<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NEAT configuration issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896070#M259757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please have a look on the brief of CISP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ITDIT/CFN/Dispatch?act=featdesc&amp;amp;task=display&amp;amp;featureId=9434"&gt;http://tools.cisco.com/ITDIT/CFN/Dispatch?act=featdesc&amp;amp;task=display&amp;amp;featureId=9434&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my understanding, the CISP is only working on the switch to switch port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which can win the race: increasing bandwidth with new technologies VS QoS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Dec 2012 23:07:43 GMT</pubDate>
    <dc:creator>networkguy13111</dc:creator>
    <dc:date>2012-12-19T23:07:43Z</dc:date>
    <item>
      <title>NEAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896069#M259681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I´m currently setting a LAB in order to test NEAT feature. The Supplicant switch (sSW) is able to authenticate toward the Authenticator Switch (aSW).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW#sh cisp summary&lt;/P&gt;&lt;P&gt;CISP is running on the following interface(s):&lt;/P&gt;&lt;P&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fa0/8 (supplicant)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I connect a PC with X.509 certificate to the sSW, I see the EAPOL request coming from the PC to the sSW on Fa0/1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 6 23:25:12.600: dot1x-ev(Fa0/1): Role determination not required&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 6 23:25:12.600: dot1x-ev(Fa0/1): New client detected, issuing Start Request to AuthMgr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the sSW does not forward the packet to the aSW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW#sh cisp interface fastEthernet 0/1&lt;/P&gt;&lt;P&gt; CISP not enabled on specified interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need additional configuration on the port toward the PC?&lt;/P&gt;&lt;P&gt;Why the CISP is not enabled on the Fa0/1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology and config is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topolgy:&amp;nbsp; &lt;/P&gt;&lt;P&gt;PC-------------0/1|sSW|0/8--------------4/10|aSW|&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration:&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;aSW: WS-C4510R-E &lt;/P&gt;&lt;P&gt;System image file is "bootflash:cat4500e-entservicesk9-mz.150-2.SG3.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet4/10&lt;/P&gt;&lt;P&gt; description toward sSW&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 332&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; switchport voice vlan 335&lt;/P&gt;&lt;P&gt; logging event link-status&lt;/P&gt;&lt;P&gt; authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; spanning-tree portfast trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW&amp;gt; 2960&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"flash:c2960-lanbasek9-mz.150-1.SE2.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x credentials cisco&lt;/P&gt;&lt;P&gt; username cisco&lt;/P&gt;&lt;P&gt; password 0 cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;cisp enable&lt;/P&gt;&lt;P&gt;dot1x supplicant force-multicast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/8&lt;/P&gt;&lt;P&gt;description toward 4/10-aSW&lt;/P&gt;&lt;P&gt; switchport trunk native vlan 332&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; dot1x pae supplicant&lt;/P&gt;&lt;P&gt; dot1x credentials cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt;description toward PC&lt;/P&gt;&lt;P&gt; switchport access vlan 332&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh cisp interface fastEthernet 0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISP not enabled on specified interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 6 23:25:12.600: dot1x-ev(Fa0/1): Role determination not required&lt;/P&gt;&lt;P&gt;*Mar&amp;nbsp; 6 23:25:12.600: dot1x-ev(Fa0/1): New client detected, issuing Start Request to AuthMgr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW#sh cisp summary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISP is running on the following interface(s):&lt;/P&gt;&lt;P&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fa0/8 (supplicant)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW#sh cisp clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Supplicant Client Table:&lt;/P&gt;&lt;P&gt;------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&lt;/P&gt;&lt;P&gt;&amp;nbsp; ---------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0000.0c07.ac01&amp;nbsp;&amp;nbsp; 332&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0024.14af.3e09&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8cb6.4fab.c7c1&amp;nbsp;&amp;nbsp; 332&amp;nbsp;&amp;nbsp;&amp;nbsp; Vl332&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0022.9031.53ff&amp;nbsp;&amp;nbsp; 332&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp; 0024.14af.3e09&amp;nbsp;&amp;nbsp; 332&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8cb6.4fab.c7c0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; Vl1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sSW#sh cisp interface fastEthernet 0/1&lt;/P&gt;&lt;P&gt; CISP not enabled on specified interface&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896069#M259681</guid>
      <dc:creator>amin.amor</dc:creator>
      <dc:date>2019-03-11T01:58:25Z</dc:date>
    </item>
    <item>
      <title>NEAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896070#M259757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please have a look on the brief of CISP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ITDIT/CFN/Dispatch?act=featdesc&amp;amp;task=display&amp;amp;featureId=9434"&gt;http://tools.cisco.com/ITDIT/CFN/Dispatch?act=featdesc&amp;amp;task=display&amp;amp;featureId=9434&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my understanding, the CISP is only working on the switch to switch port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which can win the race: increasing bandwidth with new technologies VS QoS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2012 23:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896070#M259757</guid>
      <dc:creator>networkguy13111</dc:creator>
      <dc:date>2012-12-19T23:07:43Z</dc:date>
    </item>
    <item>
      <title>NEAT configuration issue</title>
      <link>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896071#M259847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using neat the switch authenticates itself to the upstream switch so that the link becomes a trunking port. The switch that the client is connecting to must have the radius configuration to support dot1x much like your other switches. That switch that authenticates itself must have its ip address added to the radius server database so it can authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps point you in the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2012 03:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/neat-configuration-issue/m-p/1896071#M259847</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-12-21T03:14:23Z</dc:date>
    </item>
  </channel>
</rss>

