<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius authentication issue: Switch is not even communicating wi in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403990#M170285</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish it was that simple as a mismatched shared-secret.&amp;nbsp; The problem is that the switch isn't even sending any packets out to the radius server AT ALL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Nov 2013 21:10:20 GMT</pubDate>
    <dc:creator>vincehgov</dc:creator>
    <dc:date>2013-11-01T21:10:20Z</dc:date>
    <item>
      <title>Radius authentication issue: Switch is not even communicating with radius server</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403987#M170272</link>
      <description>&lt;P&gt;I'm having a strange issue.&amp;nbsp; I'm running a 3560 8 port switch with &lt;SPAN style="font-size: 10pt;"&gt;c3560-ipbasek9-mz.122-58.SE2.bin.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the relevant config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;interface Vlan140&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; ip address 172.20.40.18 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ip route 0.0.0.0 0.0.0.0 172.20.40.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;aaa new-model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;aaa group server radius RADIUSGROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; server name RADIUS-SERVER1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;aaa authentication login default group RADIUSGROUP local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;radius server RADIUS-SERVER1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; address ipv4 172.20.1.2 auth-port 1812 acct-port 1813&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; key 7 xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping the radius server from the switch so there is L3 connectivity.&amp;nbsp; However, when I try to login using my radius credentials, I get:&lt;/P&gt;&lt;P&gt;Request timed out. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;00:58:35: RADIUS(00000014): Request timed out&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;00:58:35: RADIUS: No response from (172.20.1.2:1812,1813) for id 1645/14&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;00:58:35: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;00:58:35: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response; FAIL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A packet capture shows that pings go across, but I don't see any packets being sent at all for the radius authentication attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not running any VRFs or packet filter ACLs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403987#M170272</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2019-03-11T04:03:29Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403988#M170274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way, I forgot to mention that I've tried it with the "ip radius source-interface" of the vlan interface but still no game.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 17:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403988#M170274</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2013-11-01T17:00:15Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403989#M170277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What radius server are you running? Could you please verify the shared-secret key on server and switch side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 20:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403989#M170277</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-11-01T20:48:19Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403990#M170285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish it was that simple as a mismatched shared-secret.&amp;nbsp; The problem is that the switch isn't even sending any packets out to the radius server AT ALL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 21:10:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403990#M170285</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2013-11-01T21:10:20Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403991#M170307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;What radius server are you using? Some radius servers (Windows for example) do not use port 1812 and 1813 for communication, but 1645 and 1646 instead.&lt;/P&gt;&lt;P&gt;Could be worth checking out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Dal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Nov 2013 09:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403991#M170307</guid>
      <dc:creator>dal</dc:creator>
      <dc:date>2013-11-02T09:38:00Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403992#M170319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry guys, I forgot the name of the radius server.&amp;nbsp; However, I want to focus on why there is no traffic coming out of the switch when it is attempting to communicate with the radius server.&amp;nbsp; I don't see any packets coming out of the switch destined for the radius server in the first place.&amp;nbsp; The radius server works when I configure it on other switches.&amp;nbsp; I used the exact same configuration on all the switches.&amp;nbsp; They are the same model with the same firmware.&amp;nbsp; I checksummed the firmware and it is good.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Nov 2013 16:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403992#M170319</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2013-11-02T16:20:10Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403993#M170333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are you trying to achieve? Do you want to use radius for managment login into the switch?&lt;/P&gt;&lt;P&gt;If so, I think you must add this line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group &lt;SPAN style="font-size: 10pt;"&gt;RADIUSGROUP &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;local&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Nov 2013 23:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403993#M170333</guid>
      <dc:creator>dal</dc:creator>
      <dc:date>2013-11-02T23:09:38Z</dc:date>
    </item>
    <item>
      <title>Radius authentication issue: Switch is not even communicating wi</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403994#M170346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, yes, I have that line in there as well.&amp;nbsp; I'm trying to ssh into the switch and authenticate using radius.&amp;nbsp; I am able to SSH in, but when I attempt to authenticate, it doesn't look like the switch is communicating with the radius server at all.&amp;nbsp; A packet capture shows that there are no radius traffic.&amp;nbsp; It is really strange and probably one of those rare issues.&amp;nbsp; I've set up dozens of switch like this and never had any problems before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 23:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-issue-switch-is-not-even-communicating/m-p/2403994#M170346</guid>
      <dc:creator>vincehgov</dc:creator>
      <dc:date>2013-11-06T23:01:58Z</dc:date>
    </item>
  </channel>
</rss>

