<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic in order to perform dot1x we in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624514#M55943</link>
    <description>&lt;P&gt;In order to perform dot1x auth endpoint needs suppliant and windows and MAC have a default supplicant that comes with OS. AP are supposed for MAB&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2015 10:16:36 GMT</pubDate>
    <dc:creator>Venkatesh Attuluri</dc:creator>
    <dc:date>2015-05-28T10:16:36Z</dc:date>
    <item>
      <title>Dot1x authentication for cisco AP</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624513#M55942</link>
      <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are experimenting with a dot1x port authentication setup.&lt;/P&gt;&lt;P&gt;The setup is as fallows:&lt;/P&gt;&lt;P&gt;Microsoft 20008r2 NPS&lt;/P&gt;&lt;P&gt;Cisco 3560 compact switch&lt;/P&gt;&lt;P&gt;Cisco 3702i AP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be using dynamic vlan assignment. So far it Works fine with pc and mac. However when connecting my Cisco 3702 ap i get an error on the NPS saying:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="DA"&gt;Reason Code: 22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="DA"&gt;Reason: The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp;the Wireless controller i have overriden the global configuration, and added the supplicant username and password to match with a user i have created in AD. I&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the NPS i have set the EAP type to: MIcrosoft: Secured Password (EAP-MSCHAPv2). According to the datasheet on the AP that should be supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my switch configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;BR /&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa group server radius NPSSERVERS&lt;BR /&gt;&amp;nbsp;server-private 10.180.15.231 auth-port 1812 acct-port 1813 key 7 ************&lt;BR /&gt;aaa authentication dot1x default group NPSSERVERS&lt;BR /&gt;aaa authorization network default group NPSSERVERS&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interfaces:&lt;/P&gt;&lt;P&gt;switchport mode access&lt;BR /&gt;&amp;nbsp;authentication event fail action authorize vlan 85&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 85&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 85&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;&amp;nbsp;spanning-tree guard root&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not entirely sure if i need to make more settings on the AP, or more on the switch. Any suggestions will be greatly appriciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Andreas&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:39:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624513#M55942</guid>
      <dc:creator>Andreas Larsen</dc:creator>
      <dc:date>2019-03-11T05:39:22Z</dc:date>
    </item>
    <item>
      <title>in order to perform dot1x we</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624514#M55943</link>
      <description>&lt;P&gt;In order to perform dot1x auth endpoint needs suppliant and windows and MAC have a default supplicant that comes with OS. AP are supposed for MAB&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2015 10:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624514#M55943</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2015-05-28T10:16:36Z</dc:date>
    </item>
    <item>
      <title>So when the data sheet for</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624515#M55944</link>
      <description>&lt;DIV class="pCellBulletCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 3pt 3pt 3pt 0.1in; text-indent: -0.105in; line-height: normal;"&gt;So when the data sheet for the AP reads fallowing, it refers to its abilities&amp;nbsp;as an authenticator, and not a supplicant, correct? I guess dot1x might no be such a great solution for wired network afterall.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="pCellBulletCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 3pt 3pt 3pt 0.1in; text-indent: -0.105in; line-height: normal;"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="pCellBulletCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 3pt 3pt 3pt 0.1in; text-indent: -0.105in; line-height: normal;"&gt;&lt;SPAN lang="X-NONE"&gt;●&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Extensible Authentication Protocol (EAP) types:&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;EAP-Transport Layer Security (TLS)&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;EAP-Tunneled TLS (TTLS) or Microsoft Challenge Handshake Authentication Protocol Version 2 (MSCHAPv2)&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Protected EAP (PEAP) v0 or EAP-MSCHAPv2&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;EAP-Flexible Authentication via Secure Tunneling (FAST)&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;PEAP v1 or EAP-Generic Token Card (GTC)&lt;/DIV&gt;&lt;DIV class="pCellBulletIndentCMT" style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; font-size: 12px; margin: 2pt 2.9pt 2pt 0.3in; text-indent: -0.14in; line-height: normal;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Times New Roman', serif;"&gt;◦&lt;SPAN style="font-stretch: normal; font-size: 7pt; font-family: 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;EAP-Subscriber Identity Module (SIM)&lt;/DIV&gt;</description>
      <pubDate>Thu, 28 May 2015 13:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624515#M55944</guid>
      <dc:creator>Andreas Larsen</dc:creator>
      <dc:date>2015-05-28T13:10:26Z</dc:date>
    </item>
    <item>
      <title>The problem is probably due</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624516#M55945</link>
      <description>&lt;P&gt;The problem is probably due to certificate errors, either the AP doesn't trust the cert you use on your NPS, or the NPS does not trust the cert issuer that the AP uses. In Cisco ISE, which is what most new solution would use, these manufacturer ca certs are already imported for Cisco AP's and IP Phones.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2015 14:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-for-cisco-ap/m-p/2624516#M55945</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-05-28T14:30:50Z</dc:date>
    </item>
  </channel>
</rss>

