<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1X EAP-TLS Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865531#M582641</link>
    <description>&lt;P&gt;The picture was captured with Wireshark from my laptop that tries to authenticate, probably the NPS server not receiving the logs but i am trying to understand why i also checked if there is any block from the FW side and there is no any rule that block the communication.&lt;/P&gt;</description>
    <pubDate>Sat, 01 Jul 2023 09:50:28 GMT</pubDate>
    <dc:creator>michaelglosker</dc:creator>
    <dc:date>2023-07-01T09:50:28Z</dc:date>
    <item>
      <title>802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863165#M582521</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Over the past few weeks, I have been working on configuring 802.1x port-based authentication between my Cisco switch (RADIUS Client) and the NPS Server (My DC) using EAP-TLS authentication.&lt;/P&gt;&lt;P&gt;After completing the configuration on both sides following the tutorial provided in this link: &lt;A href="https://www.youtube.com/watch?v=CzmFhCuUj6w" target="_new"&gt;Tutorial Link&lt;/A&gt;, I noticed that the status of my Ethernet port changed to "Authentication failed." To investigate further, I captured the EAP packets using Wireshark and observed that my computer responded with the identity but received a failure response with "EAP Code Failure 4."&lt;/P&gt;&lt;P&gt;Now, I'm trying to determine which side might be causing the error - the switch or the NPS server. I have referred to several guides, and it seems that the configuration on the NPS server was done correctly, and the CA certificate was imported to the client.&lt;/P&gt;&lt;P&gt;For reference, here is the configuration from the NPS and endpoint side: &lt;A href="https://learn.microsoft.com/en-us/answers/questions/1318668/eap-tls-authentication-failed" target="_new"&gt;Configuration Link&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any insights or guidance on resolving this issue would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863165#M582521</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-06-27T12:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863175#M582522</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1072934"&gt;@michaelglosker&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you check that you have a policy taht matches the conditions for the AUTH. request form the Cisco Switch. Constraints....Conditions....that might prevent successful AUTH.&lt;/P&gt;&lt;P&gt;Also, take a closer look at the Wireshark capture of the EAP packets exchanged between the client abd the NPS server. Analyze the packet flow to identify ant abnormalities/errors in the EAP messages exchanged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863175#M582522</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2023-06-27T12:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863314#M582532</link>
      <description>&lt;P&gt;Code failure 4 would mean access rejected which would suggest there is no policy match on the NPS. Could you please share the NPS policies and the endpoints NIC settings for review?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 15:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863314#M582532</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-27T15:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863660#M582550</link>
      <description>&lt;P&gt;Here is my post including NIC Setting and the NPS policy.&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1318668/eap-tls-authentication-failed" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/1318668/eap-tls-authentication-failed&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 06:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863660#M582550</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-06-28T06:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863784#M582556</link>
      <description>&lt;P&gt;It could be the order of the policies, it could be the policy is not enabled, I think the best place to look at to trying to find out the root cause of this would be the NPS logs on the server, usually the are good enough to point out the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 10:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863784#M582556</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-28T10:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863913#M582580</link>
      <description>&lt;P&gt;I already tried to view the NPS logs but there is no events of success or failure (even tough that i enabled the logging).&lt;/P&gt;&lt;P&gt;When i tried to capture the traffic is saw that my computer send his identity and get EAP Failure.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_0-1687955742555.png" style="width: 911px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/188813iE48BDAA32DD8D34E/image-dimensions/911x107?v=v2" width="911" height="107" role="button" title="michaelglosker_0-1687955742555.png" alt="michaelglosker_0-1687955742555.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2023 12:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4863913#M582580</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-06-28T12:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4864789#M582626</link>
      <description>&lt;P&gt;Where did you get that capture from? If the NPS is not showing any logs it could be that is not receiving these RADIUS requests?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 17:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4864789#M582626</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-29T17:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4864796#M582628</link>
      <description>&lt;P&gt;Check if the RADIUS request is reaching the NPS server. Also, check the output of "show authentication session int gig &amp;lt;id&amp;gt; detail" on the Cisco switch.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 17:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4864796#M582628</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-06-29T17:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865531#M582641</link>
      <description>&lt;P&gt;The picture was captured with Wireshark from my laptop that tries to authenticate, probably the NPS server not receiving the logs but i am trying to understand why i also checked if there is any block from the FW side and there is no any rule that block the communication.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 09:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865531#M582641</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-07-01T09:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865536#M582642</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_0-1688205220546.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189126i1ABA67DF119C2168/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelglosker_0-1688205220546.png" alt="michaelglosker_0-1688205220546.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 09:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865536#M582642</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-07-01T09:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865541#M582643</link>
      <description>&lt;P&gt;Hi can I know exactly your issue&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 10:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865541#M582643</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-01T10:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865573#M582644</link>
      <description>&lt;P&gt;Try please to drop the keyword "detail" at the end of the "show authentication" command and share the output for review. You can also enable RADIUS authentication debugs on the switch "debug radius authentication" which should you if the comms with the NPS is working. Another thing you can do from the switch would be to show the aaa server status "show aaa servers" and look at the state lines, if it should show "current UP" it means the switch and the NPS can talk to each other. Finally you can enable the epm logging on the switch which would help you finding out any issue with the dot1x flows.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 11:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865573#M582644</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-01T11:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865755#M582646</link>
      <description>&lt;P&gt;Your switch is not initiating any RADIUS request to the NPS server, hence, no log seen on the server. What is the switchport configuration and AAA configuration done on the switch?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 19:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865755#M582646</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-07-01T19:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865761#M582647</link>
      <description>&lt;P&gt;You not answer my below Q, so I review your previous comment&amp;nbsp;&lt;BR /&gt;NOW&amp;nbsp;&lt;BR /&gt;the SW enable 802.1x but the issue it stop at EAP-response Identity&amp;nbsp;&lt;BR /&gt;This can from EAP method, the user send method that NOT match the EAP method.&lt;BR /&gt;so double check in NPS and user EAP method&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (39).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189215iEDF3147CD1FD5A85/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (39).png" alt="Screenshot (39).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 19:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4865761#M582647</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-01T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866160#M582657</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_0-1688367365524.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189283iEDB4867DABAABB9D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelglosker_0-1688367365524.png" alt="michaelglosker_0-1688367365524.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_1-1688367428528.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189284i8ED490D5BFB3671B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelglosker_1-1688367428528.png" alt="michaelglosker_1-1688367428528.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 06:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866160#M582657</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-07-03T06:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866163#M582658</link>
      <description>&lt;P&gt;According to what you new share' and as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/358459"&gt;@Nancy Saini&lt;/a&gt;&amp;nbsp;mention' your SW never send request to aaa server.&lt;/P&gt;
&lt;P&gt;Share config&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 07:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866163#M582658</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-03T07:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866197#M582660</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_0-1688371188287.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189291i9511FCEDC2A15B50/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelglosker_0-1688371188287.png" alt="michaelglosker_0-1688371188287.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 08:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866197#M582660</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-07-03T08:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866199#M582661</link>
      <description>&lt;P&gt;you config radius-group in authc/authz&amp;nbsp;&lt;BR /&gt;but where is config of server in this group??&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 08:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866199#M582661</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-03T08:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866214#M582662</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="michaelglosker_1-1688373095895.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/189294i39107166331F9715/image-size/medium?v=v2&amp;amp;px=400" role="button" title="michaelglosker_1-1688373095895.png" alt="michaelglosker_1-1688373095895.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 08:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866214#M582662</guid>
      <dc:creator>michaelglosker</dc:creator>
      <dc:date>2023-07-03T08:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1X EAP-TLS Error</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866226#M582663</link>
      <description>&lt;P&gt;&lt;SPAN&gt;ip radius source-interface VLANx&amp;nbsp;&lt;BR /&gt;then ping to server using this VLAN SVI as source, are the ping success ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 08:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-error/m-p/4866226#M582663</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-03T08:53:55Z</dc:date>
    </item>
  </channel>
</rss>

