<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X on switch 2950 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549102#M426727</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this problem is related to freeradius. I was doing some tests with freeradius and it didn't work. So I changed to ACS (no changes on switch config) and it worked fine.&lt;/P&gt;&lt;P&gt;It could be some parameter that must be modified on freeradius, but I don't know what is!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Jan 2007 13:37:12 GMT</pubDate>
    <dc:creator>marcelo.zilio</dc:creator>
    <dc:date>2007-01-31T13:37:12Z</dc:date>
    <item>
      <title>802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549094#M426717</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to configure 802.1X on a 2950 switch, i can't connect from a pc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's what i did on:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* ACS&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;    aaa client ip IP_Switch&lt;/P&gt;&lt;P&gt;    authenticate : radius (ietf)&lt;/P&gt;&lt;P&gt;    key : xxxxx&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;&lt;P&gt;a certificate has been created on a ca server and installed on the acs (on same machine, i choose "use certificate from storage")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* WIN XP&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;  Type EAP : PEAP &lt;/P&gt;&lt;P&gt;  Secured password : EAP-MSCHAP V2&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* SWITCH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;  interface fastethernet0/1&lt;/P&gt;&lt;P&gt;  switchport mode access&lt;/P&gt;&lt;P&gt;  dot1x port-control auto&lt;/P&gt;&lt;P&gt;  radius-server host IP_ACS auth-port 1645 key xxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created user (same as used for logging on the client) on ACS, i always get "authentication failed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549094#M426717</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2019-03-10T21:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549095#M426718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP has not been checked in global authentication setup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2006 12:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549095#M426718</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2006-08-03T12:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549096#M426719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am in the same situation.  I have the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Model:  	2950&lt;/P&gt;&lt;P&gt;Version: 	IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(22)EA8, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/24&lt;/P&gt;&lt;P&gt; switchport access vlan 4&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; dot1x port-control auto&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host xxx.xxx.xxx.xxx auth-port 1812 acct-port 1813 key xxxxxx&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a debug on Radius I get nothing.  When I do a debug on dot1x I get a lot of messages.  Could you please help me to understand what you did on your config.  Also, how did you setup Windows XP?  I am currently using XP with SP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2006 15:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549096#M426719</guid>
      <dc:creator>stephen</dc:creator>
      <dc:date>2006-08-09T15:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549097#M426720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;A class="jive-link-custom" href="http://www.cisco.com/application/pdf/en/us/guest/netsol/ns75/c654/cdccont_0900aecd803fab62.pdf" target="_blank"&gt;http://www.cisco.com/application/pdf/en/us/guest/netsol/ns75/c654/cdccont_0900aecd803fab62.pdf&lt;/A&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know when you get a chance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2006 17:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549097#M426720</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2006-08-09T17:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549098#M426721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes this helped.  The switch contacted the radius server and I saw log messages from it.  However, I now need help getting the PC to authenticate to the radius server.  I am using freeradius.  I am open to any ideas anyone has.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2006 14:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549098#M426721</guid>
      <dc:creator>stephen</dc:creator>
      <dc:date>2006-09-27T14:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549099#M426723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hye hairinirina, i'm also have the same problem, but cannot be solved till now, user authentication failed to log on to network, could u give me some advice regarding to this problem, any configuration examples...thanks..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2007 04:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549099#M426723</guid>
      <dc:creator>elie_andika</dc:creator>
      <dc:date>2007-01-08T04:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549100#M426725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the IP communication between the switch and the radius server fine ? Is the radius server on a seperate segment ? Once u have this setup, u just need to define the username/password on the radius server and see if authenticates thro the switch. do a debug aaa authentication, debug dot1x events/packets etc to see what happens when the user logs in !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;dot1x guest-vlan supplicant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/47&lt;/P&gt;&lt;P&gt; switchport access vlan 777&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; dot1x port-control auto&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 15&lt;/P&gt;&lt;P&gt; dot1x guest-vlan 10&lt;/P&gt;&lt;P&gt; dot1x reauthentication&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; ip dhcp snooping trust&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If authentication phase passes, the user will be put in VLAN 777. if there is any guest plugging into this PC, without a dot1x client, he will be put on guest vlan 10..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. all the best. rate replies if found useful..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2007 02:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549100#M426725</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-15T02:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549101#M426726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for answering your post so late, i hadn't seen your post earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i followed what's written on &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/480/acs-eap.pdf" target="_blank"&gt;http://www.cisco.com/warp/public/480/acs-eap.pdf&lt;/A&gt; for configuring acs,CA server,client xp (the difference is that i configured wired network card instead of wireless card).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12119ea1/2950scg/swauthen.pdf" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12119ea1/2950scg/swauthen.pdf&lt;/A&gt;  for the configuration of switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope it helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2007 07:01:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549101#M426726</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2007-01-18T07:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549102#M426727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this problem is related to freeradius. I was doing some tests with freeradius and it didn't work. So I changed to ACS (no changes on switch config) and it worked fine.&lt;/P&gt;&lt;P&gt;It could be some parameter that must be modified on freeradius, but I don't know what is!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jan 2007 13:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549102#M426727</guid>
      <dc:creator>marcelo.zilio</dc:creator>
      <dc:date>2007-01-31T13:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X on switch 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549103#M426729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks harinirira for the links...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Feb 2007 02:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-on-switch-2950/m-p/549103#M426729</guid>
      <dc:creator>elie_andika</dc:creator>
      <dc:date>2007-02-06T02:33:40Z</dc:date>
    </item>
  </channel>
</rss>

