<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac Authentication bypass using ACS 4.1 Appliance and 3560 S in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267388#M348070</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error "Bad request from NAS" comes because of a radius shared secret key mismatch.&lt;/P&gt;&lt;P&gt;If you have entered the AAA client entry for the switch in a particular Network Device Group (NDG) on the ACS, please move it in the Not Assigned group.&lt;/P&gt;&lt;P&gt;Also make sure we have not copied and pasted the shared secret key on the device and the ACS but manually typed it in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:49:37 GMT</pubDate>
    <dc:creator>kussriva</dc:creator>
    <dc:date>2009-11-26T22:49:37Z</dc:date>
    <item>
      <title>Mac Authentication bypass using ACS 4.1 Appliance and 3560 Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267387#M347977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to use Mac authetication bypass for dynamic vlan assignment but I couldn't even authenticate using ACS until now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport access vlan 47&lt;BR /&gt; switchport mode access&lt;BR /&gt; dot1x mac-auth-bypass&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x port-control auto&lt;BR /&gt; dot1x timeout quiet-period 15&lt;BR /&gt; dot1x timeout tx-period 3&lt;BR /&gt; dot1x reauthentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA and Radius config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login default line&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 10.1.18.40 auth-port 1645 acct-port 1646 key secretkey&lt;BR /&gt;radius-server host 10.1.18.41 auth-port 1645 acct-port 1646 key secretkey&lt;BR /&gt;radius-server source-ports 1645-1646&lt;BR /&gt;radius-server key secretkey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS, I have configured AAA client for the switch to use RADIUS IETF. I have added the a user using the mac address of the PC I am testing as in the below format:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username : 002264b776e2&lt;/P&gt;&lt;P&gt;password : 002264b776e2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have disabled the 802.1x on the Windows XP PC that I am testing. But it is not being authenticated. I have checked the shared key to make sure I have entered them correctly on both ACS and the swith.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the debug output from the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;062524: Nov 25 13:23:41: RADIUS:&amp;nbsp; AAA Unsupported&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [161] 16&amp;nbsp; &lt;BR /&gt;062525: Nov 25 13:23:41: RADIUS:&amp;nbsp;&amp;nbsp; 46 61 73 74 45 74 68 65 72 6E 65 74 30 2F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [FastEthernet0/]&lt;BR /&gt;062526: Nov 25 13:23:41: RADIUS(00000652): Storing nasport 50014 in rad_db&lt;BR /&gt;062527: Nov 25 13:23:41: RADIUS(00000652): Config NAS IP: 0.0.0.0&lt;BR /&gt;062528: Nov 25 13:23:41: RADIUS/ENCODE(00000652): acct_session_id: 1618&lt;BR /&gt;062529: Nov 25 13:23:41: RADIUS(00000652): sending&lt;BR /&gt;062530: Nov 25 13:23:41: RADIUS/ENCODE: Best Local IP-Address 10.1.16.37 for Radius-Server 10.1.18.40&lt;BR /&gt;062531: Nov 25 13:23:41: RADIUS(00000652): Send Access-Request to 10.1.18.40:1645 id 1645/63, len 138&lt;BR /&gt;062532: Nov 25 13:23:41: RADIUS:&amp;nbsp; authenticator DD AF 86 D4 77 7D 84 B0 - 0A CE 11 D3 DF 90 AE AD&lt;BR /&gt;062533: Nov 25 13:23:41: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 14&amp;nbsp; "002264b776e2"&lt;BR /&gt;062534: Nov 25 13:23:41: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt;062535: Nov 25 13:23:41: RADIUS:&amp;nbsp; Service-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [6]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Call Check&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [10]&lt;BR /&gt;062536: Nov 25 13:23:41: RADIUS:&amp;nbsp; Framed-MTU&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [12]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 1500&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;062537: Nov 25 13:23:41: RADIUS:&amp;nbsp; Called-Station-Id&amp;nbsp;&amp;nbsp; [30]&amp;nbsp; 19&amp;nbsp; "00-1E-14-C4-7C-90"&lt;BR /&gt;062538: Nov 25 13:23:41: RADIUS:&amp;nbsp; Calling-Station-Id&amp;nbsp; [31]&amp;nbsp; 19&amp;nbsp; "00-22-64-B7-76-E2"&lt;BR /&gt;062539: Nov 25 13:23:41: RADIUS:&amp;nbsp; Message-Authenticato[80]&amp;nbsp; 18&amp;nbsp; &lt;BR /&gt;062540: Nov 25 13:23:41: RADIUS:&amp;nbsp;&amp;nbsp; 20 DD 3B A9 8E 96 13 5D F4 B2 B6 BF 08 90 33 9F&amp;nbsp; [ ?;????]??????3?]&lt;BR /&gt;062541: Nov 25 13:23:41: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Eth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [15]&lt;BR /&gt;062542: Nov 25 13:23:41: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 50014&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;062543: Nov 25 13:23:41: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.1.16.37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;062544: Nov 25 13:23:47: RADIUS: Retransmit to (10.1.18.40:1645,1646) for id 1645/63&lt;BR /&gt;062545: Nov 25 13:23:53: RADIUS: Retransmit to (10.1.18.40:1645,1646) for id 1645/63&lt;BR /&gt;062546: Nov 25 13:23:58: RADIUS: Retransmit to (10.1.18.40:1645,1646) for id 1645/63&lt;BR /&gt;062547: Nov 25 13:24:04: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.1.18.40:1645,1646 is not responding.&lt;BR /&gt;062548: Nov 25 13:24:04: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.1.18.40:1645,1646 has returned.&lt;BR /&gt;062549: Nov 25 13:24:04: RADIUS: Fail-over to (10.1.18.41:1645,1646) for id 1645/63&lt;BR /&gt;062550: Nov 25 13:24:04: RADIUS/ENCODE: Best Local IP-Address 10.1.16.37 for Radius-Server 10.1.18.41&lt;BR /&gt;062551: Nov 25 13:24:09: RADIUS: Retransmit to (10.1.18.41:1645,1646) for id 1645/63&lt;BR /&gt;062552: Nov 25 13:24:15: RADIUS: Retransmit to (10.1.18.41:1645,1646) for id 1645/63&lt;BR /&gt;062553: Nov 25 13:24:21: RADIUS: Retransmit to (10.1.18.41:1645,1646) for id 1645/63&lt;BR /&gt;062554: Nov 25 13:24:26: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.1.18.41:1645,1646 is not responding.&lt;BR /&gt;062555: Nov 25 13:24:26: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.1.18.41:1645,1646 has returned.&lt;BR /&gt;062556: Nov 25 13:24:26: RADIUS: No response from (10.1.18.41:1645,1646) for id 1645/63&lt;BR /&gt;062557: Nov 25 13:24:26: RADIUS/DECODE: parse response no app start; FAIL&lt;BR /&gt;062558: Nov 25 13:24:26: RADIUS/DECODE: parse response; FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS logs I have the below messages in the failed attempts logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="2" cellspacing="0" class="content" style="border-collapse: collapse; width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="left"&gt;25/11/2009&lt;/TD&gt;&lt;TD align="left"&gt;13:24:09&lt;/TD&gt;&lt;TD align="left"&gt;Bad request from NAS&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;(Unknown)&lt;/TD&gt;&lt;TD align="left"&gt;Invalid message authenticator in EAP request&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;10.1.16.37&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;XXX-NW-DEVICES-2&lt;/TD&gt;&lt;TD align="left"&gt;XXX-Access-Sw&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I am doing something wrong or something is missing but couldn't find what. Any ideas would be appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267387#M347977</guid>
      <dc:creator>b.zont</dc:creator>
      <dc:date>2019-03-10T23:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Mac Authentication bypass using ACS 4.1 Appliance and 3560 S</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267388#M348070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error "Bad request from NAS" comes because of a radius shared secret key mismatch.&lt;/P&gt;&lt;P&gt;If you have entered the AAA client entry for the switch in a particular Network Device Group (NDG) on the ACS, please move it in the Not Assigned group.&lt;/P&gt;&lt;P&gt;Also make sure we have not copied and pasted the shared secret key on the device and the ACS but manually typed it in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Nov 2009 22:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267388#M348070</guid>
      <dc:creator>kussriva</dc:creator>
      <dc:date>2009-11-26T22:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Mac Authentication bypass using ACS 4.1 Appliance and 3560 S</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267389#M348121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have put the switch in to not assigned group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am having the below error message on ACS:&lt;/P&gt;&lt;TABLE border="1" cellpadding="2" cellspacing="0" class="content" style="border-collapse: collapse; width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD align="left"&gt;27/11/2009&lt;/TD&gt;&lt;TD align="left"&gt;16:04:23&lt;/TD&gt;&lt;TD align="left"&gt;Authen failed&lt;/TD&gt;&lt;TD align="left"&gt;002264b776e2&lt;/TD&gt;&lt;TD align="left"&gt;Test Group 7&lt;/TD&gt;&lt;TD align="left"&gt;00-22-64-B7-76-E2&lt;/TD&gt;&lt;TD align="left"&gt;(Default)&lt;/TD&gt;&lt;TD align="left"&gt;Internal error&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;50014&lt;/TD&gt;&lt;TD align="left"&gt;10.1.16.37&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;TD align="left"&gt;XXX-NW-DEVICES-2&lt;/TD&gt;&lt;TD align="left"&gt;..&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure that I have enteres the secret key correcly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Nov 2009 15:06:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267389#M348121</guid>
      <dc:creator>b.zont</dc:creator>
      <dc:date>2009-11-27T15:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Mac Authentication bypass using ACS 4.1 Appliance and 3560 S</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267390#M348186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Internal Error can come due to many reasons like ACS Appliance agent installed on an unsupported version of the Operating System or not installed properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you created the entry of the MAC address in the ACS Internal Database or in the Active Directory? If it's in the Active Directory, if possible create a test user in the ACS database and then test with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the command "test aaa group radius (username) (password) legacy" while doing the testing. This is a test command used to check the authentication from the radius server from the IOS devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.1/installation/guide/remote_agent/rawi.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.1/installation/guide/remote_agent/rawi.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Dec 2009 05:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-authentication-bypass-using-acs-4-1-appliance-and-3560/m-p/1267390#M348186</guid>
      <dc:creator>kush.sri2001</dc:creator>
      <dc:date>2009-12-01T05:21:25Z</dc:date>
    </item>
  </channel>
</rss>

