<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x Authentication in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108144#M5482</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following config in the port:&lt;/P&gt;&lt;P&gt;#authentication open&lt;/P&gt;&lt;P&gt;#auth order dot1x&lt;/P&gt;&lt;P&gt;#auth priority dot1x&lt;/P&gt;&lt;P&gt;#dot1x pae authenticator&lt;/P&gt;&lt;P&gt;#Access-list PRE-AUTH in (allowing ICMP, DNS, etc)&lt;/P&gt;&lt;P&gt;#dot1x port-auth control auto&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 16:58:08 GMT</pubDate>
    <dc:creator>AbelBurgos5029</dc:creator>
    <dc:date>2020-06-23T16:58:08Z</dc:date>
    <item>
      <title>802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108059#M5478</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I configured a 802.1x deployment using a Cisco 9300 Switch Stack IOS 16.8.1a, Cisco ISE IOS 2.6.156 and Windows 10 workstations using windows supplicant software. The whole thing works... The supplicant is able to authenticate the user credentials, which is authenticated by the ISE against the Policy sets I created, downloading the Dacl to the switch port and granting access to the network. So the things I want to happen is happening....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the problem:&lt;/P&gt;&lt;P&gt;In order for all this to happen, I have to bring the switch port down and up (shut, no shut)... If I dont reset the switchport, the supplicant would keep trying to authenticate until it times out. It is not until I manually reset the port that it finally authenticates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on what the problem might be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 14:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108059#M5478</guid>
      <dc:creator>AbelBurgos5029</dc:creator>
      <dc:date>2020-06-23T14:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108063#M5479</link>
      <description>&lt;P&gt;Can you post the switch port configuraiton where you making shut and no shut ?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 14:57:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108063#M5479</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-06-23T14:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108144#M5482</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following config in the port:&lt;/P&gt;&lt;P&gt;#authentication open&lt;/P&gt;&lt;P&gt;#auth order dot1x&lt;/P&gt;&lt;P&gt;#auth priority dot1x&lt;/P&gt;&lt;P&gt;#dot1x pae authenticator&lt;/P&gt;&lt;P&gt;#Access-list PRE-AUTH in (allowing ICMP, DNS, etc)&lt;/P&gt;&lt;P&gt;#dot1x port-auth control auto&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 16:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108144#M5482</guid>
      <dc:creator>AbelBurgos5029</dc:creator>
      <dc:date>2020-06-23T16:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108167#M5483</link>
      <description>&lt;P&gt;Do you have aaa accounting configured?&lt;/P&gt;
&lt;P&gt;Provide your full configuration&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 17:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108167#M5483</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-06-23T17:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108185#M5484</link>
      <description>&lt;P&gt;Here is my full aaa configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; server name ______&lt;/P&gt;&lt;P&gt;aaa group server radius RADIUS-GROUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; server name ______&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login VTY group ISE local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group RADIUS-GROUP&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorizartion network default group RADIUS-GROUP&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group RADIUS-GROUP&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting command 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting command 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa login success-track-conf-time-24&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip http authentication aaa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you see something wrong... Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108185#M5484</guid>
      <dc:creator>AbelBurgos5029</dc:creator>
      <dc:date>2020-06-23T18:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108190#M5485</link>
      <description>&lt;P&gt;Add the following:-&lt;/P&gt;
&lt;PRE&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting auth-proxy default start-stop group RADIUS-GROUP&lt;BR /&gt;aaa accounting dot1x default start-stop group RADIUS-GROUP&lt;/PRE&gt;
&lt;P&gt;Check the output of the interface AFTER you have logged off the computer and ensure there is no session&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN style="font-size: 10pt;"&gt;show authentication session interface X&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108190#M5485</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-06-23T18:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108257#M5486</link>
      <description>&lt;P&gt;No luck with that. Any other ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 20:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108257#M5486</guid>
      <dc:creator>AbelBurgos5029</dc:creator>
      <dc:date>2020-06-23T20:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108272#M5487</link>
      <description>Post the output of the show command I provided of the interface when a computer has authenticated and after it has logged off.&lt;BR /&gt;&lt;BR /&gt;Provide the full configuration of the interface&lt;BR /&gt;&lt;BR /&gt;Turn on radius debug, logoff the computer and provide the output</description>
      <pubDate>Tue, 23 Jun 2020 20:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108272#M5487</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-06-23T20:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108288#M5488</link>
      <description>&lt;P&gt;I would prefer to see full interface config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run interface gi x/x&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 21:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/802-1x-authentication/m-p/4108288#M5488</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-06-23T21:06:19Z</dc:date>
    </item>
  </channel>
</rss>

