<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unauthorized devices authentication (RADIUS) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3817573#M484463</link>
    <description>Is it possible to put the switchport as errdisable after the authentication fail ?&lt;BR /&gt;&lt;BR /&gt;Not that I am aware of. If there is a way hopefully someone else will chime in.&lt;BR /&gt;&lt;BR /&gt;What you are looking for can be accomplished via this under your port configs:&lt;BR /&gt;#authentication event fail action authorize vlan ##&lt;BR /&gt;&lt;BR /&gt;HTH!</description>
    <pubDate>Mon, 11 Mar 2019 18:18:24 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-03-11T18:18:24Z</dc:date>
    <item>
      <title>Unauthorized devices authentication (RADIUS)</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3815656#M484460</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm working on a windows radius server, and a cisco switch 2960X.&lt;/P&gt;&lt;P&gt;Is it possible to put the switchport as errdisable after the authentication fail ?&lt;/P&gt;&lt;P&gt;I tried to configure the port security but it does not see the authentication fail as an security violation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So even when the authentication fail, it will still put the switchport on vlan1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your attention.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 14:24:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3815656#M484460</guid>
      <dc:creator>Teayuu</dc:creator>
      <dc:date>2019-03-07T14:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized devices authentication (RADIUS)</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3815751#M484461</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- In general this is not the intended purpose of&amp;nbsp; ISE as this has more fundamental consequences for the device and it's &lt;U&gt;network connection&lt;/U&gt;.&amp;nbsp; You may want to look into schemes such as &lt;FONT color="#0000FF"&gt;CoA&lt;/FONT&gt;, to isolate devices on quarantine VLAN's (that's only an example).&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 16:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3815751#M484461</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2019-03-07T16:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized devices authentication (RADIUS)</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3817243#M484462</link>
      <description>Thank you for your anwser.&lt;BR /&gt;&lt;BR /&gt;Do you know if it's possible to configure the access reject so it can be seen as a security violation ?</description>
      <pubDate>Mon, 11 Mar 2019 09:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3817243#M484462</guid>
      <dc:creator>Teayuu</dc:creator>
      <dc:date>2019-03-11T09:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unauthorized devices authentication (RADIUS)</title>
      <link>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3817573#M484463</link>
      <description>Is it possible to put the switchport as errdisable after the authentication fail ?&lt;BR /&gt;&lt;BR /&gt;Not that I am aware of. If there is a way hopefully someone else will chime in.&lt;BR /&gt;&lt;BR /&gt;What you are looking for can be accomplished via this under your port configs:&lt;BR /&gt;#authentication event fail action authorize vlan ##&lt;BR /&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Mon, 11 Mar 2019 18:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unauthorized-devices-authentication-radius/m-p/3817573#M484463</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-11T18:18:24Z</dc:date>
    </item>
  </channel>
</rss>

