<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No Radius-accept-request received on Radius server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567190#M311436</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to access my network through 802.1X Radius authentication. My PC is connected to a 2950 switch with following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;radius-server host 11.0.0.2 key Ralf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on interface level(connection to PC):&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 8&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on interface level(connection to Radius server):&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enabled 802.1X authentication on my PC via the service 'Wired Autoconfig' and in the tab authentication (one of the tabs of the interface configuration)&lt;/P&gt;&lt;P&gt;I choose PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;When I trace my PC-interface with Wireshark, I see an EAPOL- EAP-Request and a EAP-Response message. The next message in the flow should be a Radius-Accept-request message but it seems that this message is never sent. Although, when i open a 'debug radius' session on the switch, the logs are indicating that the accept-request message is sent. Strange because I see no message coming in on the Radius-server interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Radius-server has IP-address 11.0.0.2 and my PC 11.0.0.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody see a reason why the Radius-Accept-Request message is not received on my Radius-server interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,Ralf. &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:33:56 GMT</pubDate>
    <dc:creator>MeirsmanRalf</dc:creator>
    <dc:date>2019-03-11T00:33:56Z</dc:date>
    <item>
      <title>No Radius-accept-request received on Radius server</title>
      <link>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567190#M311436</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to access my network through 802.1X Radius authentication. My PC is connected to a 2950 switch with following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;radius-server host 11.0.0.2 key Ralf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on interface level(connection to PC):&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 8&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on interface level(connection to Radius server):&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enabled 802.1X authentication on my PC via the service 'Wired Autoconfig' and in the tab authentication (one of the tabs of the interface configuration)&lt;/P&gt;&lt;P&gt;I choose PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;When I trace my PC-interface with Wireshark, I see an EAPOL- EAP-Request and a EAP-Response message. The next message in the flow should be a Radius-Accept-request message but it seems that this message is never sent. Although, when i open a 'debug radius' session on the switch, the logs are indicating that the accept-request message is sent. Strange because I see no message coming in on the Radius-server interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Radius-server has IP-address 11.0.0.2 and my PC 11.0.0.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody see a reason why the Radius-Accept-Request message is not received on my Radius-server interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,Ralf. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567190#M311436</guid>
      <dc:creator>MeirsmanRalf</dc:creator>
      <dc:date>2019-03-11T00:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: No Radius-accept-request received on Radius server</title>
      <link>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567191#M311445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using PEAP, the authnetication is not as simple as that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the PEAP authentication process:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG alt="http://layer3.files.wordpress.com/2009/08/wireless-security-peap.jpg" class="jive-image" height="464" src="http://layer3.files.wordpress.com/2009/08/wireless-security-peap.jpg" width="602" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you can see the switch as the AP.&lt;/P&gt;&lt;P&gt;So, after the first&amp;nbsp; EAP-Response message, the ACS must reply with an Access-Challenge containing the EAP-TLS start, so the encryption tunnel can be started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possible reason for this not to happen is simply because the ACS does not support PEAP and/or does not conatin the server certificate needed to build the TLS tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 12:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567191#M311445</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-11-11T12:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: No Radius-accept-request received on Radius server</title>
      <link>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567192#M311480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found a solution to my problem. I administered an IP-adress for the VLAN-interface on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 8&lt;/P&gt;&lt;P&gt;ip address 11.0.0.4 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparentlt the switch needs an IP-address to send the Radius-accept-request from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next step is to get a Radius-server running and get the PC authenticated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 20:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-radius-accept-request-received-on-radius-server/m-p/1567192#M311480</guid>
      <dc:creator>MeirsmanRalf</dc:creator>
      <dc:date>2010-11-11T20:28:44Z</dc:date>
    </item>
  </channel>
</rss>

