<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA NPS RADIUS 3650 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412789#M548008</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a little problem configuring my 3650 stack to work with my Server 2012 NPS radius.&lt;/P&gt;
&lt;P&gt;It works actually with my wifi wlc config (eap tls with certificate!) but switches are giving me hard work !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that I can put any PC on any port &lt;U&gt;without any check fron the wsitch&lt;/U&gt;. I also don't see anything in the NPS logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I lack somethine in there? ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Here is my conf :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;vesion 16.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authentication dot1x method_list group radius&lt;BR /&gt;aaa authorization network default group radius&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;&amp;nbsp;description ### PC User ###&lt;BR /&gt;&amp;nbsp;switchport access vlan 22&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 7&lt;BR /&gt;&amp;nbsp;access-session port-control auto&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;radius server pri&lt;BR /&gt;&amp;nbsp;address ipv4 192.168.22.110 auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;key 7 033fdskjfqdskjhfdqkj&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 19:00:30 GMT</pubDate>
    <dc:creator>alfredit</dc:creator>
    <dc:date>2020-02-21T19:00:30Z</dc:date>
    <item>
      <title>AAA NPS RADIUS 3650</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412789#M548008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a little problem configuring my 3650 stack to work with my Server 2012 NPS radius.&lt;/P&gt;
&lt;P&gt;It works actually with my wifi wlc config (eap tls with certificate!) but switches are giving me hard work !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that I can put any PC on any port &lt;U&gt;without any check fron the wsitch&lt;/U&gt;. I also don't see anything in the NPS logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do I lack somethine in there? ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Here is my conf :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;vesion 16.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authentication dot1x method_list group radius&lt;BR /&gt;aaa authorization network default group radius&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;&amp;nbsp;description ### PC User ###&lt;BR /&gt;&amp;nbsp;switchport access vlan 22&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 7&lt;BR /&gt;&amp;nbsp;access-session port-control auto&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;radius server pri&lt;BR /&gt;&amp;nbsp;address ipv4 192.168.22.110 auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;key 7 033fdskjfqdskjhfdqkj&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412789#M548008</guid>
      <dc:creator>alfredit</dc:creator>
      <dc:date>2020-02-21T19:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: AAA NPS RADIUS 3650</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412795#M548009</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Have you actually defined the the server group 'radius' ? If not try the following, (as a personal best practice, always make text variables uppercase):&lt;/P&gt;
&lt;PRE&gt;!
aaa group server radius RADIUS-SERVERS
  server 192.168.22.110
!
aaa authentication dot1x default group RADIUS-SERVERS
aaa authentication dot1x method_list group RADIUS-SERVERS
aaa authorization network default group RADIUS-SERVERS
!&lt;/PRE&gt;
&lt;P&gt;If the group is already defined. Have you tried the &lt;STRONG&gt;test aaa&lt;/STRONG&gt; command?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 16:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412795#M548009</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2018-07-09T16:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: AAA NPS RADIUS 3650</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412802#M548010</link>
      <description>&lt;P&gt;The radius group is the default one, I tested with a user but I do not know how to test my computer certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;SW-CD-17EME#test aaa group radius user1 password1 new-code&lt;BR /&gt;User successfully authenticated&lt;BR /&gt;&lt;BR /&gt;USER ATTRIBUTES&lt;BR /&gt;&lt;BR /&gt;Framed-Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 1 [PPP]&lt;BR /&gt;service-type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 2 [Framed]&lt;BR /&gt;noescape&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; True&lt;BR /&gt;autocmd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; " ppp negotiate"&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 16:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-nps-radius-3650/m-p/3412802#M548010</guid>
      <dc:creator>alfredit</dc:creator>
      <dc:date>2018-07-09T16:56:41Z</dc:date>
    </item>
  </channel>
</rss>

