<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MS NAP with Cisco switch 3750 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622535#M249260</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to implement 802.1X authentication on MS NAP (Windows 2008 r2) with access switch WS-C3750-48TS-E (C3750 Software (C3750-IPSERVICES-M), Version 12.2(50)SE3).&lt;/P&gt;&lt;P&gt;I am using dynamic VLAN assignments, like guest VLAN, restricted(critical) VLAN, unauthorized VLAN for wired clients.This works flawlessly.&lt;/P&gt;&lt;P&gt;I want to use only one SSID for wireless clients and the same dynamic VLAN assignments. Is it possible to use "authentication host-mode multi-auth" mode for configuring switch port with connected Cisco AP 1242G on it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;description Cisco 1242G AP&lt;/P&gt;&lt;P&gt; switchport access vlan 2223&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 998&lt;/P&gt;&lt;P&gt; authentication event fail retry 1 action authorize vlan 2226&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2227&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2224&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate 300&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout quiet-period 10&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 1&lt;/P&gt;&lt;P&gt; dot1x max-reauth-req 1&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to enable 802.1X auth on the AP or it has to be pass-through for wireless clients ? Is this port configuration consistent ?&lt;/P&gt;&lt;P&gt;As far I managed to authenticate the AP via MAB as a RADIUS client, but no wireless clients has been authenticated.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:55:16 GMT</pubDate>
    <dc:creator>Ivaylo Terziyski</dc:creator>
    <dc:date>2019-03-11T00:55:16Z</dc:date>
    <item>
      <title>MS NAP with Cisco switch 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622535#M249260</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to implement 802.1X authentication on MS NAP (Windows 2008 r2) with access switch WS-C3750-48TS-E (C3750 Software (C3750-IPSERVICES-M), Version 12.2(50)SE3).&lt;/P&gt;&lt;P&gt;I am using dynamic VLAN assignments, like guest VLAN, restricted(critical) VLAN, unauthorized VLAN for wired clients.This works flawlessly.&lt;/P&gt;&lt;P&gt;I want to use only one SSID for wireless clients and the same dynamic VLAN assignments. Is it possible to use "authentication host-mode multi-auth" mode for configuring switch port with connected Cisco AP 1242G on it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;description Cisco 1242G AP&lt;/P&gt;&lt;P&gt; switchport access vlan 2223&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 998&lt;/P&gt;&lt;P&gt; authentication event fail retry 1 action authorize vlan 2226&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 2227&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 2224&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate 300&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout quiet-period 10&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 1&lt;/P&gt;&lt;P&gt; dot1x max-reauth-req 1&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I have to enable 802.1X auth on the AP or it has to be pass-through for wireless clients ? Is this port configuration consistent ?&lt;/P&gt;&lt;P&gt;As far I managed to authenticate the AP via MAB as a RADIUS client, but no wireless clients has been authenticated.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622535#M249260</guid>
      <dc:creator>Ivaylo Terziyski</dc:creator>
      <dc:date>2019-03-11T00:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: MS NAP with Cisco switch 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622536#M249264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope I find you well. Can we proceed with the issue I had described ?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 21:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622536#M249264</guid>
      <dc:creator>Ivaylo Terziyski</dc:creator>
      <dc:date>2011-04-06T21:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: MS NAP with Cisco switch 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622537#M249271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;At least could anybody answer if the configuration on Cisco switch port is correct for connectiong Cisco AP 1242G to it.&lt;/P&gt;&lt;P&gt;Should the port be configured as access port or it should be trunk port ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 10:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ms-nap-with-cisco-switch-3750/m-p/1622537#M249271</guid>
      <dc:creator>Ivaylo Terziyski</dc:creator>
      <dc:date>2011-05-05T10:05:33Z</dc:date>
    </item>
  </channel>
</rss>

