<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there anyone using wired 802.1x in production? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469462#M428523</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of ACS are you using? What Catalyst operating system and Supervisor are you using?  What version of Catalyst OS are you using?  Which Microsoft operating system(s) are you using and approximately what service pack are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you configured to do after you authenticate a device?  Are you changing VLANs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Oct 2005 18:42:51 GMT</pubDate>
    <dc:creator>brford</dc:creator>
    <dc:date>2005-10-25T18:42:51Z</dc:date>
    <item>
      <title>Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469457#M428510</link>
      <description>&lt;P&gt;I have 802.1x configured with PEAP and vlan assignment using the MS supplicant.  I have hardcoded Machine Auth because Remote Desktop does not work with User Auth. (see my other posts) I have figured out how to change the Microsoft supplicant to PEAP with a vb script.  I have a catalyst 6509 enabled with 802.1x enabled on module 8 and 9 with about 60 actual PCs authenticated between to 2 modules.  At this point I am testing ACS redundancy (2 ACS SE) and any potential ACS load issues before campus deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  If I reset module 8 or 9 the switch reloads.  I guess it is overwhelmed by all the 802.1x requests.  I am not too concerned about this right now because this type of product quality is very common in this new era.  I have not reset another module in this switch that does not have 802.1x enabled.  Though, I have reset modules in the past.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  My main concern is the amount of time it takes for all the ports on a given module to finally 802.1x authenticate.  To avoid problem (1.), I disabled/enabled all ports on module 8.  It takes about 8-12 minutes before all 30+ ports are authenticated.  This behavior is the same after the reload.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It takes about 10 seconds for one supplicant to authenticate.  It appears the switch is serializing the logins in a loop until all are authenticated.  I calculate 384 ports * 10 seconds = 1.06 hour to authenticate after reload (best case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share your experiences or ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469457#M428510</guid>
      <dc:creator>jimmie25h69</dc:creator>
      <dc:date>2019-03-10T21:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469458#M428515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The time delay that you are seeing is just the way the 802.1x authentication works and there is nothing we can do about it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2005 13:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469458#M428515</guid>
      <dc:creator>s-doyle</dc:creator>
      <dc:date>2005-09-13T13:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469459#M428517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have dot1x enabled in production. Over thousand of supplicants. Terrible!! I found last week that while we reset one of the modules; the switch crashed. Because we have 2 Sup in one box, the switch did not reload but failed over to the standby SUP.&lt;/P&gt;&lt;P&gt;We have CatOS 8.4.1 and 8.4.5 in our environment; 2 ACSes for redundant purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not perceive the dealy you mention.We found that  a lot of supplicants could not be authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the trace that I found when switches crashed. Do you see the same output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pantree port fast start set to default for ports 6/29,6/34.&lt;/P&gt;&lt;P&gt;QRDCN05ACC01&amp;gt; (enable) set vlan 461 System reset on software watchdog is disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TLB Exception (load/instruction fetch) occurred on Sep 26 2005 16:15:00&lt;/P&gt;&lt;P&gt;Software version = 8.4(1)&lt;/P&gt;&lt;P&gt;Process ID #4c, Name = Backend_SM&lt;/P&gt;&lt;P&gt;process stack top = 3ff1b170, stack pointer = 3ff1b0e8&lt;/P&gt;&lt;P&gt;cause = 00000008&lt;/P&gt;&lt;P&gt;TLB Exception (load/instruction fetch) exception happened&lt;/P&gt;&lt;P&gt;    EPC: 210274A0&lt;/P&gt;&lt;P&gt;    Traceback: &lt;/P&gt;&lt;P&gt;        210274A0&lt;/P&gt;&lt;P&gt;        210274A0&lt;/P&gt;&lt;P&gt;    Stack content:&lt;/P&gt;&lt;P&gt;    sp+00: 00000006 00000006 21026C38 202ECAB0&lt;/P&gt;&lt;P&gt;    sp+10: 267AD970 22F9B290 22FA0000 00000006&lt;/P&gt;&lt;P&gt;    sp+20: 0000001D 00000030 00000005 21027230&lt;/P&gt;&lt;P&gt;    sp+30: 0000012C 00000000 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+40: 00000000 00000000 00000000 00000000&lt;/P&gt;&lt;P&gt;    sp+50: 00000000 00000000 00000000 00000000&lt;/P&gt;&lt;P&gt;    sp+60: 3FF1B150 20B4A2A0 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+70: 20B47BDC 20B47BDC 00000007 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+80: 00000000 20B4A250 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+90: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+A0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+B0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+C0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+D0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+E0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    sp+F0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC&lt;/P&gt;&lt;P&gt;    Register content:&lt;/P&gt;&lt;P&gt;      Status: 3400FC23    Cause: 00800008&lt;/P&gt;&lt;P&gt;AT: 22830000&lt;/P&gt;&lt;P&gt;          V0: 00000001       V1: 267AD970&lt;/P&gt;&lt;P&gt;          A0: 00000006       A1: 0000001D&lt;/P&gt;&lt;P&gt;          A2: 0000001C       A3: 22FA0000&lt;/P&gt;&lt;P&gt;          T0: 23C00BC0       T1: 3FFFF070&lt;/P&gt;&lt;P&gt;          T2: 00000001       T3: 00000007&lt;/P&gt;&lt;P&gt;          T4: 00007080       T5: 00000000&lt;/P&gt;&lt;P&gt;          T6: 00800000       T7: F03FFFFF&lt;/P&gt;&lt;P&gt;          S0: 22F9B290       S1: 00000000&lt;/P&gt;&lt;P&gt;          S2: 00000006       S3: 0000001D&lt;/P&gt;&lt;P&gt;          S4: 00000005       S5: 0000001C&lt;/P&gt;&lt;P&gt;          S6: 22FA0000       S7: 0000000D&lt;/P&gt;&lt;P&gt;          T8: FFFFFFFF       T9: 4B34A6A4&lt;/P&gt;&lt;P&gt;          K0: 30409001       K1: 215016E8&lt;/P&gt;&lt;P&gt;          GP: 2283AC70       SP: 3FF1B0E8&lt;/P&gt;&lt;P&gt;          S8: 00000007       RA: 2102742C&lt;/P&gt;&lt;P&gt;        HIGH: 0000001A      LOW: 0355485E&lt;/P&gt;&lt;P&gt;    BADVADDR: 00000002  ERR EPC: A3A3A3A3&lt;/P&gt;&lt;P&gt;Total download memory used = 3989996&lt;/P&gt;&lt;P&gt;crash info filename is bootflash:crashinfo_050926-161503&lt;/P&gt;&lt;P&gt;Opening crash info file bootflash:crashinfo_050926-161503&lt;/P&gt;&lt;P&gt;Time took to write crashinfo = 00:05.09&lt;/P&gt;&lt;P&gt;crashinfo finished&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2005 16:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469459#M428517</guid>
      <dc:creator>chilinh</dc:creator>
      <dc:date>2005-10-11T16:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469460#M428519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like we have a similar configuration and similar problem.  I also found that "a lot of supplicants could not be authenticated".  I think it is because of a timeout that appears to be within the 6509 chassis.  This is what I did to expose the timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I enabled security logging debug.  I disabled/enabled (1) port to see the normal output.  I incremented by (1) port until I reached (4) ports.  At (4) ports there is a TIMEOUT entry.  802.1x retries and the port eventually authenticates.  BUT when I authenticate up to 48 ports most ports do not authenticate.  I believe the MS supplicant quits trying at some point. Give it a try and let me know if you get the timeouts.  What hardware do you have 6000 or 4000 series?  I have a case open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set logging level security 7&lt;/P&gt;&lt;P&gt;2005 Sep 24 09:36:49 CDT -05:00 %SECURITY-7-DOT1X_BACKEND_STATE:DOT1X: backend state for port 8/41 is TIMEOUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2005 22:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469460#M428519</guid>
      <dc:creator>jimmie25h69</dc:creator>
      <dc:date>2005-10-11T22:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469461#M428521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;8.4(5) fixed both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bug ID CSCeh95025 - 802.1x simultaneous authentications fail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2005 21:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469461#M428521</guid>
      <dc:creator>jimmie25h69</dc:creator>
      <dc:date>2005-10-24T21:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469462#M428523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of ACS are you using? What Catalyst operating system and Supervisor are you using?  What version of Catalyst OS are you using?  Which Microsoft operating system(s) are you using and approximately what service pack are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you configured to do after you authenticate a device?  Are you changing VLANs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2005 18:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469462#M428523</guid>
      <dc:creator>brford</dc:creator>
      <dc:date>2005-10-25T18:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anyone using wired 802.1x in production?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469463#M428525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version of ACS are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS SE 1112&lt;/P&gt;&lt;P&gt;Cisco Secure ACS 3.3.2.2 &lt;/P&gt;&lt;P&gt;Appliance Management Software 3.3.2.1 &lt;/P&gt;&lt;P&gt;Appliance Base Image 3.3.1.6 &lt;/P&gt;&lt;P&gt;CSA build 4.0.1.543.2 (Patch: 4_0_1_543)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS SE 1111&lt;/P&gt;&lt;P&gt;Cisco Secure ACS 3.3.2.2 &lt;/P&gt;&lt;P&gt;Appliance Management Software 3.3.2.1 &lt;/P&gt;&lt;P&gt;Appliance Base Image 3.3.1.1-HP &lt;/P&gt;&lt;P&gt;CSA build 4.0.1.543.2 (Patch: 4_0_1_543)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What Catalyst operating system and Supervisor are you using?&lt;/P&gt;&lt;P&gt;8.4(5), SUP2/PFC2&lt;/P&gt;&lt;P&gt;Crashed once when 802.1x was disabled on a port after upgrading to 8.4(5)&lt;/P&gt;&lt;P&gt;"set port dot1x 7/26 port-control force-authorized"&lt;/P&gt;&lt;P&gt;Possibly related to bugs CSCei80863 and CSCsc02053&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of Catalyst OS are you using?&lt;/P&gt;&lt;P&gt;WS-C6509 Software, Version NmpSW: 8.4(5)&lt;/P&gt;&lt;P&gt;Copyright (c) 1995-2005 by Cisco Systems&lt;/P&gt;&lt;P&gt;NMP S/W compiled on Aug  3 2005, 12:01:19&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which Microsoft operating system(s) are you using and approximately what service pack are you running? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All are XP SP2. updates are current within 30-45 days. The PCs are PEAP with registry keys AuthMode=2, SupplicantMode=3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are you configured to do after you authenticate a device?&lt;/P&gt;&lt;P&gt;Authenticating a PC only once unless port state changes.&lt;/P&gt;&lt;P&gt;Dynamic vlan assignment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you changing VLANs?&lt;/P&gt;&lt;P&gt;yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2005 21:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-there-anyone-using-wired-802-1x-in-production/m-p/469463#M428525</guid>
      <dc:creator>jimmie25h69</dc:creator>
      <dc:date>2005-10-25T21:52:05Z</dc:date>
    </item>
  </channel>
</rss>

