<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316820#M378680</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i find the port in the auth-fail vlan,but don't get ip.why.thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jul 2009 13:42:26 GMT</pubDate>
    <dc:creator>lss_ingli</dc:creator>
    <dc:date>2009-07-30T13:42:26Z</dc:date>
    <item>
      <title>802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316818#M378548</link>
      <description>&lt;P&gt;I  am  doing the NAP With 802.1x enforcement. I Set the Guest vlan and auth-fail vlan and set the 802.1x authcation based port in the cisco 3550 switch and configure the RADIUS standard attributes Tunnel-Medium-Type, Tunnel-Pvt-Group-ID, and Tunnel-Type. Authcation method is EAP-mschap v2 .Authcation Mode is user authication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question 1: When I  log on nap client  that is a domain computer  and inpute the domain  password that is ok and the client can obtain  corresponding  right IP normal.but when i input local username and password  in it ,the nap client obtain 169 IP. Sometime I must inpute command ipconfig/release  and ipconfig/renew,the client can obtain restricted vlan IP .  The client auth-fail,it should Immediately  obtain auth-fail vlan IP. Why must inpute command ipconfig/release  and ipconfig/renew,?how to solve it ?&lt;/P&gt;&lt;P&gt;Question 2: A group computer  inpute user name and password ,the client auth-fail.It  should Immediately  obtain auth-fail vlan IP,but i must also muaul  ipconfig/release  and ipconfig/renew,the client can obtain restricted vlan IP ã&amp;#128;&amp;#130;&lt;/P&gt;&lt;P&gt;Why ?How  to  solve it ?&lt;/P&gt;&lt;P&gt;Question3:No sccm server ,i only deploy nps server ã&amp;#128;&amp;#129; wsus serverã&amp;#128;&amp;#129; dc and so on ,if client that  don't install the new patches that have been in the wsus server   is the client   put in the  restricted vlan ?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316818#M378548</guid>
      <dc:creator>lss_ingli</dc:creator>
      <dc:date>2019-03-10T23:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316819#M378598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume in Q1/2 that you are just failing 1X auth, right? Can you confirm the port is enabled in the auth-fail-vlan in a timely manner? FYI, 802.1X is async with things like DHCP in Windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WRT Q3, that's my understanding as well, though it's a configurable choice in NPS AFAIK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2009 04:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316819#M378598</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2009-07-29T04:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316820#M378680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i find the port in the auth-fail vlan,but don't get ip.why.thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 13:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316820#M378680</guid>
      <dc:creator>lss_ingli</dc:creator>
      <dc:date>2009-07-30T13:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316821#M378735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, can't tell from the current description. A few things to remember:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) 802.1X and DHCP is async with Windows (meaning one has nothing to do with the other on the client).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The port isn't "UP" until it's "authorized", and the Auth-Fail-VLAN being deployed is a valid authorization if you configured it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) There's no signal from the switch to the client to say "instead of denying you all access, I'm going to enable the port anyway and place you in this VLAN", hence reliance on #1 above essentially.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2009 13:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x/m-p/1316821#M378735</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2009-07-30T13:45:43Z</dc:date>
    </item>
  </channel>
</rss>

