<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x with ACS 3.3 and windowsXP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355754#M432924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kschuster,thanks for your help!&lt;/P&gt;&lt;P&gt;I wanna authenticatite against windows database without nay certificate. It's possible? If you has the steps to make this configuration...&lt;/P&gt;&lt;P&gt;Ob.: The configuration with MD5 works ok, but I nead to create 2  users: one with domain/name an other with name, so I'm think that it's not correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jan 2005 18:30:31 GMT</pubDate>
    <dc:creator>gsales</dc:creator>
    <dc:date>2005-01-31T18:30:31Z</dc:date>
    <item>
      <title>802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355747#M432917</link>
      <description>&lt;P&gt;We are using RADIUS IETF in ACS and EAP MD5. &lt;/P&gt;&lt;P&gt;My switch is 2950 whith this commands:&lt;/P&gt;&lt;P&gt;radius-server host a.b.c.d&lt;/P&gt;&lt;P&gt;radius-server key cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa 0/1&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we try authenticate appears this error: "CS user unknown" in ACS reports.&lt;/P&gt;&lt;P&gt;Has somethings that we forget?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where I configure the respective VLAN to user when he authenticate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355747#M432917</guid>
      <dc:creator>gsales</dc:creator>
      <dc:date>2019-03-10T20:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355748#M432918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as the "CS user uknown" issue, this usually means that the user your using to authenticate, doesn't exist in the radius database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the user ID's manually entered or are they externally mapped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the VLAN assignment from the radius server, assign the following IETF RADIUS attributes to either the individual user or the groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[64] Tunnel-Type = VLAN&lt;/P&gt;&lt;P&gt;[65] Tunnel-Medium-Type = 802&lt;/P&gt;&lt;P&gt;[81] Tunnel-Private-Group-Id = VLAN NAME&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2005 10:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355748#M432918</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-07T10:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355749#M432919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CS User Unknown means that ACS doesn't know about the user. Have you defined the user that uses MD5 either locally in ACS or have you configured integration with a backend identity store?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for VLAN Assignment, you can configure this as either a per-user or per-group RADIUS Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jan 2005 17:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355749#M432919</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2005-01-17T17:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355750#M432920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I`m using 2950 and Cisco ACS. In my Windows XP, I did only this"Ativar authenticaçao IEEE 802.1x para esta rede --&amp;gt;MD5 Challenge".  I create one user in ACS database and assign the following IETF RADIUS attributes to this user: &lt;/P&gt;&lt;P&gt;[64] Tunnel-Type = VLAN &lt;/P&gt;&lt;P&gt;[65] Tunnel-Medium-Type = 802 &lt;/P&gt;&lt;P&gt;[81] Tunnel-Private-Group-Id = teste&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At my network icon apears: Authentication Fail&lt;/P&gt;&lt;P&gt;See some debug message on my switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Received AuthStart from Authenticator for supp_info=80D607DC&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Managed Timer in sub-block attached as leaf to master&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Going to Send Request to AAA Client on RP for id = 0 and length = 25&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Got a Request from SP to send it to Radius with id 7&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Couldn't Find a process thats already handling the request for this id 0&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Inserted the request on to list of pending requests&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Found a free slot at slot 0&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Found a free slot at slot 0&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Request id = 7 and length = 25&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:The Interface on which we got this AAA Request is FastEthernet0/1&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:Username is SMSTESTE\joe&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:MAC Address is 0026.540f.5555&lt;/P&gt;&lt;P&gt;03:09:14: dot1x-ev:MAC Address copied is 0026.540f.4c43&lt;/P&gt;&lt;P&gt;03:09:15: dot1x-ev:dot1x_post_message_to_auth_sm: Skipping tx for req_id for default supplicant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-err:EAP packet not recvd&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:going to send to backend on SP, length = 4&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Received VLAN is No Vlan&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Enqueued the response to BackEnd&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Received QUEUE EVENT in response to AAA Request&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Dot1x matching request-response found&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Length of recv eap packet from radius = 4&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:Received VLAN Id -1&lt;/P&gt;&lt;P&gt;03:09:34: dot1x-ev:dot1x_bend_fail_enter:0026.540f.5555: Current ID=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2005 18:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355750#M432920</guid>
      <dc:creator>gsales</dc:creator>
      <dc:date>2005-01-21T18:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355751#M432921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before, when you said ACS told you "CS User Unknown", what user did it tell you was unknown, and was it the exact one you put into Windows? Example: the native supplicant avail in Windows is most likely prepending your MD5 username as &lt;MACHINE-NAME&gt;\&lt;USER-NAME&gt;. So, if you only setup &lt;USER-NAME&gt; in ACS, it think they are different.&lt;/USER-NAME&gt;&lt;/USER-NAME&gt;&lt;/MACHINE-NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2005 19:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355751#M432921</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2005-01-21T19:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355752#M432922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's works now only if I create 2 users in ACS, one "username" and other "domain/username". I wanna use only windows database, but it don't works with only windows user. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jan 2005 17:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355752#M432922</guid>
      <dc:creator>gsales</dc:creator>
      <dc:date>2005-01-25T17:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355753#M432923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;as far as I know:&lt;/P&gt;&lt;P&gt;Authentication against windows database (AD) is not supported with EAP MD5. You have to use EAP PEAP, and you have to use certificates from a CA server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2005 13:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355753#M432923</guid>
      <dc:creator>kschuster</dc:creator>
      <dc:date>2005-01-27T13:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with ACS 3.3 and windowsXP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355754#M432924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kschuster,thanks for your help!&lt;/P&gt;&lt;P&gt;I wanna authenticatite against windows database without nay certificate. It's possible? If you has the steps to make this configuration...&lt;/P&gt;&lt;P&gt;Ob.: The configuration with MD5 works ok, but I nead to create 2  users: one with domain/name an other with name, so I'm think that it's not correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2005 18:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-acs-3-3-and-windowsxp/m-p/355754#M432924</guid>
      <dc:creator>gsales</dc:creator>
      <dc:date>2005-01-31T18:30:31Z</dc:date>
    </item>
  </channel>
</rss>

