<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 2960X not sending Radius machine authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4809687#M580998</link>
    <description>&lt;P&gt;The authentication order and priority in the switchport configuration is "mab dot1x". With this configuration, dot1x will only happen if MAB fails.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NancySaini_0-1680804702466.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181105iED03B4DCF0BCEA82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NancySaini_0-1680804702466.png" alt="NancySaini_0-1680804702466.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Change the authentication priority to "dot1x mab" and you should see switch initiating EAPoL.&lt;/P&gt;
&lt;P&gt;Reference : &lt;A href="https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2023 18:13:07 GMT</pubDate>
    <dc:creator>Nancy Saini</dc:creator>
    <dc:date>2023-04-06T18:13:07Z</dc:date>
    <item>
      <title>Cisco 2960X not sending Radius machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4809210#M580967</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have machine that is joined in AD and supposed to be doing machine auth, we notice for 2960x not sending radius machine authentication, instead it only does mac address. IPPhone/Printer authentication are working fine no issue at all.&lt;/P&gt;&lt;P&gt;We are using Anyconnect network module, and the same XML file we use all throughout deployment, with other switch model we do not encounter the issue.&lt;/P&gt;&lt;P&gt;Does anyone encounter the same issue? Please share your idea&lt;/P&gt;&lt;P&gt;Apr 5 12:59:22.118: RADIUS(00000000): Send Access-Request to 10.62.32.19:1812 onvrf(0) id 1645/123, len 274&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: authenticator 96 97 20 A7 63 28 A9 71 - EA FE 25 86 29 D7 CB 5C&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: User-Name [1] 14&lt;STRONG&gt; "10E7C67821E8"&lt;/STRONG&gt;&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: User-Password [2] 18 *&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: Service-Type [6] 6 Call Check [10]&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: Vendor, Cisco [26] 31&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: Cisco AVpair [1] 25 "service-type=Call Check"&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: Framed-MTU [12] 6 1500&lt;BR /&gt;Apr 5 12:59:22.118: RADIUS: Called-Station-Id [30] 19 "6C-41-0E-BD-98-8A"&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Calling-Station-Id [31] 19 "10-E7-C6-78-21-E8"&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Message-Authenticato[80] 18&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: 17 88 CA ED AF 58 4F 00 4A A3 F8 A8 93 EE 33 DA [ XOJ3]&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: EAP-Key-Name [102] 2 *&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Vendor, Cisco [26] 49&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Cisco AVpair [1] 43 "audit-session-id=0A7106FE00000BA2643F8AEF"&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Vendor, Cisco [26] 18&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Cisco AVpair [1] 12 &lt;STRONG&gt;"method=mab"&lt;/STRONG&gt;&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: NAS-IP-Address [4] 6 10.113.6.254&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: Nas-Identifier [32] 13 "SEL-SWC-06S"&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: NAS-Port-Id [87] 23 "GigabitEthernet1/0/10"&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: NAS-Port-Type [61] 6 Ethernet [15]&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS: NAS-Port [5] 6 50110&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS(00000000): Sending a IPv4 Radius Packet&lt;BR /&gt;Apr 5 12:59:22.122: RADIUS(00000000): Started 5 sec timeout&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: &lt;STRONG&gt;Received from id 1645/123 10.62.32.19:1812, Access-Reject, len 92&lt;/STRONG&gt;&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: authenticator C2 25 DA DB 9F 79 15 6F - E4 24 A3 CB AA EE 6C 9F&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: Message-Authenticato[80] 18&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: 11 80 C2 6C 8E C6 58 99 CD 95 FE 99 4A D3 C1 42 [ lXJB]&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: Vendor, Cisco [26] 54&lt;BR /&gt;Apr 5 12:59:22.387: RADIUS: Cisco AVpair [1] 48 "AuthenticationIdentityStore=Internal Endpoints"&lt;BR /&gt;Apr 5 12:59:22.391: RADIUS(00000000): Received from id 1645/123&lt;/P&gt;&lt;P&gt;Switch port configuration:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/10&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 2&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize vlan 11&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority mab dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast edge&lt;/P&gt;&lt;P&gt;Radius/AAA configuration:&lt;/P&gt;&lt;P&gt;aaa group server radius SP-ISE-GROUP&lt;BR /&gt;server name VMISE02&lt;BR /&gt;server name VMISE01&lt;BR /&gt;aaa authentication login CONSOLE local&lt;BR /&gt;aaa authentication login THALOGIN group ISE-TACACS local&lt;BR /&gt;aaa authentication dot1x default group SP-ISE-GROUP&lt;BR /&gt;aaa authorization exec default group ISE-TACACS local if-authenticated&lt;BR /&gt;aaa authorization network default group SP-ISE-GROUP&lt;BR /&gt;aaa authorization auth-proxy default group SP-ISE-GROUP&lt;BR /&gt;aaa accounting send stop-record authentication failure&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting dot1x default start-stop group SP-ISE-GROUP&lt;BR /&gt;aaa accounting exec default start-stop group ISE-TACACS&lt;BR /&gt;aaa accounting network default start-stop group SP-ISE-GROUP&lt;BR /&gt;aaa accounting system default start-stop group SP-ISE-GROUP&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 10.62.x.xserver-key 7 (omitted)&lt;BR /&gt;client 10.62.x.x server-key 7 (omitted)&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan11&lt;BR /&gt;radius server VMISE01&lt;BR /&gt;address ipv4 10.62.x.x auth-port 1812 acct-port 1813&lt;BR /&gt;automate-tester username dummy idle-time 5&lt;BR /&gt;key 7 (omitted)&lt;BR /&gt;radius server VMISE02&lt;BR /&gt;address ipv4 10.62.x.x auth-port 1812 acct-port 1813&lt;BR /&gt;automate-tester username dummy idle-time 5&lt;BR /&gt;key 7(omitted)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 04:06:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4809210#M580967</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-04-06T04:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2960X not sending Radius machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4809687#M580998</link>
      <description>&lt;P&gt;The authentication order and priority in the switchport configuration is "mab dot1x". With this configuration, dot1x will only happen if MAB fails.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NancySaini_0-1680804702466.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181105iED03B4DCF0BCEA82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NancySaini_0-1680804702466.png" alt="NancySaini_0-1680804702466.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Change the authentication priority to "dot1x mab" and you should see switch initiating EAPoL.&lt;/P&gt;
&lt;P&gt;Reference : &lt;A href="https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/flexible_authentication.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 18:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4809687#M580998</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-06T18:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2960X not sending Radius machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4810187#M581018</link>
      <description>&lt;P&gt;I agree with Nancy. Also, i dont see below command for data vlan on this port.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: red;"&gt;switchport access vlan xx&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 15:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4810187#M581018</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2023-04-07T15:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 2960X not sending Radius machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4810614#M581023</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/358459"&gt;@Nancy Saini&lt;/a&gt;&amp;nbsp; had a great suggestion and you may compare your configuration with our &lt;LI-MESSAGE title="ISE Secure Wired Access Prescriptive Deployment Guide" uid="3641515" url="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/m-p/3641515#U3641515" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt; which has example configurations following best practices.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, we always recommend &lt;FONT face="courier new,courier"&gt;authentication host-mode multi-auth&lt;/FONT&gt; over &lt;FONT face="courier new,courier"&gt;multi-domain&lt;/FONT&gt;. if you have problems with phones+workstations on the same port, switch to &lt;FONT face="courier new,courier"&gt;multi-auth&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2023 21:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-2960x-not-sending-radius-machine-authentication/m-p/4810614#M581023</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-04-08T21:53:47Z</dc:date>
    </item>
  </channel>
</rss>

