<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433195#M527749</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not finding H3C_AV_PAIR attribute in ISE. If you imported it or modified an existing RADIUS vendor dictionary, please provide a copy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is HPWired selected as the NAD profile in the NAD definition for this switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've not been able to see "&lt;SPAN style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-size: 9pt; font-family: Arial, sans-serif; color: red; background-color: #fafafa;"&gt;Rejected per authorization profile&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;". Instead, HP:Egress-VLAN-Name is not showing up if I enabled "Allow Tagging"; HP:Egress-VLAN-Name is showing up if disabled "Allow Tagging" but not properly, either:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Egress-VLAN-Name = "&lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;1:&lt;/STRONG&gt;&lt;/SPAN&gt;VLAN-TOIP"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Tunnel-Type:1 = VLAN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Tunnel-Medium-Type:1 = IEEE-802&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, is your ISE 2.3 upgraded from a previous release? Did you use the migration tool to import ACS 5.8 data to ISE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 12 Aug 2017 04:42:34 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-08-12T04:42:34Z</dc:date>
    <item>
      <title>Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433192#M527745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a new behavior with ISE and HPE Comware swicth when trying to authenticate Cisco IP Phone on the network using MD5.&lt;/P&gt;&lt;P&gt;I configured Authorization Profile named "VLANTOIP" with these attributes:&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;Egress-VLAN-Name = 1:VLAN-TOIP&lt;/P&gt;&lt;P&gt;H3C_AV_PAIR = device-traffic-class=voice&lt;/P&gt;&lt;P&gt;Tunnel-Medium-Type = 1:6 // This line is translated in ISE to indicate 802&lt;/P&gt;&lt;P&gt;Tunnel-Type = 1:13 // This line is translated in ISE to indicateVLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All other Authentication policies and Authorization Policies configuration are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the Phone try to access to the network, it is rejected by the AUthorization Profile and ISE says:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: red; background: #FAFAFA;"&gt;15039 Rejected per authorization profile&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;Selected Authorization Profile contains ACCESS_REJECT attribute&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;Authorization profile/s specified are not suited for this Network Access Device&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;The same configuration in ACS 5.8.1.4 is working fine!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="color: #666666; background: #FAFAFA; font-size: 9.0pt; font-family: 'Arial','sans-serif';"&gt;&lt;SPAN&gt;My question is:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;1. Why this configuration works with ACS and not with ISE?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;2. Why when I change the "H3C_AV_PAIR = device-traffic-class=voice" attribute to "cisco-av-pair = device-traffic-class=voice" and "Egress-VLAN-Name = 1:VLAN-TOIP" to "Tunnel-Private-Group-ID = 1:VLAN-TOIP" the IP Phone can access the network without issue?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;Any reply will be appreciated!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #666666; background: #FAFAFA;"&gt;&lt;SPAN&gt;Best regard&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 05:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433192#M527745</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-08-10T05:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433193#M527747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't worked with non-Cisco switches before so this is just a guess.&amp;nbsp; In your Network Device definition of the switch did you set it to an HP device profile?&amp;nbsp; That is the only spot I can think of that ISE would have awareness of the type of NAD device.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/110355_Capture.JPG" style="height: 436px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Aug 2017 12:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433193#M527747</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-08-10T12:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433194#M527748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi paul@berbee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. It was helpeful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue was not in the NAD profile (I can choose every profile).&lt;/P&gt;&lt;P&gt;It was an issu on the Authorization Profile that I created with HPWired Profile. Because this is a Comware OS, i chosen &lt;STRONG&gt;Any&lt;/STRONG&gt; as "Network Device Profile" in the Authorization Profile and it worked well.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/110423_pastedImage_3.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the necessary attributes must be added in the "Advanced Attributes Settings".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Aug 2017 12:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433194#M527748</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-08-11T12:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433195#M527749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not finding H3C_AV_PAIR attribute in ISE. If you imported it or modified an existing RADIUS vendor dictionary, please provide a copy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is HPWired selected as the NAD profile in the NAD definition for this switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've not been able to see "&lt;SPAN style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="font-weight: inherit; font-style: inherit; font-size: 9pt; font-family: Arial, sans-serif; color: red; background-color: #fafafa;"&gt;Rejected per authorization profile&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;". Instead, HP:Egress-VLAN-Name is not showing up if I enabled "Allow Tagging"; HP:Egress-VLAN-Name is showing up if disabled "Allow Tagging" but not properly, either:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Egress-VLAN-Name = "&lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;1:&lt;/STRONG&gt;&lt;/SPAN&gt;VLAN-TOIP"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Tunnel-Type:1 = VLAN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Tunnel-Medium-Type:1 = IEEE-802&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, is your ISE 2.3 upgraded from a previous release? Did you use the migration tool to import ACS 5.8 data to ISE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Aug 2017 04:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433195#M527749</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-12T04:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433196#M527750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is critical that the Authorization Profile be set to 'Any' or to specific NAD Profile&amp;nbsp; AND&amp;nbsp; that the intended matching Authorization Policy Rule includes reference to the Authorization Profile which has been flagged as Any or Specific Profile name.&amp;nbsp; Otherwise, the rule may match, but will not find a compatible NAD profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Realize that you can overload the Permissions list with multiple AuthZ Profiles such that it can match NAD Profile for Cisco OR HP or Any.&amp;nbsp; Typically 'Any' would be used as a single entry versus multiple listing for specific NAD profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 19:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433196#M527750</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-14T19:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433197#M527752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hslai&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the H3C_AV_PAIR attribute is a modified attribute in ISE (previously added to the ACS 5.8.1.4 configuration). In attachment a capture for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes HPWired is selected as the NAD profile in the NAD definition for this switch but you can choose another one.&lt;/P&gt;&lt;P&gt;As I mentioned previously the issue was in the Profile defined in the&amp;nbsp; "Network Device Profile" in the Authorization Profile. Because the switch uses the Comware OS I choosed Any in the Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, is your ISE 2.3 upgraded from a previous release? Did you use the migration tool to import ACS 5.8 data to ISE?&lt;/P&gt;&lt;P&gt;==&amp;gt; Yes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Aug 2017 07:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433197#M527752</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-08-16T07:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433198#M527754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the HPWired profile does not match the requirements for Comware based model, then duplicate or create new profile and make necessary changes such as RADIUS dictionaries, CoA settings etc.&amp;nbsp; Any option is a bit more flexible for handling multiple NAD profiles, but will be limited in what it offers in Common tasks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is matching the correct AuthZ policy rule and AuthZ Profile and still failing, then may be issue with the attributes itself.&amp;nbsp; I would try returning same attribute in a simple policy for a Cisco device and see if it returns same error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, make sure the NAD Profile includes the RADIUS dictionary that holds special attribute for vendor-specific NAD profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Aug 2017 12:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433198#M527754</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-16T12:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IP Phone Authentication on ISE 2.3 using MD5 on HPE Comware switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433199#M527755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chyps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already resolved the issue. Please refer to my previous comments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Aug 2017 17:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ip-phone-authentication-on-ise-2-3-using-md5-on-hpe/m-p/3433199#M527755</guid>
      <dc:creator>B. BELHADJ</dc:creator>
      <dc:date>2017-08-16T17:50:49Z</dc:date>
    </item>
  </channel>
</rss>

