<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I don't think the &amp;quot;test aaa&amp;quot; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794857#M41297</link>
    <description>&lt;P&gt;I don't think the "test aaa" command uses all the settings from your AAA server group. There is probably an option in the command to specify port.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2015 17:41:14 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2015-12-16T17:41:14Z</dc:date>
    <item>
      <title>Port 1812 config but port 1645 used</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794856#M41296</link>
      <description>&lt;P&gt;Switch configured to use port 1812.&amp;nbsp; Why in debug radius authentication, do we see port 1645 used between switch and ISE?&amp;nbsp; See config and debug output below:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;CONFIG&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;
&lt;P&gt;L3-SWITCH(config)# radius server ISE-PRIMARY&lt;BR /&gt;L3-SWITCH(config-radius-server)#&lt;SPAN style="color: #000000;"&gt; address ipv4 10.10.2.50 auth-port &lt;SPAN style="color: #993300;"&gt;&lt;STRONG&gt;1812 &lt;/STRONG&gt;&lt;/SPAN&gt;acct-port 1813&lt;/SPAN&gt;&lt;BR /&gt;L3-SWITCH(config-radius-server)# automate-tester username ISE_HEALTH ignore-acct-port&lt;BR /&gt;L3-SWITCH(config-radius-server)# key sharedsecret&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;DEBUG OUTPUT:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;L3-SWITCH# test aaa group radius admin admin$Pwd new-code&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr" style="text-align: left;"&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Attempting authentication test to server-group radius using radius&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS/ENCODE(00000000):Orig. component type = Invalid&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS/ENCODE(00000000): dropping service type, "radius-server attribute 6 on-for-login-auth" is off &lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr" style="text-align: left;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): Config NAS IP: 10.10.2.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): Config NAS IPv6: ::&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): sending&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS/DECODE(00000000): There is no General DB. Want server details may not be specified&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): Send Access-Request to &lt;SPAN style="color: #993300;"&gt;&lt;STRONG&gt;10.10.2.50:1645&lt;/STRONG&gt;&lt;/SPAN&gt; id 1645/2, len 51&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS: authenticator 99 E2 71 98 E2 84 C8 BE - 34 B9 56 91 A8 E3 DC FB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS: User-Password [2] 18 *&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr" style="text-align: left;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS: User-Name [1] 7 "admin"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS: NAS-IP-Address [4] 6 10.10.2.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): Sending a IPv4 Radius Packet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.873: RADIUS(00000000): Started 5 sec timeout &lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr" style="text-align: left;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.881: RADIUS: Received from id &lt;STRONG&gt;&lt;SPAN style="color: #800000;"&gt;1645&lt;/SPAN&gt;&lt;/STRONG&gt;/2 10.10.2.50:&lt;STRONG&gt;&lt;SPAN style="color: #993300;"&gt;1645&lt;/SPAN&gt;&lt;/STRONG&gt;, Access-Reject, len 20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.881: RADIUS: authenticator 61 6D 9A 38 9B 58 9E 44 - 4C 4A F2 1F 29 B3 74 3F&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;Dec 3 21:09:57.881: RADIUS/DECODE(00000000): There is no General DB. Reply server details may not be recorded&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;L3-SWITCH#&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794856#M41296</guid>
      <dc:creator>Catherine Paquet</dc:creator>
      <dc:date>2019-03-11T06:20:09Z</dc:date>
    </item>
    <item>
      <title>I don't think the "test aaa"</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794857#M41297</link>
      <description>&lt;P&gt;I don't think the "test aaa" command uses all the settings from your AAA server group. There is probably an option in the command to specify port.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 17:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794857#M41297</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-12-16T17:41:14Z</dc:date>
    </item>
    <item>
      <title>See the command type, with</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794858#M41298</link>
      <description>&lt;P&gt;command used is:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;L3-SWITCH# test aaa group radius admin admin$Pwd &lt;STRONG&gt;&lt;SPAN style="color: #993300;"&gt;new-code&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;new-code&lt;/SPAN&gt; means use port 1812/1813. &amp;nbsp; If the keyword would have been &lt;SPAN style="color: #993300;"&gt;legacy&lt;/SPAN&gt;, that would have mean to use port 1645/1646.&lt;/P&gt;
&lt;P&gt;So, it's still puzzling that if we tell the switch to use NEW-CODE (1812), the switch is using port 1645.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2015 19:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794858#M41298</guid>
      <dc:creator>Catherine Paquet</dc:creator>
      <dc:date>2015-12-16T19:07:57Z</dc:date>
    </item>
    <item>
      <title>try this : test aaa group</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794859#M41299</link>
      <description>&lt;H5&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;try this : test aaa group radius server 10.10.2.50 auth-port 1812 acct-port 1813 admin admin$Pwd new-code&lt;/SPAN&gt;&lt;/H5&gt;</description>
      <pubDate>Wed, 16 Dec 2015 20:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794859#M41299</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-12-16T20:11:24Z</dc:date>
    </item>
    <item>
      <title>Hello All,</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794860#M41300</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the issue. The command you are using to perform the test is using "radius" group which is default group IOS device uses to put the devices:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;test aaa &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;group radius&lt;/STRONG&gt;&lt;/SPAN&gt; admin admin$Pwd new-code&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In order to test the configuration of the group you created and configured port 1812, you need to execute the test command using the group you created called "&lt;SPAN&gt;ISE-PRIMARY":&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;test aaa &lt;STRONG&gt;&lt;SPAN style="color: #339966;"&gt;group&amp;nbsp;ISE-PRIMARY&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;admin admin$Pwd new-code/legacy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;Note: Please mark it as answered if applicable&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 16:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794860#M41300</guid>
      <dc:creator>Ivan Gonzalez</dc:creator>
      <dc:date>2015-12-17T16:02:00Z</dc:date>
    </item>
    <item>
      <title>I tried Jan suggestion and it</title>
      <link>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794861#M41301</link>
      <description>&lt;P&gt;I tried Jan suggestion and it worked, on port 1812, without changing the &lt;EM&gt;group radius&lt;/EM&gt;.&amp;nbsp; Following are the results:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;L3-Switch#&lt;STRONG&gt;test aaa group radius server 10.10.2.50 auth-port 1812 acct-port 1813 admin admin$Pwd new-code&lt;/STRONG&gt; &lt;BR /&gt; User rejected&lt;BR /&gt; L3-Switch#&lt;BR /&gt; &amp;lt;output omitted&amp;gt;&lt;BR /&gt; Dec 17 13:20:12.803: RADIUS(00000000): Send Access-Request to &lt;STRONG&gt;&lt;SPAN style="color: #800000;"&gt;10.10.2.50:1812&lt;/SPAN&gt;&lt;/STRONG&gt; id 1645/233, len 51&lt;BR /&gt; Dec 17 13:20:12.803: RADIUS:&amp;nbsp; authenticator 8D 14 82 14 C4 AA 68 5B - DC D4 02 53 50 BB 02 AC&lt;BR /&gt; Dec 17 13:20:12.803: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt; Dec 17 13:20:12.803: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 7&amp;nbsp;&amp;nbsp; "admin"&lt;BR /&gt; &amp;lt;output omitted&amp;gt;&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS: Received from id 1645/233 &lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;10.10.2.50:1812&lt;/STRONG&gt;&lt;/SPAN&gt;, Access-Reject, len 20&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS:&amp;nbsp; authenticator 8D 1E 41 8E 9D DC 8E 36 - 9C 70 1A 72 19 DC 04 FE&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS/DECODE(00000000): There is no General DB. Reply server details may not be recorded&lt;BR /&gt; L3-Switch#&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS(00000000): Received from id 1645/233&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS/ENCODE(00000000):Orig. component type = Invalid&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS(00000000): Config NAS IP: 10.10.2.1&lt;BR /&gt; Dec 17 13:20:12.811: RADIUS(00000000): Config NAS IPv6: ::&lt;BR /&gt; Dec 17 13:20:12.820: RADIUS(00000000): Sending a IPv4 Radius Packet&lt;BR /&gt; Dec 17 13:20:12.820: RADIUS(00000000): Started 5 sec timeout&lt;BR /&gt; Dec 17 13:20:12.820: RADIUS: Received from id 1646/208 &lt;STRONG&gt;&lt;SPAN style="color: #800000;"&gt;10.10.2.50:1813&lt;/SPAN&gt;&lt;/STRONG&gt;, Accounting-response, len 20&lt;BR /&gt; Dec 17 13:20:12.82&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 20:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/port-1812-config-but-port-1645-used/m-p/2794861#M41301</guid>
      <dc:creator>Catherine Paquet</dc:creator>
      <dc:date>2015-12-17T20:56:16Z</dc:date>
    </item>
  </channel>
</rss>

