<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x clients not authenticated after reload in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049449#M158400</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you will need to tell your ports what action to take when the AAA server becomes available. It knows what to do when it's dead or unavailable, but has the default setting when it is returned to service.  Likely the switch is tripping AAA dead or non-responsive for a bit during boot and its a race. You want the port to reauth when the AAA server becomes avail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2012 10:55:10 GMT</pubDate>
    <dc:creator>PAUL SHELTON</dc:creator>
    <dc:date>2012-09-24T10:55:10Z</dc:date>
    <item>
      <title>Dot1x clients not authenticated after reload</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049448#M158399</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a switch setup with dynamic vlan assignment. Everything works fine until the switch is rebooted. Then none of the pc's are authenticated anymore. I have to do a shut/no shut of all the user ports to start the re-authentication of the pc's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config I have so far. Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Global commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius &lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;aaa accounting system default start-stop group radius&lt;BR /&gt;aaa authorization exec default local if-authenticated&lt;BR /&gt;aaa authorization commands 1 default local if-authenticated&lt;BR /&gt;aaa authorization commands 15 default local if-authenticated&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;dot1x guest-vlan supplicant&lt;BR /&gt;dot1x critical eapol&lt;BR /&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646 key *****&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Interface-specific commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;switchport port-security maximum 5&lt;BR /&gt;switchport port-security&lt;BR /&gt;switchport port-security violation restrict&lt;BR /&gt;authentication event fail action authorize vlan 200&lt;BR /&gt;authentication event server dead action authorize vlan 110&lt;BR /&gt;authentication event no-response action authorize vlan 200&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;mab&lt;BR /&gt;no snmp trap link-status&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout quiet-period 3&lt;BR /&gt;dot1x timeout tx-period 3&lt;BR /&gt;dot1x max-req 1&lt;BR /&gt;storm-control broadcast level 1.00&lt;BR /&gt;storm-control multicast level 1.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;storm-control action trap&lt;BR /&gt;no cdp enable&lt;BR /&gt;no cdp tlv server-location &lt;BR /&gt;no cdp tlv app&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049448#M158399</guid>
      <dc:creator>Joris Deprouw</dc:creator>
      <dc:date>2019-03-11T02:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x clients not authenticated after reload</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049449#M158400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe you will need to tell your ports what action to take when the AAA server becomes available. It knows what to do when it's dead or unavailable, but has the default setting when it is returned to service.  Likely the switch is tripping AAA dead or non-responsive for a bit during boot and its a race. You want the port to reauth when the AAA server becomes avail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 10:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049449#M158400</guid>
      <dc:creator>PAUL SHELTON</dc:creator>
      <dc:date>2012-09-24T10:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x clients not authenticated after reload</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049450#M158401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So If I add the following line to my interface specific config it should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"authentication timer reauthenticate server"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll give it a try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 10:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049450#M158401</guid>
      <dc:creator>Joris Deprouw</dc:creator>
      <dc:date>2012-09-24T10:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x clients not authenticated after reload</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049451#M158402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication event server alive action reinitialize (or reauthenticate). It's an R word. The command is definitely an auth event command not a timer however.  Think of it as post failure recovery. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 11:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-clients-not-authenticated-after-reload/m-p/2049451#M158402</guid>
      <dc:creator>PAUL SHELTON</dc:creator>
      <dc:date>2012-09-24T11:03:36Z</dc:date>
    </item>
  </channel>
</rss>

