<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA_DOT1X radius DEAD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-dot1x-radius-dead/m-p/4400030#M567208</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Affected users are the one already authorized or new people connecting?&lt;/P&gt;
&lt;P&gt;The class-map &lt;STRONG&gt;AAA-DOWN-AUTH&lt;/STRONG&gt;&amp;nbsp;is in match-any instead of match-all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, have you ran a debug radius to see why your AAA servers are flapping between alive and not alive?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 May 2021 02:52:57 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2021-05-10T02:52:57Z</dc:date>
    <item>
      <title>AAA_DOT1X radius DEAD</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-dot1x-radius-dead/m-p/4398520#M567159</link>
      <description>&lt;P&gt;hI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems the Radius DEAD and ALIVE logs were occuring every few minutes. User complains it affect their access. However I thought when AAA down, all hosts will be AZ (authorised)? It seems AAA servers intermittent reachability frm the switch affects host access. How is this possible espeecially when script says AAA-down, all Authorised?&lt;/P&gt;&lt;P&gt;Also both AAA servers are fine, however switch logs says otherwise. It cant be 2 AAA down at same time. there wasnt any ping timeout but switch keeps logging AAA unreachable every few mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are my script. Any idea guys?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May 6 13:24:11.350: %RADIUS-4-RADIUS_DEAD: RADIUS server 172.1.1.1:1812,1813 is not responding.&lt;BR /&gt;May 6 13:24:26.920: %RADIUS-4-RADIUS_DEAD: RADIUS server 172.1.1.2:1812,1813 is not responding.&lt;BR /&gt;May 6 13:24:26.920: %RADIUS-3-ALLDEADSERVER: Group AAA_DOT1X: No active radius servers found. Id 110.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class-map type control subscriber match-any AAA-DOWN-AUTH&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;match result-type aaa-timeout&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;match authorization-status authorized&lt;BR /&gt;!&lt;BR /&gt;class-map type control subscriber match-all AAA-DOWN-UNAUTHD&lt;BR /&gt;match result-type aaa-timeout&lt;BR /&gt;match authorization-status unauthorized&lt;BR /&gt;!&lt;BR /&gt;class-map type control subscriber match-all DOT1X_FAILED&lt;BR /&gt;match method dot1x&lt;BR /&gt;match result-type method dot1x authoritative&lt;BR /&gt;!&lt;BR /&gt;class-map type control subscriber match-all DOT1X_NO_RESP&lt;BR /&gt;match method dot1x&lt;BR /&gt;match result-type method dot1x agent-not-found&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;20 class AAA-DOWN-UNAUTHD do-until-failure&lt;BR /&gt;10 activate service-template CRITICAL_AUTH_VLAN&lt;BR /&gt;20 activate service-template DEFAULT_CRITICAL_VOICE_TEMPLATE&lt;BR /&gt;30 authorize&lt;BR /&gt;40 pause reauthentication&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;30 class AAA-DOWN-AUTH do-until-failure&lt;BR /&gt;10 pause reauthentication&lt;BR /&gt;20 authorize&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 03:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-dot1x-radius-dead/m-p/4398520#M567159</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2021-05-06T03:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: AAA_DOT1X radius DEAD</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-dot1x-radius-dead/m-p/4400030#M567208</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Affected users are the one already authorized or new people connecting?&lt;/P&gt;
&lt;P&gt;The class-map &lt;STRONG&gt;AAA-DOWN-AUTH&lt;/STRONG&gt;&amp;nbsp;is in match-any instead of match-all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, have you ran a debug radius to see why your AAA servers are flapping between alive and not alive?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 02:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-dot1x-radius-dead/m-p/4400030#M567208</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2021-05-10T02:52:57Z</dc:date>
    </item>
  </channel>
</rss>

