<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Haidar, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-host-authentication-failure/m-p/2719022#M54511</link>
    <description>&lt;P&gt;Haidar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was able to have success if I changed&lt;STRONG&gt; &lt;SPAN style="text-decoration: underline;"&gt;the settings in WinRadius&lt;/SPAN&gt;&lt;/STRONG&gt;. Those are:&lt;/P&gt;
&lt;P&gt;Authorization Port 1645&lt;BR /&gt;Accounting Port 1646&lt;/P&gt;
&lt;P&gt;Let me know if that helps.&lt;/P&gt;
&lt;P&gt;-Jason&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jun 2016 08:18:20 GMT</pubDate>
    <dc:creator>jasonmadruga84</dc:creator>
    <dc:date>2016-06-26T08:18:20Z</dc:date>
    <item>
      <title>Dot1x host authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-host-authentication-failure/m-p/2719021#M54510</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Hi guys,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;I'm working on configuring 802.1x on a 3750 and a free WinRadius server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/fullsizerender.jpg" class="migrated-markup-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;WinRadius is up and running, I can even test authentication using the testing tool as per image.&lt;BR /&gt;&lt;BR /&gt;I've also ran the testing command from the switch to make sure that it can communicate with the Radius and it was successful:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Switch#test aaa group radius cisco cisco new-code&amp;nbsp;&lt;BR /&gt;User successfully authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;However, when I try to authenticate from the host/laptop I get an authentication failure. I do get prompted to enter the username and password. however, for some reason the Radius seems to be returning an failure to authenticate.&lt;BR /&gt;&lt;BR /&gt;Error on the switch shows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;*Mar &amp;nbsp;1 20:45:14.133: %LINK-3-UPDOWN: Interface FastEthernet1/0/16, changed state to up&lt;BR /&gt;*Mar &amp;nbsp;1 20:45:22.387: %DOT1X-5-FAIL: Authentication failed for client (ecf4.bb08.7e76) on Interface Fa1/0/16 AuditSessionID C0A80A1E0000001F0474044A&lt;BR /&gt;*Mar &amp;nbsp;1 20:45:22.387: %AUTHMGR-7-RESULT: Authentication result 'fail' from 'dot1x' for client (ecf4.bb08.7e76) on Interface Fa1/0/16 AuditSessionID C0A80A1E0000001F0474044A&lt;BR /&gt;*Mar &amp;nbsp;1 20:45:22.387: %AUTHMGR-5-FAIL: Authorization failed for client (ecf4.bb08.7e76) on Interface Fa1/0/16 AuditSessionID C0A80A1E0000001F0474044A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:12px;"&gt;Switch#sho authentication sessions int f1/0/16 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;FastEthernet1/0/16&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;Unknown&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;Unknown&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Running&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;UNKNOWN&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Policy: &amp;nbsp;Should Secure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Status: &amp;nbsp;Unsecure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;single-host&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;both&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;C0A80A1E0000002004751782&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x00000027&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0x4D000020&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Running&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-size:14px;"&gt;And on the Radius server it shows that user authentication failed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;I'm not sure where the issue is...&lt;BR /&gt;&lt;BR /&gt;Switch configuration for dot1x is:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;authentication mac-move permit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;interface FastEthernet1/0/16&lt;BR /&gt;&amp;nbsp;switchport access vlan 10&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;interface FastEthernet1/0/20&lt;BR /&gt;&amp;nbsp;switchport access vlan 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;interface Vlan10&lt;BR /&gt;&amp;nbsp;ip address 192.168.10.30 255.255.255.0&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;ip sla enable reaction-alerts&lt;BR /&gt;radius-server host 192.168.10.10 auth-port 1812 acct-port 1813 key WinRadius&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;I'm not sure what I'm doing wrong...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can you please have a look and advise??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-host-authentication-failure/m-p/2719021#M54510</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2019-03-11T05:57:37Z</dc:date>
    </item>
    <item>
      <title>Haidar,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-host-authentication-failure/m-p/2719022#M54511</link>
      <description>&lt;P&gt;Haidar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was able to have success if I changed&lt;STRONG&gt; &lt;SPAN style="text-decoration: underline;"&gt;the settings in WinRadius&lt;/SPAN&gt;&lt;/STRONG&gt;. Those are:&lt;/P&gt;
&lt;P&gt;Authorization Port 1645&lt;BR /&gt;Accounting Port 1646&lt;/P&gt;
&lt;P&gt;Let me know if that helps.&lt;/P&gt;
&lt;P&gt;-Jason&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 08:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-host-authentication-failure/m-p/2719022#M54511</guid>
      <dc:creator>jasonmadruga84</dc:creator>
      <dc:date>2016-06-26T08:18:20Z</dc:date>
    </item>
  </channel>
</rss>

