<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X - multi server radius ?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488701#M570510</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1263942"&gt;@m.humbert&lt;/a&gt;&amp;nbsp;- Yes. Like&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;said, you can list those in a group and used the group name in your aaa statements. The first in the list is the active one; if down,&amp;nbsp; the switch try the next and so on.&lt;/P&gt;&lt;P&gt;On some platforms, it could&amp;nbsp; look like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;aaa group server radius "ISE_Group_Name"&lt;BR /&gt;server-private "IP_ISE1" auth-port 1812 acct-port 1813 key "Radius_Key"&lt;BR /&gt;server-private "IP_ISE2" auth-port 1812 acct-port 1813 key "Radius_Key"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group "ISE_Group_Name"&lt;BR /&gt;aaa authorization network default group "ISE_Group_Name"&lt;BR /&gt;aaa accounting dot1x default start-stop group "ISE_Group_Name"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 17:15:12 GMT</pubDate>
    <dc:creator>Pat Pouna</dc:creator>
    <dc:date>2021-10-19T17:15:12Z</dc:date>
    <item>
      <title>802.1X - multi server radius ??</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488535#M570504</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;i'm working on project to deploy 802.1X security on all my L2 switches on our HQ. this part is the first step but we plan to deploy this security on all L2 switches of remote site (Branch office, shop, warehouse..)&lt;/P&gt;&lt;P&gt;- we are using NPS from Win2016 Std&lt;/P&gt;&lt;P&gt;i would like to know if it possible to setup two Radius server for dot1x authentication on switches? (redondancy purpose) like you can setup two dhcp server.&lt;/P&gt;&lt;P&gt;So if the first radius down, the switch try to reach the second one....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488535#M570504</guid>
      <dc:creator>m.humbert</dc:creator>
      <dc:date>2021-10-19T13:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X - multi server radius ??</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488542#M570505</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1263942"&gt;@m.humbert&lt;/a&gt;&amp;nbsp;yes you can, setup 2 radius servers and add them to a aaa group, reference the group in the aaa authentication command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;radius server ISE-1 &lt;BR /&gt;address ipv4 192.168.10.10 auth-port 1812 acct-port 1813 &lt;BR /&gt;automate-tester username switch-probe ignore-acct-port probe-on &lt;BR /&gt;key XXXXXXXX &lt;BR /&gt;! &lt;BR /&gt;radius server ISE-2 &lt;BR /&gt;address ipv4 192.168.10.11 auth-port 1812 acct-port 1813 &lt;BR /&gt;automate-tester username switch-probe ignore-acct-port probe-on &lt;BR /&gt;key XXXXXXXX &lt;BR /&gt;! &lt;BR /&gt;aaa group server radius ISE-RADIUS &lt;BR /&gt;server name ISE-1 &lt;BR /&gt;server name ISE-2&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group ISE-RADIUS&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 13:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488542#M570505</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-10-19T13:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X - multi server radius ??</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488701#M570510</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1263942"&gt;@m.humbert&lt;/a&gt;&amp;nbsp;- Yes. Like&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;said, you can list those in a group and used the group name in your aaa statements. The first in the list is the active one; if down,&amp;nbsp; the switch try the next and so on.&lt;/P&gt;&lt;P&gt;On some platforms, it could&amp;nbsp; look like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;aaa group server radius "ISE_Group_Name"&lt;BR /&gt;server-private "IP_ISE1" auth-port 1812 acct-port 1813 key "Radius_Key"&lt;BR /&gt;server-private "IP_ISE2" auth-port 1812 acct-port 1813 key "Radius_Key"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group "ISE_Group_Name"&lt;BR /&gt;aaa authorization network default group "ISE_Group_Name"&lt;BR /&gt;aaa accounting dot1x default start-stop group "ISE_Group_Name"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 17:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4488701#M570510</guid>
      <dc:creator>Pat Pouna</dc:creator>
      <dc:date>2021-10-19T17:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X - multi server radius ??</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4489048#M570522</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;many thanks for your help !&lt;/P&gt;&lt;P&gt;i had some trouble with other option but i finished to make it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;have nice day !&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 08:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-multi-server-radius/m-p/4489048#M570522</guid>
      <dc:creator>m.humbert</dc:creator>
      <dc:date>2021-10-20T08:51:24Z</dc:date>
    </item>
  </channel>
</rss>

