<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dot1x server dead if client is unknown in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-server-dead-if-client-is-unknown/m-p/1747506#M223622</link>
    <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Situation&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured dot1x with ACS 5.2 on a WS-C3750X-24P (12.2(58)SE1). I configured EAP-TLS and MAB for a port with the following configurations. It looks like this: access port -&amp;gt; ip phone -&amp;gt; client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;General Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; switchport access vlan 1421&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="border-collapse: collapse;"&gt;Port Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; switchport access vlan x&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="border-collapse: collapse;"&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a know client (either client certificates installed or MAC address configured on ACS 5.2), everything works fine. As soon as a unknown client connects, the radius servers are marked as dead. As soon as this happens, the know clients fail to connect too:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.044 METDST: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.044 METDST: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.633 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.642 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.709 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.967 METDST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/3, changed state to up&lt;/P&gt;&lt;P&gt;Oct 18 14:52:59.974 METDST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/3, changed state to up&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %AUTHMGR-5-START: Starting 'dot1x' for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID 0A00050B0000001E19DB9EE8&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %DOT1X-5-FAIL: Authentication failed for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (0023.7d10.9a6f) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:05.250 METDST: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:05.250 METDST: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know if I configured something wrong (see config above) or if there is a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:29:22 GMT</pubDate>
    <dc:creator>Dominic Stalder (old profile)</dc:creator>
    <dc:date>2019-03-11T01:29:22Z</dc:date>
    <item>
      <title>Dot1x server dead if client is unknown</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-server-dead-if-client-is-unknown/m-p/1747506#M223622</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Situation&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured dot1x with ACS 5.2 on a WS-C3750X-24P (12.2(58)SE1). I configured EAP-TLS and MAB for a port with the following configurations. It looks like this: access port -&amp;gt; ip phone -&amp;gt; client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;General Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; switchport access vlan 1421&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="border-collapse: collapse;"&gt;Port Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; switchport access vlan x&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2329&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="border-collapse: collapse;"&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a know client (either client certificates installed or MAC address configured on ACS 5.2), everything works fine. As soon as a unknown client connects, the radius servers are marked as dead. As soon as this happens, the know clients fail to connect too:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.013 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.044 METDST: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.044 METDST: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (Unknown MAC) on Interface Gi1/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.633 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.642 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:57.709 METDST: %AUTHMGR-5-VLANASSIGN: VLAN 2329 assigned to Interface Gi1/0/3 AuditSessionID Unassigned (xxx)&lt;/P&gt;&lt;P&gt;Oct 18 14:52:58.967 METDST: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/3, changed state to up&lt;/P&gt;&lt;P&gt;Oct 18 14:52:59.974 METDST: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/3, changed state to up&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %AUTHMGR-5-START: Starting 'dot1x' for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID 0A00050B0000001E19DB9EE8&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %DOT1X-5-FAIL: Authentication failed for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:04.218 METDST: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (0023.7d10.9a6f) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:05.250 METDST: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;Oct 18 14:53:05.250 METDST: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (xxxx.yyyy.zzzz) on Interface Gi4/0/3 AuditSessionID xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know if I configured something wrong (see config above) or if there is a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-server-dead-if-client-is-unknown/m-p/1747506#M223622</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2019-03-11T01:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x server dead if client is unknown</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-server-dead-if-client-is-unknown/m-p/1747507#M223624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the problem, the ACS configuration was wrong, I wrongly configured "If user not found" to Drop instead of Reject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Oct 2011 08:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-server-dead-if-client-is-unknown/m-p/1747507#M223624</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2011-10-26T08:46:34Z</dc:date>
    </item>
  </channel>
</rss>

