<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dot1x Guest Vlan / Auth Fail Vlan Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134322#M147082</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your recommendations - looks like we're going to upgrade to cat4500e-entservicesk9-mz.122-53.SG4 and hopefully that'll resolve our issues.&amp;nbsp; I'll post an update afterwards to let everyone know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Nov 2012 16:12:57 GMT</pubDate>
    <dc:creator>Brian Saunders</dc:creator>
    <dc:date>2012-11-15T16:12:57Z</dc:date>
    <item>
      <title>Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134320#M147080</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring dot1x on our access layer switch-ports and am having some issues with devices that fail authentication.&amp;nbsp; This is the current configuration on the switch-port:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;switchport mode access&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;switchport voice vlan 38&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x mac-auth-bypass&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x pae authenticator&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x port-control auto&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x host-mode multi-domain&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x timeout server-timeout 10&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x timeout reauth-period server&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x timeout tx-period 10&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x timeout supp-timeout 3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x max-req 3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x max-reauth-req 3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x reauthentication&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x critical&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x critical recovery action reinitialize&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x auth-fail vlan 7&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x guest-vlan 7&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;dot1x critical vlan 36&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt;spanning-tree bpduguard enable&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 8pt; "&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When a non-employee connects they go through the authentication process and eventually fail dot1x and mab and get placed into the designated guest vlan 7.&amp;nbsp; If you do a "show int gx/x status" on that switch-port it shows them connected and in that vlan 7.&amp;nbsp; If you do a "show dot1x int gx/x details" it also shows the port as authorized (By Guest-Vlan) and the vlan policy is 7.&amp;nbsp; The problem is the user never gets a valid ip address - they just receive a 169.x.x.x.&amp;nbsp; Anyone have any experience with this type of issues or have any recommendations?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Brian&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134320#M147080</guid>
      <dc:creator>Brian Saunders</dc:creator>
      <dc:date>2019-03-11T02:47:13Z</dc:date>
    </item>
    <item>
      <title>Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134321#M147081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;- First off, your switch commands tell me you are using an old software on your switch, you should upgrade it firstly, there has been many bug fixed and enhancements to dot1x/mab in recent releases&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Your problem is probably that your guest dhcp client is timing out before you are done with dot1x and mab, susally adjusting tx-period to a lower number could help the time it takes before you reach the guest vlan, but could also have an impact on your machines that are running dot1x, you would have to try some different values. Also using Windows XP SP3 or Windows 7, helps as well on your dot1x machines, and finally using AnyConnect NAM supplicant will make it work fine without having problems when adjusting dot1x timers on your switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- With the new software i would go with default timers, maybe change tx-period to 5 secs, and then use the "authentication order mab dot1x" and "authentication priority mab dot1x", also having your guest vlan as your default vlan, will usually also solve the problem of guests having to do a new dhcp reqeust once aauthorized, however you could run into problems with stuff you wan't to use mab on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2012 01:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134321#M147081</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-11-15T01:08:17Z</dc:date>
    </item>
    <item>
      <title>Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134322#M147082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your recommendations - looks like we're going to upgrade to cat4500e-entservicesk9-mz.122-53.SG4 and hopefully that'll resolve our issues.&amp;nbsp; I'll post an update afterwards to let everyone know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Nov 2012 16:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134322#M147082</guid>
      <dc:creator>Brian Saunders</dc:creator>
      <dc:date>2012-11-15T16:12:57Z</dc:date>
    </item>
    <item>
      <title>Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134323#M147083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After upgrading to cat4500e-entservicesk9-mz.122-53.SG4 all dot1x parameters worked fine!&amp;nbsp; Thanks for your assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 18:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134323#M147083</guid>
      <dc:creator>Brian Saunders</dc:creator>
      <dc:date>2012-11-20T18:50:24Z</dc:date>
    </item>
    <item>
      <title>Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134324#M147084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats great, good luck with your dot1x setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2012 19:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/2134324#M147084</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-11-20T19:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x Guest Vlan / Auth Fail Vlan Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/3689992#M147085</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I Configure mac authentication bypass with NPS server and its working if I add mac-address in active directory.&amp;nbsp; But for Unknown devices ports are still going error-disable state 9(Orange) .&amp;nbsp; instead it should go in guest vlan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please see my configuration and let me know if I am missing anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa authentication dot1x default group radius&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa authorization network deafult group radius&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa&amp;nbsp; accounting dot1x default start-stop group radius&amp;nbsp; &amp;nbsp;(i dont know the purpose of this command)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;dot1x system-auth-control&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Interface G1/0/3&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;authentication event fail action authorize vlan 10&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;authentication host-mode multi-auth&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;authentication order mab&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thats all I configure , basically i just to want to use mac-address from NPS to allocate vlans and If it fails then switch just assign Guest Vlan.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thanks&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 19:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-guest-vlan-auth-fail-vlan-issues/m-p/3689992#M147085</guid>
      <dc:creator>ITexpert</dc:creator>
      <dc:date>2018-08-16T19:43:29Z</dc:date>
    </item>
  </channel>
</rss>

