<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PXE boot with dot1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167641#M160556</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever get your issue figured out?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 05:13:12 GMT</pubDate>
    <dc:creator>Travis Stroebele</dc:creator>
    <dc:date>2013-11-08T05:13:12Z</dc:date>
    <item>
      <title>PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167639#M160544</link>
      <description>&lt;P&gt;Hi guys.&lt;BR /&gt;&lt;BR /&gt; We have dot1x ISE BASED. Solution running for a customer. Everything seems to work fine. Now they have a new requirement for clients with PXE boot. These are the laptops with no image on them. Atleast when they connect to the network. These laptops connect behind the ip phone as customer is using VoIP solution.&lt;BR /&gt;&lt;BR /&gt;The problem I am facing is that when is configure dot1x authentication order dot1x mab. The PXE boot fails as it times out. If I configure dot1x authentication order mab dot1x. The PXE boot works fine. But in logs I end up with unnecessary logs that ISE tries to authenticate phone with mab but failed then tried dot1x. This means unnecessary logs and traffic in network.&lt;BR /&gt;&lt;BR /&gt;Which timer or what should I configure so that the PXE boot works fine and phone uses dot1x ..&lt;BR /&gt;&lt;BR /&gt;Has anyone seen that or any ideas ?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167639#M160544</guid>
      <dc:creator>Amit Singh2000</dc:creator>
      <dc:date>2019-03-11T03:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167640#M160551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your client use WinPE for deployment? I have this same issue right now with PXE timing out, and we're working on it this way:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/972831" rel="nofollow"&gt;http://support.microsoft.com/kb/972831&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't found any way to tweak the timers to help this problem, but I'd be interested to know if anyone else has.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 17:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167640#M160551</guid>
      <dc:creator>ryan.lambert</dc:creator>
      <dc:date>2013-04-18T17:51:24Z</dc:date>
    </item>
    <item>
      <title>PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167641#M160556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever get your issue figured out?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 05:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167641#M160556</guid>
      <dc:creator>Travis Stroebele</dc:creator>
      <dc:date>2013-11-08T05:13:12Z</dc:date>
    </item>
    <item>
      <title>PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167642#M160564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We got PXE boot working with authentication order dot1x mab by setting &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the switchports (after a lot of experimentation)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phaon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Nov 2013 23:20:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167642#M160564</guid>
      <dc:creator>phaon.reid</dc:creator>
      <dc:date>2013-11-10T23:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167643#M160567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything working for PXE. We are about to venture down this road. Just curious how you are handling pcs out of the box?&lt;BR /&gt;&lt;BR /&gt;Auth-fail vlan? Guest vlan? Dedicate ports for initial imaging??&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 02:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167643#M160567</guid>
      <dc:creator>Tedwheat53</dc:creator>
      <dc:date>2014-01-14T02:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167644#M160569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might even try something like this on your swichport config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 5 (I usually use somewhere between 5-10 for this setting)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow MAB to happen first.&amp;nbsp; Just make sure your endpoint doesn't match another policy and your default authorization policy is set to deny access.&amp;nbsp; This should work unless your default is being used to default to a central web auth or something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wouldn't advise dropping the "dot1x timeout tx-period" much below 5 as you may cause timeouts on your 802.1x configured supplicants and unnecessary retries.&amp;nbsp; Just my opinion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 03:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167644#M160569</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-01-14T03:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167645#M160572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's sort of how I think I'm going to do it. Going to use dot1x open. Oh pxe booting.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 04:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167645#M160572</guid>
      <dc:creator>Tedwheat53</dc:creator>
      <dc:date>2014-01-14T04:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167646#M160574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had problems with IAB (critical auth) when setting the following configuration:&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;/P&gt;&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I might be doing something wrong but as I understand it when critical auth recovery occurs it reauths using the first method and then stops. The drama with this is that all 802.1x clients must manually connect and reconnect to the port or they are subject to MAB..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 22:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/2167646#M160574</guid>
      <dc:creator>Stephen McBride</dc:creator>
      <dc:date>2014-01-14T22:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: PXE boot with dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/3867287#M160576</link>
      <description>&lt;P&gt;&lt;SPAN&gt;dot1x timeout tx-period 1 helped me!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dot1x timeout tx-period 5 was also working but takes a little bit more time.....&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 10:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pxe-boot-with-dot1x/m-p/3867287#M160576</guid>
      <dc:creator>mchammer7</dc:creator>
      <dc:date>2019-06-04T10:32:20Z</dc:date>
    </item>
  </channel>
</rss>

