<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS authentication with 3750 switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434784#M428054</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you read through the guide above? or any guide?&lt;/P&gt;&lt;P&gt;I'm a little confused as to how you have your setup configured.&lt;/P&gt;&lt;P&gt;The reason your authentication is failing now, is because either:&lt;/P&gt;&lt;P&gt;a) The user doesn't exist on the radius server&lt;/P&gt;&lt;P&gt;b) Unsupported authentication method (PEAP, PAP, CHAP etc.. not enabled on your acs)_&lt;/P&gt;&lt;P&gt;c) Other user restrictions in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your using the Cisco ACS, you should be able to check the 'failed attempts' log to find out why the authentication wasn't sucessful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can you post the log, along with the dot1x config for your switch up. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Dec 2005 14:36:32 GMT</pubDate>
    <dc:creator>will.shaw</dc:creator>
    <dc:date>2005-12-14T14:36:32Z</dc:date>
    <item>
      <title>ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434777#M428047</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am configured my acs server to act as Tacacs+ AAA Server and configured 3750 SWICTH as AAA client but with dot1x implementation. But when i connect a laptop to this switch dot1x port, it prompts me for username and password and after providing the credentials it keeps on failing to authenticate. This is what i get on switch when user sends credential information. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;23:09:21: %TAC+: illegal type=6 for login&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: send AUTHEN/START packet ver=192 id=2079844561&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: Opening TCP/IP to 10.200.2.2/49 timeout=5&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: Opened TCP/IP handle 0x304E230 to 10.200.2.2/49&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: periodic timer started&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 req=2A32320 Qd id=2079844561 ver=192 handle=0x304E230 expire=5 AUTHEN/START/LOGIN/UNKNOWN queued&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 (2079844561) AUTHEN/START/LOGIN/UNKNOWN queued&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 id=2079844561 wrote 121 of 121 bytes&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 req=2A32320 Qd id=2079844561 ver=192 handle=0x304E230 expire=4 AUTHEN/START/LOGIN/UNKNOWN sent&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 read=12 wanted=12 alloc=12 got=12&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 read=28 wanted=28 alloc=28 got=16&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: 10.200.2.2 received 28 byte reply for 2A32320&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: req=2A32320 Tx id=2079844561 ver=192 handle=0x304E230 expire=4 AUTHEN/START/LOGIN/UNKNOWN processed&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: (2079844561) AUTHEN/START/LOGIN/UNKNOWN processed&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: periodic timer stopped (queue empty)&lt;/P&gt;&lt;P&gt;23:09:21: TAC+: ver=192 id=2079844561 received AUTHEN status = GETPASS&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434777#M428047</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2019-03-10T21:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434778#M428048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use radius.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2005 16:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434778#M428048</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-13T16:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434779#M428049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer but i have to stick with ACS as it supports external databse (i.e. like AD and LDAP) which i will be integrating with dot1x &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 05:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434779#M428049</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-14T05:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434780#M428050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco ACS supports Radius. You can't use TACACS+ for dot1x because you can't use EAP over TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_guide_chapter09186a00801f0a44.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_guide_chapter09186a00801f0a44.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 08:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434780#M428050</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-14T08:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434781#M428051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank Shaw for ur reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possible to integrate radius with LDAP or active directory for authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 09:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434781#M428051</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-14T09:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434782#M428052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, the ACS server will still handle the integration with the Active Directory or LDAP, in the same way it does for any autherntication method. Radius is the method of authentication between the ACS server and the client, and the reason it is used instead of TACACS+, is because TACACS+ does 'present' the necessary information needed to authenticate with the windows domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 09:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434782#M428052</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-14T09:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434783#M428053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have just swicthed my configuration to radius but  as soon as i connect a laptop to my AAA client i.e 3750 switch it gives me the below error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My AAA Radius server ip is 10.200.2.2 and &lt;/P&gt;&lt;P&gt;AAA client switch 3750 ip is 10.200.2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1d21h: %LINK-3-UPDOWN: Interface FastEthernet1/0/1, changed state to down&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: Pick NAS IP for u=0x2355BC0 tableid=0 cfg_addr=0.0.0.0&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: ustruct sharecount=2&lt;/P&gt;&lt;P&gt;1d21h: Radius: radius_port_info() success=1 radius_nas_port=1&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: EAP-login: length of radius packet = 149 code = 1&lt;/P&gt;&lt;P&gt;1d21h: RADIUS(00000000): Send Access-Request to 10.200.2.2:1812 id 1645/7, len 149&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  authenticator 89 AD D5 29 4F 57 CF 6A - 64 15 29 ED ED B6 02 D7&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  NAS-IP-Address      [4]   6   10.200.2.1                &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  NAS-Port            [5]   6   50101                     &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  NAS-Port-Type       [61]  6   Eth                       [15]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  User-Name           [1]   19  "DIFC\adil.ibrahim"&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Called-Station-Id   [30]  19  "00-12-7F-72-2F-03"&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Calling-Station-Id  [31]  19  "00-0D-60-FB-89-C0"&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Framed-MTU          [12]  6   1500                      &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  EAP-Message         [79]  24  &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   02 00 00 16 01 44 49 46 43 5C 61 64 69 6C 2E 69  [?????DIFC\adil.i]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   62 72 61 68 69 6D                                [brahim]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Message-Authenticato[80]  18  &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   89 B1 E7 61 43 EF 6A 7B E5 7D 95 AF 94 12 26 B6  [???aC?j{?}????&amp;amp;?]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: Received from id 1645/7 10.200.2.2:1812, Access-Reject, len 56&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  authenticator 96 7E 41 5A 20 48 28 F1 - B7 F7 26 21 F5 B0 82 92&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  EAP-Message         [79]  6   &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   04 00 00 04                                      [????]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Reply-Message       [18]  12  &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   52 65 6A 65 63 74 65 64 0A 0D                    [Rejected??]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS:  Message-Authenticato[80]  18  &lt;/P&gt;&lt;P&gt;1d21h: RADIUS:   00 D6 71 93 0F 2F 61 FB 01 1A 69 53 B3 3B E5 3A  [??q??/a???iS?;?:]&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: EAP-login: length of eap packet = 4 &lt;/P&gt;&lt;P&gt;1d21h: RADIUS: EAP-login: got reject from radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it keeps on giving me below error whenover i connect a laptop to this AAA client.&lt;/P&gt;&lt;P&gt;1d21h: RADIUS: EAP-login: length of eap packet = 4 &lt;/P&gt;&lt;P&gt;1d21h: RADIUS: EAP-login: got reject from radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 13:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434783#M428053</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-14T13:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434784#M428054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you read through the guide above? or any guide?&lt;/P&gt;&lt;P&gt;I'm a little confused as to how you have your setup configured.&lt;/P&gt;&lt;P&gt;The reason your authentication is failing now, is because either:&lt;/P&gt;&lt;P&gt;a) The user doesn't exist on the radius server&lt;/P&gt;&lt;P&gt;b) Unsupported authentication method (PEAP, PAP, CHAP etc.. not enabled on your acs)_&lt;/P&gt;&lt;P&gt;c) Other user restrictions in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your using the Cisco ACS, you should be able to check the 'failed attempts' log to find out why the authentication wasn't sucessful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can you post the log, along with the dot1x config for your switch up. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2005 14:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434784#M428054</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-14T14:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434785#M428056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shaw,&lt;/P&gt;&lt;P&gt;i am able to authenticate users via radius know but only those users which i have created in my ACS manaully. Also i've specified external database of my Active Directory in my ACS BUT the users from AD are not being authenticated. Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Dec 2005 14:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434785#M428056</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-18T14:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434786#M428058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to configure the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EXTERNAL USER DATABASES:&lt;/P&gt;&lt;P&gt; - Unknown user policy: make sure the option to check    the databse instead of fail attempt is selected.&lt;/P&gt;&lt;P&gt; - Database Group Mapping: ensure that the unknown users are being placed in the correct ACS group when they are automatically added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check in the failed attempts log to see why the users are not being authenticated.. please post the log so I can better advise you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2005 11:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434786#M428058</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-19T11:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434787#M428059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've gone through the Logs and have found the following errors:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i firts tried to login using the MD5 Authentication from XP Machine, ACS generated the following error: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"12/19/2005 19:20:59 Authen failed DIFC\adil.ibrahim .. 00-00-39-28-94-B8 Auth type not supported by External DB"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Later when i tried to login with PEAP authentication ACS generated this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Date  Time Message-Type User-Name Group-Name Caller-ID Authen-Failure-Code Author-Failure-Code Author-Data NAS-Port NAS-IP-Address &lt;/P&gt;&lt;P&gt;12/19/2005 19:27:10 Authen failed DIFC\adil.ibrahim .. 00-0D-60-5F-B8-40 EAP type not configured check Global Authentication Setup page .. .. 50102 10.200.2.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After all this when i went to System Configuration&amp;gt; Global Authentication Setup and checked marked the  &lt;/P&gt;&lt;P&gt;Allow EAP-MSCHAPv2 &lt;/P&gt;&lt;P&gt;Allow EAP-GTC  under PEAP settings and said submit and restart, it gave me the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication configuration errors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failed to initialize PEAP or EAP-TLS authentication protocol because ACS certificate is not installed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will bring us to final solution of this ACS to be operation. Your comments are really appreciated and helpfull.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Dec 2005 14:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434787#M428059</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-20T14:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434788#M428060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just select the "allow EAP-MSCHAPv2" option in Global Authentication Setup, and leave EAP-GTC un-checked. This should enable MS-Chap v2 without any problems, and this should now work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use any of the certificate based authentication methods (PEAP, EAP-TLS) then you will need obtain a certificate for your server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try enabling the EAP-MSCHAPv2 and let me know if it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2005 10:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434788#M428060</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-21T10:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434789#M428061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by just selecting "allow EAP-MSCHAPv2" under PEAP it still keeps on giving me the same error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Failed to initialize PEAP or EAP-TLS authentication protocol because ACS certificate is not installed." &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2005 13:25:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434789#M428061</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-21T13:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434790#M428062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to use PEAP then you will need to install a certificate on your server, and all your clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use Just MD5 for Dot1x.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ensure the EAP-MD5 box is checked on the Global authentication page, and that the MS-CHAP version 1  version 2 authentication boxes are checkd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In you client, select the authentication EAP type to be "MD5-Challenge".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2005 13:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434790#M428062</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-21T13:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434791#M428063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i doubt that under ACS active directory with dot1x authentication, it wont support MD5. Well anyway i'll try that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;further more if i need to install a certificate on server, how can i obtain it both for the client and acs server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2005 15:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434791#M428063</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-21T15:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434792#M428064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MD5 will work as an authentication method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use a certificate then you will need a certificate server to obtain the certificates from. Do you have one of these, or can you set them up? Have you worked with certificates before? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Installing a certificate on the ACS is documented in the ACS help section. For clients, just install the certificate in the usual way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2005 16:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434792#M428064</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-21T16:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434793#M428065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;back again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;using md5 login method it gives error "Auth type not supported by External DB"&lt;/P&gt;&lt;P&gt;AND AFTER configuring PEAP support and using PEAP login method from end users machine it gives the following error "EAP-TLS or PEAP authentication failed during SSL handshake"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way i haven't install the certificate on client. Do i need to install it on client machine also , if yes, pls let me know how to install it a client machine which is not part of domain. I just need to test it before i implement it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;now where is the probelm. what needs to be sorted out. Pls help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2005 12:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434793#M428065</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-25T12:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434794#M428067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just to let u know, that i was missing the certificate installation on client side. i have done the certificate installation on client side and know when i try to put the login credentials it generates following error in log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"12/25/2005 18:20:42 Authen failed DIFC\adil.ibrahim .. 00-10-C6-CD-5F-67 External DB account Restriction .. .. 50102 10.200.2.1 "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've checked thier is no any kind of time restirction for the mapped group. Pls help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Dec 2005 14:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434794#M428067</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2005-12-25T14:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434795#M428069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check if you have the "Dialin Permission" option checked within&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External User Databases -&amp;gt; Database Configuration -&amp;gt; Windows Databse -&amp;gt; Configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is checked, then the user needs to have Dialin Permission within the Active Directory Account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check if you have any logs within AD to see why the user authentication failed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Dec 2005 12:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434795#M428069</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-12-28T12:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS authentication with 3750 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434796#M428071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Back again....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first of all i would like to thank you for all the help you provided to me ....yeh my acs seems to be working with Active directory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am able to login my machine after i conf a cert server and install the cert on client machine...it works fine...but know when my login with my domain ID and try to change my domain password it gives me error that MYDOMAIN not available.....where can be the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2006 17:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-authentication-with-3750-switch/m-p/434796#M428071</guid>
      <dc:creator>bws</dc:creator>
      <dc:date>2006-01-17T17:00:25Z</dc:date>
    </item>
  </channel>
</rss>

