<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC 802.1x: VLAN assignment via RADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-802-1x-vlan-assignment-via-radius/m-p/687436#M422291</link>
    <description>&lt;P&gt;I'm deploy a 802.1x NAC solution. Users authenticate ok but the VLAN is not assigned to the port. &lt;/P&gt;&lt;P&gt;The RADIUS server send the attributes to the NAD (switch 3560). I see the following lines in the radius debug output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS: Received from id 1645/4 192.168.1.1:1645, Access-Accept, len 267&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  authenticator AB 90 94 95 D0 86 04 E5 - D3 AC 43 21 C0 31 29 EB&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Session-Timeout     [27]  6   3600                      &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Termination-Action  [29]  6   1                         &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Type         [64]  6   01:Unsupported            [13]&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Medium-Type  [65]  6   01:Unsupported            [6]&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Private-Group[81]  10  01:"healthy"&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Vendor, Cisco       [26]  29  &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:   Cisco AVpair       [1]   23  "posture-token=Healthy"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose that the error appears because the attributes 64 and 65 are "Unsupported". Is it right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In RADIUS server I configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attribute 64 = VLAN (13)&lt;/P&gt;&lt;P&gt;attribute 65 = 802 (6)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below I attach switch configuration. The "healthy" vlan is configured in this one. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mart?n.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:52:31 GMT</pubDate>
    <dc:creator>mmoranzo</dc:creator>
    <dc:date>2019-03-10T21:52:31Z</dc:date>
    <item>
      <title>NAC 802.1x: VLAN assignment via RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-802-1x-vlan-assignment-via-radius/m-p/687436#M422291</link>
      <description>&lt;P&gt;I'm deploy a 802.1x NAC solution. Users authenticate ok but the VLAN is not assigned to the port. &lt;/P&gt;&lt;P&gt;The RADIUS server send the attributes to the NAD (switch 3560). I see the following lines in the radius debug output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS: Received from id 1645/4 192.168.1.1:1645, Access-Accept, len 267&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  authenticator AB 90 94 95 D0 86 04 E5 - D3 AC 43 21 C0 31 29 EB&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Session-Timeout     [27]  6   3600                      &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Termination-Action  [29]  6   1                         &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Type         [64]  6   01:Unsupported            [13]&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Medium-Type  [65]  6   01:Unsupported            [6]&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Tunnel-Private-Group[81]  10  01:"healthy"&lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:  Vendor, Cisco       [26]  29  &lt;/P&gt;&lt;P&gt;02:49:08: RADIUS:   Cisco AVpair       [1]   23  "posture-token=Healthy"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose that the error appears because the attributes 64 and 65 are "Unsupported". Is it right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In RADIUS server I configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attribute 64 = VLAN (13)&lt;/P&gt;&lt;P&gt;attribute 65 = 802 (6)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below I attach switch configuration. The "healthy" vlan is configured in this one. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mart?n.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-802-1x-vlan-assignment-via-radius/m-p/687436#M422291</guid>
      <dc:creator>mmoranzo</dc:creator>
      <dc:date>2019-03-10T21:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: NAC 802.1x: VLAN assignment via RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-802-1x-vlan-assignment-via-radius/m-p/687437#M422296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I change the IOS and all work fine. The IOS must  have the feature "NAC - L2 IEEE 802.1x". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other user has the same problem, he posted the question with the following subject: "NAC L2 802.1x VLAN assignment".In this question the problem is better described.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2006 13:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-802-1x-vlan-assignment-via-radius/m-p/687437#M422296</guid>
      <dc:creator>mmoranzo</dc:creator>
      <dc:date>2006-12-12T13:17:13Z</dc:date>
    </item>
  </channel>
</rss>

