<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x, xp, amd 2950 connectivity issues.. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291324#M435578</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same problem with the IAS 2003 wizard.&lt;/P&gt;&lt;P&gt;The RAS Policies was "NAS Port= Ethernet", but my swith  3550 sent NAS port= Async. I could see that with a sniffer in the values for RADIUS Attribute 61 (rfc 2865), the value for Ethernet is 15 and for Async is 0.&lt;/P&gt;&lt;P&gt;First i changed my policie swith NAS port= Async and the authentication is OK. After i put the last Ios version on the 3550, then the swith sent the good value for the radius attribute 61, then i changed my policie with NAS port= Ethernet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Aug 2004 12:18:01 GMT</pubDate>
    <dc:creator>aaffolter</dc:creator>
    <dc:date>2004-08-10T12:18:01Z</dc:date>
    <item>
      <title>dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291316#M435570</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am trying out port authentication on a cisco catalyst 2950g-24-ei switch and am having the following problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xp laptop ----------switch-----------Win 2k IAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up the cisco with the following commands :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa auth dot1x default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int f0/24&lt;/P&gt;&lt;P&gt;switchport mode-access&lt;/P&gt;&lt;P&gt;dot1x port-control auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 1.2.3.4 auth-port 1812 acct-port 1813 key radkey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up a client within IAS with the correct shared secret and vendor as cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem i am having is that once i connect the laptop to the port it turns immediately orange and i try to authenticate but the port stays orange and i receive the message once logged in that the laptop was unbale to connect to network. The message in the windows eventviewer is that " user attempted to use an unauthorised authentication method ".&lt;/P&gt;&lt;P&gt;Obviously the laptop does not receive a correct ip and can not talk on the network,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anyone have any suggestions ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291316#M435570</guid>
      <dc:creator>rsd1234</dc:creator>
      <dc:date>2019-03-10T20:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291317#M435571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use DHCP in your network ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2004 20:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291317#M435571</guid>
      <dc:creator>umedryk</dc:creator>
      <dc:date>2004-07-02T20:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291318#M435572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sounds like normal behavior. The port turns orange b/c spanning-tree isn't even in a forwarding state on an 802.1x-enabled port until the port is authorized via 802.1x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestion would be to find out why 802.1x isn't working. The config on the switch looks OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're running PEAP, the PC is probably trying to login via cached credentials. If you're running TLS, you need to insure certs are present on the PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should help:&lt;/P&gt;&lt;P&gt;&amp;lt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/8021x_client_configure.mspx" target="_blank"&gt;http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/8021x_client_configure.mspx&lt;/A&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Jul 2004 13:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291318#M435572</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2004-07-03T13:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291319#M435573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Richard!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you already solve your problem because i got exactly the same one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be, that the Cisco 2950 doesn´t Support EAP-MSCHAP v2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Rudolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2004 12:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291319#M435573</guid>
      <dc:creator>scholzr74</dc:creator>
      <dc:date>2004-08-05T12:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291320#M435574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rudolf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I didnt get a chance to look in to this further as I was called on to another project. I will be re-visiting this some time soon so if you come up with a solution I would be most grateful to hear from you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2004 17:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291320#M435574</guid>
      <dc:creator>rsd1234</dc:creator>
      <dc:date>2004-08-05T17:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291321#M435575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal behavior. The port begins amber b/c the port has not been authenticated. You should notice the port in an up/down status, and spanning-tree will not be in a forwarding state either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The port will turn green when 802.1x has successfully authenticated the port (up/up status, and spanning-tree is in a forwarding state).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need more info to determine root cause.&lt;/P&gt;&lt;P&gt;FYI, the switch doesn't really have visibility into PEAP+MS-CHAPv2. It transposes whatever the PC is sending it, and re-encapsulates the EAP conversation into RADIUS frames.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of quick things to check:&lt;/P&gt;&lt;P&gt;sho dot1x int&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the port in a HELD state, this should mean that 802.1x actually failed (so look on the PC, IAS, and/or backend DB to determine why).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the port in a CONNECTING state, this should mean that 802.1x isn't enabled on the PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further debugging can be performed on the XP supplicant by enabling tracing:&lt;/P&gt;&lt;P&gt;netsh ras set tracing * enable&lt;/P&gt;&lt;P&gt;This enables tracing for all components on the supplicant (namely eap and mschapv2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify tracing logs:&lt;/P&gt;&lt;P&gt;Explore to the C:\WINDOWS\tracing folder.&lt;/P&gt;&lt;P&gt;This folder should then contain the sets of traces for the components invoked from the command above.&lt;/P&gt;&lt;P&gt;Study the RASEAP, RASCHAP, RASTLS files for this context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2004 17:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291321#M435575</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2004-08-05T17:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291322#M435576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi thanks, i will try this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meanwhile i found another solution.I found the problem in the RAS Policies on the IAS Server (Windows 2003 Enterprise). I made my RAS Policies with the wizard for ethernet. If I checked my RAS Policies there was a term like "NAS Port = "Ethernet". I canceled this one and then it worked promptly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange thing is, that my RAS Policies for WLAN with "NAS Port = "802.11" OR "WLAN " work perfectly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;Rudolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2004 05:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291322#M435576</guid>
      <dc:creator>scholzr74</dc:creator>
      <dc:date>2004-08-06T05:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291323#M435577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is port authentication supposed to work at the same time as a users logs on to a network ? I am trying to get a user to log on to a system using an rsa token and want the following to happen :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. user presses ctrl - alt - del on client and enters uname and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Info is taken by catalyst 2950 running port authentication and passed on to 2003 server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. the uname and password is authentacted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. port is opened and user is then prompted by ace server for tokencode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. tokencode accepted and user has acces to the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this possible, has anyone done this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you have a single authentication for the cisco port and the domain and can this be forwarded to an ace server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice is much appreciated,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Aug 2004 14:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291323#M435577</guid>
      <dc:creator>rsd1234</dc:creator>
      <dc:date>2004-08-09T14:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291324#M435578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same problem with the IAS 2003 wizard.&lt;/P&gt;&lt;P&gt;The RAS Policies was "NAS Port= Ethernet", but my swith  3550 sent NAS port= Async. I could see that with a sniffer in the values for RADIUS Attribute 61 (rfc 2865), the value for Ethernet is 15 and for Async is 0.&lt;/P&gt;&lt;P&gt;First i changed my policie swith NAS port= Async and the authentication is OK. After i put the last Ios version on the 3550, then the swith sent the good value for the radius attribute 61, then i changed my policie with NAS port= Ethernet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2004 12:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291324#M435578</guid>
      <dc:creator>aaffolter</dc:creator>
      <dc:date>2004-08-10T12:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291325#M435579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. This is CSCec86385.&lt;/P&gt;&lt;P&gt;You should be able to see the Releae Notes indicating the fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was fixed in the following releases:&lt;/P&gt;&lt;P&gt;12.1(20)EA2 &lt;/P&gt;&lt;P&gt;12.2(20)SE&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2004 13:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291325#M435579</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2004-08-10T13:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x, xp, amd 2950 connectivity issues..</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291326#M435580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ist there the same problem with den Cat 2950? I´using IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(14)EA1a, RELEASE SOFTWARE(fc1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Isn´t this the latest os version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance,&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;rudolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Aug 2004 15:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-xp-amd-2950-connectivity-issues/m-p/291326#M435580</guid>
      <dc:creator>scholzr74</dc:creator>
      <dc:date>2004-08-10T15:16:55Z</dc:date>
    </item>
  </channel>
</rss>

