<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please Help Diagnose RADIUS Timeout in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/please-help-diagnose-radius-timeout/m-p/3375450#M549069</link>
    <description>&lt;P&gt;I am attempting to deploy 802.1x to my VPN sites, my NPS has the ports allowed on both inbound and outbound rules.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I am using 1812 for Authentication and 1813 for accounting (although 1645, 1646 are also allows on the NPS ports)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On a Cisco 3850-48P&amp;nbsp;(139.139.210.18) on interface G1/0/21 I have a machine and a phone.&lt;/P&gt;
&lt;P&gt;If I configure 802.1x here at my campus (a network which is directly connected to RADIUS I can authenticate no problems. So it is not a server issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The phone is only authenticating since i have the "trust device cisco-phone" command enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface info:&lt;/P&gt;
&lt;P&gt;description USER_DOT1X&lt;BR /&gt; switchport access vlan 120&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 3120&lt;BR /&gt; trust device cisco-phone&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication event fail retry 3 action authorize vlan 65&lt;BR /&gt; authentication event server dead action authorize vlan 120&lt;BR /&gt; authentication event no-response action authorize vlan 67&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order mab dot1x&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication timer restart 65535&lt;BR /&gt; authentication violation restrict&lt;BR /&gt; mab&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can ping my server (147.36.34.164), and I quadruple checked that the shared-secrets were identical.&lt;/P&gt;
&lt;P&gt;Once 802.1x is enabled, the debugging capture authenticates the phone due to it being a "trusted device" but still says "Check network" the machine does not authenticate. Here is my output: **I have omitted irrelevant lines**&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See attached for the full notepad log and other commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:54:48 GMT</pubDate>
    <dc:creator>stevenbailor</dc:creator>
    <dc:date>2020-02-21T18:54:48Z</dc:date>
    <item>
      <title>Please Help Diagnose RADIUS Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/please-help-diagnose-radius-timeout/m-p/3375450#M549069</link>
      <description>&lt;P&gt;I am attempting to deploy 802.1x to my VPN sites, my NPS has the ports allowed on both inbound and outbound rules.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I am using 1812 for Authentication and 1813 for accounting (although 1645, 1646 are also allows on the NPS ports)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;On a Cisco 3850-48P&amp;nbsp;(139.139.210.18) on interface G1/0/21 I have a machine and a phone.&lt;/P&gt;
&lt;P&gt;If I configure 802.1x here at my campus (a network which is directly connected to RADIUS I can authenticate no problems. So it is not a server issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The phone is only authenticating since i have the "trust device cisco-phone" command enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface info:&lt;/P&gt;
&lt;P&gt;description USER_DOT1X&lt;BR /&gt; switchport access vlan 120&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 3120&lt;BR /&gt; trust device cisco-phone&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication event fail retry 3 action authorize vlan 65&lt;BR /&gt; authentication event server dead action authorize vlan 120&lt;BR /&gt; authentication event no-response action authorize vlan 67&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order mab dot1x&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication timer restart 65535&lt;BR /&gt; authentication violation restrict&lt;BR /&gt; mab&lt;BR /&gt; no snmp trap link-status&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; spanning-tree portfast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can ping my server (147.36.34.164), and I quadruple checked that the shared-secrets were identical.&lt;/P&gt;
&lt;P&gt;Once 802.1x is enabled, the debugging capture authenticates the phone due to it being a "trusted device" but still says "Check network" the machine does not authenticate. Here is my output: **I have omitted irrelevant lines**&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See attached for the full notepad log and other commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/please-help-diagnose-radius-timeout/m-p/3375450#M549069</guid>
      <dc:creator>stevenbailor</dc:creator>
      <dc:date>2020-02-21T18:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Please Help Diagnose RADIUS Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/please-help-diagnose-radius-timeout/m-p/3375852#M549070</link>
      <description>&lt;P&gt;Your switch logs say access-reject received from RADIUS server; what do the logs in your RADIUS server say?&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 07:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/please-help-diagnose-radius-timeout/m-p/3375852#M549070</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-05-01T07:52:20Z</dc:date>
    </item>
  </channel>
</rss>

