<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dot1x issues inside cisco switch with Cisco ACS 5.7 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743395#M54439</link>
    <description>&lt;P&gt;dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configured my switch to support dot1x on each port but some of the ports after restarting the pc or laptop its not working the dot1x in each port is below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface GigabitEthernet1/0/19&lt;BR /&gt;&amp;nbsp;description Client Access EndPoint&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;BR /&gt;&amp;nbsp;switchport port-security&lt;BR /&gt;&amp;nbsp;switchport port-security mac-address sticky&lt;BR /&gt;&amp;nbsp;switchport port-security mac-address sticky 0021.9b6d.ea8b&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-host&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout server-timeout 5&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout supp-timeout 10&lt;BR /&gt;&amp;nbsp;dot1x max-req 10&lt;BR /&gt;&amp;nbsp;dot1x max-reauth-req 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all the users are loged in via the domain username and password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the below error message i get inside the ACS 5.7&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/dot1x_errors.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its urgent can somebody please send check my config if its ok or having issues please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RG&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:58:18 GMT</pubDate>
    <dc:creator>Waisudin Farzam</dc:creator>
    <dc:date>2019-03-11T05:58:18Z</dc:date>
    <item>
      <title>Dot1x issues inside cisco switch with Cisco ACS 5.7</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743395#M54439</link>
      <description>&lt;P&gt;dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configured my switch to support dot1x on each port but some of the ports after restarting the pc or laptop its not working the dot1x in each port is below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface GigabitEthernet1/0/19&lt;BR /&gt;&amp;nbsp;description Client Access EndPoint&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;BR /&gt;&amp;nbsp;switchport port-security&lt;BR /&gt;&amp;nbsp;switchport port-security mac-address sticky&lt;BR /&gt;&amp;nbsp;switchport port-security mac-address sticky 0021.9b6d.ea8b&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-host&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout server-timeout 5&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;dot1x timeout supp-timeout 10&lt;BR /&gt;&amp;nbsp;dot1x max-req 10&lt;BR /&gt;&amp;nbsp;dot1x max-reauth-req 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all the users are loged in via the domain username and password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the below error message i get inside the ACS 5.7&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/dot1x_errors.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its urgent can somebody please send check my config if its ok or having issues please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RG&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743395#M54439</guid>
      <dc:creator>Waisudin Farzam</dc:creator>
      <dc:date>2019-03-11T05:58:18Z</dc:date>
    </item>
    <item>
      <title>From the error, its clear</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743396#M54444</link>
      <description>&lt;P&gt;From the error, its clear that ACS is not able to find the user identity in the configured identity store under your access policy. Check your access policy.&lt;/P&gt;&lt;P&gt;Check the details of the log, whether ACS is trying to contact AD to retrieve username from the AD or not. Whether AD is reachable and shows joined and connected.&lt;/P&gt;&lt;P&gt;If you have multiple domain controllers in the domain then check to which domain controller ACS is joined to. If it is joined to remote domain controller then join it manually with your local domain controller using the below command in acs-config mode.&lt;/P&gt;&lt;P&gt;ad-agent-configuration dns.dc.&amp;lt;domain.name&amp;gt;: [hostname1],[hostname2] ...&lt;BR /&gt;ad-agent-configuration dns.gc.&amp;lt;domain.name&amp;gt;: [hostname1],[hostname2] ...&lt;/P&gt;&lt;P&gt;Sometimes due to delay in response from AD also causes this issue.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 09:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743396#M54444</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2015-08-11T09:54:36Z</dc:date>
    </item>
    <item>
      <title>dear brother. i have checked</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743397#M54451</link>
      <description>&lt;P&gt;dear brother.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have checked both the domain and acs configs there is no issues or errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the only things is that clients should authenticate after they logeding to their pc or laptop with their domain username and password, but after they login there is no network connectivity and dotx errors should inside ACS that they have been authenticated via the mac address so the mac address comes to their username and password section.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when i shutdown and unshutdown the interface they login and dot1x works fine for them so can you tell me what could be the problem brother.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see attached files for more info also my lan card properties for Dot1x authetication is that when client login it should take its autheticatioin from logeding useranema nd password which is their current domain account and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RG&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 07:35:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743397#M54451</guid>
      <dc:creator>Waisudin Farzam</dc:creator>
      <dc:date>2015-08-12T07:35:43Z</dc:date>
    </item>
    <item>
      <title>This is a really confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743398#M54456</link>
      <description>&lt;P&gt;This is a really confusing config. My suggestions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change order to 802.1x first, second MAB.&lt;/P&gt;&lt;P&gt;In the client config, change from User auth to "Computer AND User", then create an authz policy that matches computer authentications and possibly give them limited network access (so they can be allowed to perform a proper Active Directory login).&lt;/P&gt;&lt;P&gt;This is how you normally do wired 802.1x for domain PCs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any perticular reasons why you want MAB as primary method?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 13:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-issues-inside-cisco-switch-with-cisco-acs-5-7/m-p/2743398#M54456</guid>
      <dc:creator>Andreas di Zazzo</dc:creator>
      <dc:date>2015-08-12T13:11:37Z</dc:date>
    </item>
  </channel>
</rss>

