<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Manually re-authenticate dot1x client? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082310#M276187</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Michal!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But does that command do the same thing?&amp;nbsp; Shouldn't &lt;EM&gt;dot1x reauthenticate interface&lt;/EM&gt; force a new authentication and &lt;EM&gt;clear dot1x interface&lt;/EM&gt; just deauthenticate the client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I really fint it intressting that commands from Configuration Guide does not exist i real life.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, thanks for your efforts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jan 2013 12:17:34 GMT</pubDate>
    <dc:creator>jmandersson</dc:creator>
    <dc:date>2013-01-18T12:17:34Z</dc:date>
    <item>
      <title>Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082308#M276160</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was looking for a way the manually re-authenticate dot1x client from cli and found this:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/15.0_2_se/configuration/guide/sw8021x.html#wp1195665" target="_blank"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/15.0_2_se/configuration/guide/sw8021x.html#wp1195665&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt; font-family: Times-Roman; "&gt;"You manually reauthenticate the client by entering the &lt;STRONG style="font-size: 10pt; font-family: Times-Bold; "&gt;&lt;STRONG style="font-size: 10pt; font-family: Times-Bold; "&gt;dot1x reauthenticate interface &lt;/STRONG&gt;&lt;/STRONG&gt;&lt;EM style=": ; font-size: 10pt; font-family: Times-Bold; "&gt;interface-id &lt;/EM&gt;&lt;SPAN style="font-size: 10pt; font-family: Times-Bold; "&gt;privileged &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Times-Bold; "&gt;EXEC command"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;I've tried it 2960 with 12.2(58)SE and 15.0(2)SE, but it doesn't seems to be implemented. &lt;/P&gt;&lt;P align="left"&gt;Have I missunderstood something? Or do you guys have any other command to accomplish a manually re-auth?&lt;/P&gt;&lt;P align="left"&gt;&lt;/P&gt;&lt;P align="left"&gt;Thanks,&lt;/P&gt;&lt;P align="left"&gt;Johan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082308#M276160</guid>
      <dc:creator>jmandersson</dc:creator>
      <dc:date>2019-03-11T02:59:27Z</dc:date>
    </item>
    <item>
      <title>Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082309#M276165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use "clear dot1x interface e0/0"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 10:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082309#M276165</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2013-01-18T10:32:44Z</dc:date>
    </item>
    <item>
      <title>Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082310#M276187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Michal!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for answering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But does that command do the same thing?&amp;nbsp; Shouldn't &lt;EM&gt;dot1x reauthenticate interface&lt;/EM&gt; force a new authentication and &lt;EM&gt;clear dot1x interface&lt;/EM&gt; just deauthenticate the client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I really fint it intressting that commands from Configuration Guide does not exist i real life.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, thanks for your efforts!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 12:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082310#M276187</guid>
      <dc:creator>jmandersson</dc:creator>
      <dc:date>2013-01-18T12:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082311#M276236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right, should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what is the trigger for "dot1x reauthenticate interface". Maybe we need to have configured periodic reauthentication to have it working, example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch(config-if)# dot1x reauthentication&lt;/P&gt;&lt;P&gt;Switch(config-if)# dot1x timeout reauth-period 4000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you try that ?&lt;/P&gt;&lt;P&gt;You can also enable "debug dot1x all" and verify if any packet has been send by switch ("&lt;/P&gt;&lt;P&gt;EAPOL pak dump Tx").&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you will still have the problem i will build a lab and test it myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ---&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;P&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 12:37:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082311#M276236</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2013-01-18T12:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082312#M276283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Okey, i think some of my problems are related to Authentication Manager commands and pre Authentication Manager commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x reauthentication&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication periodic&lt;/P&gt;&lt;P&gt;dot1x timeout reauth-period 4000 --&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication timer reauthenticate 4000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still, I can't find any equivalent to my &lt;EM&gt;dot1x reauthenticate interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 13:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082312#M276283</guid>
      <dc:creator>jmandersson</dc:creator>
      <dc:date>2013-01-18T13:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082313#M276343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Johan, i can confirm, tested on version 15 - i do not have that command "dot1x reauthenticate interface"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right: this is a documentation bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not make sense to have two command which does something similar. "clear dot1x interface" does the same - after 2 seconds my switch sent EAP request identity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Michal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 13:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082313#M276343</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2013-01-18T13:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082314#M276412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, then I'l satisfy with &lt;EM&gt;clear dot1x interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 13:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/2082314#M276412</guid>
      <dc:creator>jmandersson</dc:creator>
      <dc:date>2013-01-18T13:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3174416#M276448</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thought not in timely manner but just for ultimate clarity on the subject &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;b0202094-01#dot1x re-authenticate interface g2/39&lt;BR /&gt;b0202094-01#&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 08:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3174416#M276448</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2017-08-23T08:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3179751#M276518</link>
      <description>&lt;P&gt;Hmmm, if I do a "clear dot1x interface gigabitEthernet 1/0/41" the client will lost his connectivity and will never be reachable till I shut and no-shut the interface (or unplug and replug the clients ethernet interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also enabled fot testing the reauthentication enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It stays in this state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2960XR#sh authentication sessions interface gigabitEthernet 1/0/41&lt;/P&gt;&lt;P&gt;Interface Identifier Method Domain Status Fg Session ID&lt;BR /&gt;-----------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/41 5c26.0a01.ed64 N/A UNKNOWN Unauth 000000000000002F00A291E6&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;A - Applying Policy (multi-line status for details)&lt;BR /&gt;D - Awaiting Deletion&lt;BR /&gt;F - Final Removal in progress&lt;BR /&gt;I - Awaiting IIF ID allocation&lt;BR /&gt;N - Waiting for AAA to come up&lt;BR /&gt;P - Pushed Session&lt;BR /&gt;R - Removing User Profile (multi-line status for details)&lt;BR /&gt;U - Applying User Profile (multi-line status for details)&lt;BR /&gt;X - Unknown Blocker&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;Handle Priority Name&lt;BR /&gt;8 0 dot1xSupp&lt;BR /&gt;7 5 dot1x&lt;BR /&gt;18 10 mab&lt;BR /&gt;16 15 webauth&lt;/P&gt;&lt;P&gt;2960XR#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a shutdown and no-shutdown of the interface all is fine again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2960XR#sh authentication sessions interface gigabitEthernet 1/0/41&lt;/P&gt;&lt;P&gt;Interface Identifier Method Domain Status Fg Session ID&lt;BR /&gt;-----------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/41 5c26.0a01.ed64 dot1x DATA Auth 000000000000003000A407B3&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;A - Applying Policy (multi-line status for details)&lt;BR /&gt;D - Awaiting Deletion&lt;BR /&gt;F - Final Removal in progress&lt;BR /&gt;I - Awaiting IIF ID allocation&lt;BR /&gt;N - Waiting for AAA to come up&lt;BR /&gt;P - Pushed Session&lt;BR /&gt;R - Removing User Profile (multi-line status for details)&lt;BR /&gt;U - Applying User Profile (multi-line status for details)&lt;BR /&gt;X - Unknown Blocker&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;Handle Priority Name&lt;BR /&gt;8 0 dot1xSupp&lt;BR /&gt;7 5 dot1x&lt;BR /&gt;18 10 mab&lt;BR /&gt;16 15 webauth&lt;/P&gt;&lt;P&gt;2960XR#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any ideas whats going wrong here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 14:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3179751#M276518</guid>
      <dc:creator>RAINER ADAM</dc:creator>
      <dc:date>2017-09-04T14:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Manually re-authenticate dot1x client?</title>
      <link>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3313128#M276582</link>
      <description>&lt;P&gt;You can do "clear authentication session interface gigabitEthernet 1/0/41" I believe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then "show authentication session interface gigabitEthernet 1/0/41 details"&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 19:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/manually-re-authenticate-dot1x-client/m-p/3313128#M276582</guid>
      <dc:creator>jalemanp</dc:creator>
      <dc:date>2018-01-17T19:08:34Z</dc:date>
    </item>
  </channel>
</rss>

