<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635638#M575633</link>
    <description>&lt;PRE&gt;sessmgrd: Authorization failed or unapplied for client &lt;/PRE&gt;
&lt;P&gt;how is your switch port config on the switch, what version of IOS XE running cat 9200 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check this thread may help you :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/switching/802-1x-configure-wired-802-1x-with-nps/td-p/3720361" target="_blank"&gt;https://community.cisco.com/t5/switching/802-1x-configure-wired-802-1x-with-nps/td-p/3720361&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2022 09:45:47 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-06-21T09:45:47Z</dc:date>
    <item>
      <title>NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635627#M575631</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;I read many tutorials how to configure NPS + IOS for dynamic VLAN assignment, but all of these tutorials are how to authorize and assign VLAN based on user Group in AD.&lt;/P&gt;&lt;P&gt;But I would like to assign VLAN based on PC in AD PC Group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.Is tis possible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If yes, this is my log&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;*Jun 21 08:32:20.861: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/40, changed state to down&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;*Jun 21 08:32:28.834: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (b445.064d.6b4a) with reason (Cred Fail) on Interface Gi1/0/40 AuditSessionID 83AD2C0A000000148564408D Username: host/PC-049.testdoamin.com&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;*Jun 21 08:32:28.834: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (b445.064d.6b4a) on Interface GigabitEthernet1/0/40 AuditSessionID 83AD2C0A000000148564408D. Failure reason: Authc fail. Authc failure reason: Cred Fail.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;*Jun 21 08:32:30.765: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/40, changed state to up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;*Jun 21 08:32:31.765: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/40, changed state to up&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in NPS I have policy defined&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 907px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154208i47CA780EF56BA93A/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2_LI.jpg" style="width: 915px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154209i079323B5BFC22B90/image-size/large?v=v2&amp;amp;px=999" role="button" title="2_LI.jpg" alt="2_LI.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 907px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154210i7B1C902AB8E401A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 907px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/154211i9D121EC0508B3D35/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PC network card there is dot1x enabled and PEAP selected&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635627#M575631</guid>
      <dc:creator>IPhoneRZ</dc:creator>
      <dc:date>2022-06-21T09:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635632#M575632</link>
      <description>&lt;P&gt;sorry,&lt;/P&gt;&lt;P&gt;I forgot to put Cisco config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;radius server NPS&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;address ipv4 10.184.35.11 auth-port 1812 acct-port 1813&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;key .........&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa group server radius RADIUS_TEST&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;server name NPS&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;no aaa authentication login default local&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa authentication dot1x default group RADIUS_TEST&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa authorization network default group RADIUS_TEST if-authenticated&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;dot1x system-auth-control&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x guest-vlan supplicant&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;int gig1/0/40&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x guest-vlan 99&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635632#M575632</guid>
      <dc:creator>IPhoneRZ</dc:creator>
      <dc:date>2022-06-21T09:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635638#M575633</link>
      <description>&lt;PRE&gt;sessmgrd: Authorization failed or unapplied for client &lt;/PRE&gt;
&lt;P&gt;how is your switch port config on the switch, what version of IOS XE running cat 9200 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check this thread may help you :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/switching/802-1x-configure-wired-802-1x-with-nps/td-p/3720361" target="_blank"&gt;https://community.cisco.com/t5/switching/802-1x-configure-wired-802-1x-with-nps/td-p/3720361&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 09:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635638#M575633</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-21T09:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635646#M575634</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port configuration is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;int gig1/0/40&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x guest-vlan 99&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW version is 17.03.04&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635646#M575634</guid>
      <dc:creator>IPhoneRZ</dc:creator>
      <dc:date>2022-06-21T10:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635662#M575635</link>
      <description>&lt;P&gt;I take this as Wired client testing rigt (not Wireless)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope you trying 802.1x with Cert authentication not MAB right ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;suggested config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;spanning-tree portfast&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;switchport access vlan XX&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan XX&lt;BR /&gt;access-session closed&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635662#M575635</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-21T10:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - NPS + 9200 switches and Dynamic VLAN assigment</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635723#M575636</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;, thanks for the link in the first post:) i didn't have Cert enrolled on NPS Server (it's separated server from AD)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created few more AD groups and VLANs. I added my PC to different groups and i received correct VLAN dynamically - it's working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing left I think , when I removed my PC from any AD group created for VLAN Assigment, i recived authen / authori failed as in the first post - but I would like that guest VLAN will be assign when PC is not in dedicated group, possible ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW&lt;/P&gt;&lt;P&gt;I tried understand Your switch port config, and could You please describe why these command if dynamic vlan assigment ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;switchport access vlan XX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport voice vlan XX&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and lite describe purpose of these command &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;access-session closed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication periodic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer reauthenticate server&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:54:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-nps-9200-switches-and-dynamic-vlan-assigment/m-p/4635723#M575636</guid>
      <dc:creator>IPhoneRZ</dc:creator>
      <dc:date>2022-06-21T10:54:01Z</dc:date>
    </item>
  </channel>
</rss>

