<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ESW 520 802.1x MAB authentication problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/esw-520-802-1x-mab-authentication-problem/m-p/1988485#M180536</link>
    <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I am having problem with 802.1x MAB authentication on ESW 520 switch, the authentication server is ACS 5.3.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The Authentication method on ESW is 802.1x &amp;amp; MAC, and Host Authentication mode is Multi Session. When i plug ip phone it never authenticate the phone, and on ACS I get following error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Radius authentication failed for USER: aa1effbb8fd4&amp;nbsp; MAC: aa-1E-FF-bb-8F-D4&amp;nbsp; AUTHTYPE:&amp;nbsp; Radius authentication failed&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P id="AUTOGENBOOKMARK_11" style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;RADIUS Status:Authentication failed&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;A href="https://172.16.4.225/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=11509+Access+Service+does+not+allow+any+EAP+protocols&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681; text-decoration: none;" target="_self"&gt;11509 Access Service does not allow any EAP protocols&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;------&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;15012&amp;nbsp; Selected Access Service - MAB&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11507&amp;nbsp; Extracted EAP-Response/Identity&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11509&amp;nbsp; Access Service does not allow any EAP protocols&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11504&amp;nbsp; Prepared EAP-Failure&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11003&amp;nbsp; Returned RADIUS Access-Reject&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;For that Access Service I have configured only Host Lookup.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The same ACS configuration is working perfectly on Catalyst 3560G switche.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0in 0in 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;It seems that ESW switch is not telling ACS that authentication is going to be by MAC address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Do you have any idea what can be the problem.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:21:13 GMT</pubDate>
    <dc:creator>ngtransge</dc:creator>
    <dc:date>2019-03-11T02:21:13Z</dc:date>
    <item>
      <title>ESW 520 802.1x MAB authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/esw-520-802-1x-mab-authentication-problem/m-p/1988485#M180536</link>
      <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I am having problem with 802.1x MAB authentication on ESW 520 switch, the authentication server is ACS 5.3.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The Authentication method on ESW is 802.1x &amp;amp; MAC, and Host Authentication mode is Multi Session. When i plug ip phone it never authenticate the phone, and on ACS I get following error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Radius authentication failed for USER: aa1effbb8fd4&amp;nbsp; MAC: aa-1E-FF-bb-8F-D4&amp;nbsp; AUTHTYPE:&amp;nbsp; Radius authentication failed&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P id="AUTOGENBOOKMARK_11" style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;RADIUS Status:Authentication failed&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;A href="https://172.16.4.225/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Facsadmin%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=11509+Access+Service+does+not+allow+any+EAP+protocols&amp;amp;__locale=en_US&amp;amp;iportalID=TKNENRBYE&amp;amp;__masterpage=false&amp;amp;__newWindow=false" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681; text-decoration: none;" target="_self"&gt;11509 Access Service does not allow any EAP protocols&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;------&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;15012&amp;nbsp; Selected Access Service - MAB&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11507&amp;nbsp; Extracted EAP-Response/Identity&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11509&amp;nbsp; Access Service does not allow any EAP protocols&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11504&amp;nbsp; Prepared EAP-Failure&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;11003&amp;nbsp; Returned RADIUS Access-Reject&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;For that Access Service I have configured only Host Lookup.&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The same ACS configuration is working perfectly on Catalyst 3560G switche.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; margin: 0in 0in 0.0001pt; font-family: Arial, verdana, sans-serif;"&gt;It seems that ESW switch is not telling ACS that authentication is going to be by MAC address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Do you have any idea what can be the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/esw-520-802-1x-mab-authentication-problem/m-p/1988485#M180536</guid>
      <dc:creator>ngtransge</dc:creator>
      <dc:date>2019-03-11T02:21:13Z</dc:date>
    </item>
    <item>
      <title>ESW 520 802.1x MAB authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/esw-520-802-1x-mab-authentication-problem/m-p/1988486#M180538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you hitting the same selection rule? Also is "mab eap" configured globally on the switch, or on the port itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also can you post the port configuration and the show ver of the ESW?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Jul 2012 21:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/esw-520-802-1x-mab-authentication-problem/m-p/1988486#M180538</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-28T21:07:39Z</dc:date>
    </item>
  </channel>
</rss>

