<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Machine Authentication and 802.1x Authenticatio in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239687#M358768</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to configure the following on the port:&lt;/P&gt;&lt;P&gt;Swichport mode access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hth,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Feb 2009 12:59:30 GMT</pubDate>
    <dc:creator>jafrazie</dc:creator>
    <dc:date>2009-02-18T12:59:30Z</dc:date>
    <item>
      <title>Problem with Machine Authentication and 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239686#M358767</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to configure Dot1x authentication on each switch interface that belongs to data and voice vlan such as for eg:&lt;/P&gt;&lt;P&gt;Interface FastEthernet 1/1&lt;/P&gt;&lt;P&gt;switchport access vlan 10&lt;/P&gt;&lt;P&gt;switchport voice vlan 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it is not allowed to configure Dot1x on these interfaces, Our aim is to provide authorized access to our LAN either by Dot1x Authentication or through Machine Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I am having the following doubts &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Is Dot1x configurations on switch ports is a part of Machine Authentication procedure&lt;/P&gt;&lt;P&gt;2.What kind of configurations is required on switch port interface to enable machine authentication &lt;/P&gt;&lt;P&gt;3.And how the individual switch port is controlled in case of machine authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your kind response will be appreciated and thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Ahmed&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239686#M358767</guid>
      <dc:creator>itlogical</dc:creator>
      <dc:date>2019-03-10T23:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Machine Authentication and 802.1x Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239687#M358768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to configure the following on the port:&lt;/P&gt;&lt;P&gt;Swichport mode access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hth,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Feb 2009 12:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239687#M358768</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2009-02-18T12:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Machine Authentication and 802.1x Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239688#M358769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the immediate response,I verified the Switchport mode access is configured but still Dot1x is not allowed to configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2009 11:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239688#M358769</guid>
      <dc:creator>itlogical</dc:creator>
      <dc:date>2009-02-19T11:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Machine Authentication and 802.1x Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239689#M358770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the model switch and IOS/CATOS version running.  What is the current AAA and DOT1X global settings.  What is the configuration for the port.  What is the command that you are entering that is failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2009 16:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239689#M358770</guid>
      <dc:creator>Daniel Laden</dc:creator>
      <dc:date>2009-02-19T16:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Machine Authentication and 802.1x Authenticatio</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239690#M358771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the kind response, please be updated on the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. IOS Version and Model: &lt;/P&gt;&lt;P&gt;Cisco Internetwork Operating System Software IOS (tm) s3223_rp Software (s3223_rp-IPBASEK9-M), Version 12.2(18)SXF4, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco WS-C6509-E (R7000) processor (revision 1.2) with 227328K/34816K bytes of memory.Processor board ID SMC1022009Q&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. AAA and DOT1x global configs: &lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication fail-message ^CCCUsername or Password is not Correct^C&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure &lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x&lt;/P&gt;&lt;P&gt;tacacs-server host y.y.y.y&lt;/P&gt;&lt;P&gt;tacacs-server key zzz&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646 key zzz&lt;/P&gt;&lt;P&gt;radius-server host y.y.y.y auth-port 1645 acct-port 1646 key zzz&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Port Configs:&lt;/P&gt;&lt;P&gt;sh run interface fa2/6&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 139 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2/6&lt;/P&gt;&lt;P&gt; switchport&lt;/P&gt;&lt;P&gt; switchport access vlan 101&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 102&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Dot1x command output:&lt;/P&gt;&lt;P&gt;dot1x port-control auto &lt;/P&gt;&lt;P&gt;Command rejected: One or more ports configured with voice vlan.&lt;/P&gt;&lt;P&gt;Dot1x can't be enabled on voice vlan configured ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this information will help you to suggest a feasible solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again Thanks&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Feb 2009 10:08:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-machine-authentication-and-802-1x-authentication/m-p/1239690#M358771</guid>
      <dc:creator>itlogical</dc:creator>
      <dc:date>2009-02-22T10:08:14Z</dc:date>
    </item>
  </channel>
</rss>

