&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Unauthorizing interface in shim&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) set host access to ask on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) set host access to ask on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Get domain: Unknown MAC: 0026.b99a.8f2f&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Setting vlan to 0 on DATA Vlan&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Unauthorizing interface in shim&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) set host access to ask on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) set host access to ask on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8)&amp;nbsp; host access set to 1 on FastEthernet0/8&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Get domain: Unknown MAC: 0026.b99a.8f2f&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Domain DATA client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Authorized client count: 0&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Freed Auth Manager context&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT: Received internal event DELETE SUBBLOCK&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT: Destroying Auth Manager SWSB (0x038CE600)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT: Destroyed Auth Manager SWSB (0x038CE600)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Link UP&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.605: AUTH-EVENT (Fa0/8) Received internal event START&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.613: AUTH-EVENT (Fa0/8) Client delete *ALL* from platform (2)&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:09.613: AUTH-EVENT (Fa0/8) Ignoring delete *ALL* - ctx list empty&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:10.570: AUTH-EVENT: Stopped Auth Manager tick timer&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 1 03:19:10.603: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/8, changed state to down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody who can help me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks ,Johan&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 03:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/problem-with-radius-authentication-on-catalyst-2960/m-p/2194055#M212785</guid>
      <dc:creator>Johan Boeckx</dc:creator>
      <dc:date>2019-03-05T03:08:25Z</dc:date>
    </item>
    <item>
      <title>Problem with radius authentication on catalyst 2960</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/problem-with-radius-authentication-on-catalyst-2960/m-p/2194056#M212786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean wired 802.1X ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-top: solid windowtext 1.0pt; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: none; padding: 1.0pt 0in 1.0pt 0in; background: #E6E6E6; margin-left: 14.2pt; margin-right: 0in;"&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;dot1x system-auth-control&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 6 on-for-login-auth&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;radius-server vsa send authentication&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa authentication dot1x default group RADGR&lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa authorization network default group RADGR&amp;nbsp; &lt;/P&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;aaa accounting dot1x default start-stop group RADGR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="border-top: solid windowtext 1.0pt; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: none; padding: 1.0pt 0in 1.0pt 0in; background: #E6E6E6; margin-left: 14.2pt; margin-right: 0in;"&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;int F0/x&lt;/P&gt;switchport mode access&lt;BR /&gt;&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;authentication host-mode multi-domain&lt;/P&gt;authentication port-control auto&lt;P style="margin-left: 0in; background: none repeat scroll 0% 0% #e6e6e6;"&gt;dot1x pae authenticator &lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 16:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/problem-with-radius-authentication-on-catalyst-2960/m-p/2194056#M212786</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2013-02-27T16:58:09Z</dc:date>
    </item>
  </channel>
</rss>

