<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius configuration(dot1x) problem with ios version 15 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666851#M55848</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I upgrade one 3750x from version 12.2 55 to&amp;nbsp;15.0(2)SE7 and i see that some configuration must be changed&lt;/P&gt;&lt;P&gt;&amp;nbsp;Warning: The CLI will be deprecated soon&lt;BR /&gt;&amp;nbsp;'radius-server host xxxxxxxx auth-port 1645 acct-port 1646 test username &lt;EM&gt;name&lt;/EM&gt;&amp;nbsp;key 7 &lt;EM&gt;sharedsecret&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp;Please move to 'radius server &amp;lt;name&amp;gt;' CLI.&lt;/P&gt;&lt;P&gt;I try to adapt the configuration but the 802.1x fails :&lt;/P&gt;&lt;P&gt;radius server RADIUS-SRV&lt;BR /&gt;&amp;nbsp;address ipv4 xxxxxxxxxx auth-port 1645 acct-port 1646&lt;BR /&gt;&amp;nbsp;timeout 15&lt;BR /&gt;&amp;nbsp;retransmit 3&lt;BR /&gt;&amp;nbsp;automate-tester username name (username created in global configuration mode)&lt;BR /&gt;&amp;nbsp;key 7&amp;nbsp;&lt;SPAN style="font-size: 16.3636360168457px;"&gt;sharedsecret&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius RADIUS-SRV&lt;BR /&gt;&amp;nbsp;server-private xxxxxxxxxx key 7 &lt;SPAN style="font-size: 16.3636360168457px;"&gt;sharedsecret&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;ip radius source-interface VlanX&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group RADIUS-SRV&lt;BR /&gt;aaa authorization network default group RADIUS-SRV&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the configuration for the interface with an IP phone connected :&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication event fail action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&amp;nbsp;&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication violation protect&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt;On the logs, i have the server-dead result (not the message that the switch can't reach the radius server):&lt;/P&gt;&lt;P&gt;Apr 28 12:33:45.075: %AUTHMGR-5-START: Starting 'dot1x' for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;BR /&gt;Apr 28 12:34:05.191: %DOT1X-5-FAIL: Authentication failed for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;BR /&gt;Apr 28 12:34:05.191: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;/P&gt;&lt;P&gt;When i put the old fashion config, the IP phone is authenticated without problems, see capture from the ACS server (attached file&amp;nbsp;802.1x-OK)&lt;/P&gt;&lt;P&gt;With the new configuration, see attached file&amp;nbsp;802.1x-NOK ; i don't have the same field in the ACS (username field) and i have the message&amp;nbsp;&lt;A href="https://10.30.46.25/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Fl0357308%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=11036+The+Message-Authenticator+RADIUS+attribute+is+invalid.&amp;amp;__locale=en_US&amp;amp;iportalID=TVLPSVSQZ&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: rgb(255, 0, 0); font-family: sans-serif; font-size: small; line-height: normal; white-space: nowrap; margin-top: 0pt; background-color: rgb(245, 249, 253);" target="_self" title="Click for failure reason details"&gt;11036 The Message-Authenticator RADIUS attribute is invalid&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Why the authentication doesn't "come" to the ACS like before with this new configuration? What i'm missing?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:41:35 GMT</pubDate>
    <dc:creator>Aret Avedis SET</dc:creator>
    <dc:date>2019-03-11T05:41:35Z</dc:date>
    <item>
      <title>Radius configuration(dot1x) problem with ios version 15</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666851#M55848</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I upgrade one 3750x from version 12.2 55 to&amp;nbsp;15.0(2)SE7 and i see that some configuration must be changed&lt;/P&gt;&lt;P&gt;&amp;nbsp;Warning: The CLI will be deprecated soon&lt;BR /&gt;&amp;nbsp;'radius-server host xxxxxxxx auth-port 1645 acct-port 1646 test username &lt;EM&gt;name&lt;/EM&gt;&amp;nbsp;key 7 &lt;EM&gt;sharedsecret&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp;Please move to 'radius server &amp;lt;name&amp;gt;' CLI.&lt;/P&gt;&lt;P&gt;I try to adapt the configuration but the 802.1x fails :&lt;/P&gt;&lt;P&gt;radius server RADIUS-SRV&lt;BR /&gt;&amp;nbsp;address ipv4 xxxxxxxxxx auth-port 1645 acct-port 1646&lt;BR /&gt;&amp;nbsp;timeout 15&lt;BR /&gt;&amp;nbsp;retransmit 3&lt;BR /&gt;&amp;nbsp;automate-tester username name (username created in global configuration mode)&lt;BR /&gt;&amp;nbsp;key 7&amp;nbsp;&lt;SPAN style="font-size: 16.3636360168457px;"&gt;sharedsecret&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius RADIUS-SRV&lt;BR /&gt;&amp;nbsp;server-private xxxxxxxxxx key 7 &lt;SPAN style="font-size: 16.3636360168457px;"&gt;sharedsecret&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;ip radius source-interface VlanX&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group RADIUS-SRV&lt;BR /&gt;aaa authorization network default group RADIUS-SRV&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the configuration for the interface with an IP phone connected :&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication event fail action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&amp;nbsp;&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication violation protect&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;/P&gt;&lt;P&gt;On the logs, i have the server-dead result (not the message that the switch can't reach the radius server):&lt;/P&gt;&lt;P&gt;Apr 28 12:33:45.075: %AUTHMGR-5-START: Starting 'dot1x' for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;BR /&gt;Apr 28 12:34:05.191: %DOT1X-5-FAIL: Authentication failed for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;BR /&gt;Apr 28 12:34:05.191: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'dot1x' for client (MAC) on Interface Gi1/0/1 AuditSessionID 0A175140000004640014346D&lt;/P&gt;&lt;P&gt;When i put the old fashion config, the IP phone is authenticated without problems, see capture from the ACS server (attached file&amp;nbsp;802.1x-OK)&lt;/P&gt;&lt;P&gt;With the new configuration, see attached file&amp;nbsp;802.1x-NOK ; i don't have the same field in the ACS (username field) and i have the message&amp;nbsp;&lt;A href="https://10.30.46.25/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Fl0357308%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=11036+The+Message-Authenticator+RADIUS+attribute+is+invalid.&amp;amp;__locale=en_US&amp;amp;iportalID=TVLPSVSQZ&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: rgb(255, 0, 0); font-family: sans-serif; font-size: small; line-height: normal; white-space: nowrap; margin-top: 0pt; background-color: rgb(245, 249, 253);" target="_self" title="Click for failure reason details"&gt;11036 The Message-Authenticator RADIUS attribute is invalid&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Why the authentication doesn't "come" to the ACS like before with this new configuration? What i'm missing?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666851#M55848</guid>
      <dc:creator>Aret Avedis SET</dc:creator>
      <dc:date>2019-03-11T05:41:35Z</dc:date>
    </item>
    <item>
      <title>Hi avedis, Can you please</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666852#M55850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;avedis,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please check the connectivity between switch vlan to ACS server and Shared secret key. Please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Bikash&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 12:11:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666852#M55850</guid>
      <dc:creator>Bikash Shaw</dc:creator>
      <dc:date>2015-04-29T12:11:45Z</dc:date>
    </item>
    <item>
      <title>Hello,Thank you for your</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666853#M55853</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your reply. The password is correct in both sides&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also when i put the old fashion config, the dot1x is working correctly = password is correct&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2015 12:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666853#M55853</guid>
      <dc:creator>Aret Avedis SET</dc:creator>
      <dc:date>2015-04-29T12:42:57Z</dc:date>
    </item>
    <item>
      <title>Hello all,I modify the</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666854#M55858</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I modify the configuration and now it's working :&lt;/P&gt;&lt;P&gt;aaa group server radius RADIUS-SRV&lt;BR /&gt;&amp;nbsp;server-private xxxxxxxxxxxx timeout 15 retransmit 3 test username xxxxxxxxx key 7 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;&amp;nbsp;ip radius source-interface xxxxx&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;radius server RADIUS-SRV&lt;BR /&gt;&amp;nbsp;address ipv4 xxxxxx auth-port 1645 acct-port 1646&lt;BR /&gt;&amp;nbsp;key 7 xxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group RADIUS-SRV&lt;BR /&gt;aaa authorization network default group RADIUS-SRV&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 10:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666854#M55858</guid>
      <dc:creator>Aret Avedis SET</dc:creator>
      <dc:date>2015-05-05T10:44:48Z</dc:date>
    </item>
    <item>
      <title>Hi,I see you are</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666855#M55861</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I see you are using&lt;/P&gt;&lt;DIV&gt;&lt;SPAN style="font-family:monospace"&gt;&lt;SPAN style="color:#000000;background-color:#ffffff;"&gt;automate-tester&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;command.&lt;/P&gt;&lt;P&gt;I did some test sand registered this behaviour.&lt;/P&gt;&lt;P&gt;If a radius server has been marked alive the switch wait for the configured deadtime interval and then for the&lt;/P&gt;&lt;DIV&gt;&lt;SPAN style="font-family:monospace"&gt;&lt;SPAN style="color:#000000;background-color:#ffffff;"&gt;idle-time&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;to expire before sending the probe.&lt;/DIV&gt;&lt;DIV&gt;So if confgured dead time is 10 minutes and idle-time is 2 minutes&amp;nbsp; the dead server is marked alive after 12 minutes even if it has been re-activated in 5 minutes.&lt;/DIV&gt;&lt;DIV&gt;Is this the expected behaviour?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Regards&lt;/DIV&gt;&lt;DIV&gt;MM&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Jun 2015 14:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666855#M55861</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2015-06-10T14:52:54Z</dc:date>
    </item>
    <item>
      <title>Hello,The time out is in</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666856#M55864</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The time out is in seconds not in minutes. When i put "&lt;SPAN style="font-size: 14.5454540252686px;"&gt;timeout 15 retransmit 3" it says that if the radius service is unavailable it will timeout after 15seconds * 3 times= 45sec&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;sh aaa dead-criteria radius xxxxxxxxxxxxxxxxx&lt;BR /&gt;RADIUS: No server group specified. Using radius&lt;BR /&gt;RADIUS Server Dead Critieria:&lt;BR /&gt;=============================&lt;BR /&gt;Server Details:&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Address &amp;nbsp; : xxxxxxxxxxxxxxxx&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Auth Port : 1645&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Acct Port : 1646&lt;BR /&gt;Server Group &amp;nbsp;: radius&lt;BR /&gt;Dead Criteria Details:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Configured Retransmits &amp;nbsp; : 3&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Configured Timeout &amp;nbsp; &amp;nbsp; &amp;nbsp; : 5&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Estimated Outstanding Transactions: 0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Dead Detect Time &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 15s&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Computed Retransmit Tries: 3&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2015 18:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-configuration-dot1x-problem-with-ios-version-15/m-p/2666856#M55864</guid>
      <dc:creator>Aret Avedis SET</dc:creator>
      <dc:date>2015-06-10T18:35:47Z</dc:date>
    </item>
  </channel>
</rss>

