<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3Com VSA and 802.1x end-station authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479248#M428370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "Bad request from NAS" error indicates one of four things:&lt;/P&gt;&lt;P&gt;1.  Invalid key - (do not cut and paste as this cause a key mismatch)&lt;/P&gt;&lt;P&gt;2.  Wrong IP in authentication request &lt;/P&gt;&lt;P&gt;3.  Wrong protocol specified in Network Configuration for NAS &lt;/P&gt;&lt;P&gt;4.  Special characters in Key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Oct 2005 12:56:57 GMT</pubDate>
    <dc:creator>didyap</dc:creator>
    <dc:date>2005-10-13T12:56:57Z</dc:date>
    <item>
      <title>3Com VSA and 802.1x end-station authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479247#M428367</link>
      <description>&lt;P&gt;I am using the CiscoSecure ACS v3.3 build 11 on Windows to handle authentication of some network devices.  I had added in a VSA for our 3Com 4400-series switches which allowed us to authenticate against our Windows AD for administration of the switches.  The VSA is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;[User Defined Vendor]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name=3Com&lt;/P&gt;&lt;P&gt;IETF Code=43&lt;/P&gt;&lt;P&gt;VSA 1=3Com-User-Access-Level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[3Com-User-Access-Level]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type=INTEGER&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt;Enums=3Com-User-Access-Level-Values&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[3Com-User-Access-Level-Values]&lt;/P&gt;&lt;P&gt;1=Monitor&lt;/P&gt;&lt;P&gt;2=Manager&lt;/P&gt;&lt;P&gt;3=Administrator&lt;/P&gt;&lt;P&gt;------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been working well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The complication started when I was tasked with implementing 802.1x authentication for the end-nodes on these 4400-series switches (Windows XPsp2 clients).  After doing the initial configuration, I was getting a "Bad request from NAS" in the ACS logs.   As I feared, the fact that the 4400s, the NASes, were using the Radius (3Com) interface configuration as shown above, this seems to exclude the 802.1x authentication from happening.  I moved the 4400 in question out of the radius group using the 3com VSA and into just a IETF Radius VSA and the users were able to authenticate just fine using 802.1x.  Of course, it seems to be one or the other, I can't seem to have radius authentication to the switches themselves AND authentication of devices hanging off the switch at the same time.  I suspect that if I add the IETF parameters to the VSA above, I might be able to accomplish both, but I don't know what the format would look like.  Of course, I can't have the switch in two different AAA Client groups, so one client group needs to be able to do both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479247#M428367</guid>
      <dc:creator>srogala</dc:creator>
      <dc:date>2019-03-10T21:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: 3Com VSA and 802.1x end-station authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479248#M428370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "Bad request from NAS" error indicates one of four things:&lt;/P&gt;&lt;P&gt;1.  Invalid key - (do not cut and paste as this cause a key mismatch)&lt;/P&gt;&lt;P&gt;2.  Wrong IP in authentication request &lt;/P&gt;&lt;P&gt;3.  Wrong protocol specified in Network Configuration for NAS &lt;/P&gt;&lt;P&gt;4.  Special characters in Key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2005 12:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479248#M428370</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2005-10-13T12:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: 3Com VSA and 802.1x end-station authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479249#M428373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.  I figure one of those is probably true, especially since the information being passed as an administrator trying to connect to the switch autenticating against the ACS is going to be different than an 802.1x user trying to authenticate against the ACS.  The problem right now is that it's an either/or scenario, and I'm trying to figure out how to make it so that the tacacs+ authentication to the switch AND 802.1x authentication can occur at the same time, which would seem to involve having a VSA that incorporated elements of both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short -&lt;/P&gt;&lt;P&gt;1. Configure the ACS to handle the 3Com VSA, then you can authenticate against the switch via tacacs+ but not 802.1x users (get the "Bad request from NAS" error, which I would expect)&lt;/P&gt;&lt;P&gt;2. Configure the ACS to handle the 3com via just straight radius and then 802.1x authentication works, but authentication for administration to the switch doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally, both should be able to occur at the same time I would think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Oct 2005 14:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3com-vsa-and-802-1x-end-station-authentication/m-p/479249#M428373</guid>
      <dc:creator>srogala</dc:creator>
      <dc:date>2005-10-13T14:04:30Z</dc:date>
    </item>
  </channel>
</rss>

