<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Switch AAA Authencation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000594#M586546</link>
    <description>&lt;P&gt;Hi Think its a EVE-NG limitations,&lt;/P&gt;
&lt;P&gt;if i enable only MAB even then i dont see any packets.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 08:29:38 GMT</pubDate>
    <dc:creator>Mahendervyas35821</dc:creator>
    <dc:date>2024-01-19T08:29:38Z</dc:date>
    <item>
      <title>Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000002#M586509</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;
&lt;P&gt;Was trying to do AAA authentication for Radius and observed one issue.&lt;/P&gt;
&lt;P&gt;When i put authentication open then Dot1x and mab both works fine but when i do not configure authentication open command dot1x works fine but mab device does not work in this scenerio.&lt;/P&gt;
&lt;P&gt;please find my interface commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface Ethernet0/1&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000002#M586509</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-18T16:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000007#M586510</link>
      <description>&lt;P&gt;use this:&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;authentication order mab dot1x&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000007#M586510</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2024-01-18T16:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000011#M586511</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317086"&gt;@Charlie Moreton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried this command as well.&lt;/P&gt;
&lt;P&gt;It is of no use.&lt;/P&gt;
&lt;P&gt;Even tried only mab.&lt;/P&gt;
&lt;P&gt;Until i give authentication open command mab is not working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 16:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000011#M586511</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-18T16:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000014#M586512</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1035237"&gt;@Mahendervyas35821&lt;/a&gt; look in the ISE live logs and confirm what authorisation rule the MAB endpoints match, it must receive an access-accept.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000014#M586512</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-18T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000017#M586513</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If authentication session starts from Switc then ISE policy is matching and works, But authentication session is not starting until i configure authentication open command in Switch interface.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000017#M586513</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-18T17:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000021#M586515</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1035237"&gt;@Mahendervyas35821&lt;/a&gt; provide screenshot of ISE live logs the endpoint matches.&lt;/P&gt;
&lt;P&gt;From the switch please provide - "show authentication session interface x/y/z detail" when in closed mode and another in open mode for comparison.&lt;/P&gt;
&lt;P&gt;Turn on aaa/radius debugs when in closed mode and provide the output.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000021#M586515</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-18T17:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000024#M586516</link>
      <description>&lt;P&gt;What is the source you use to connect to radius is it vlan 20 SVI?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 17:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000024#M586516</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-18T17:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000546#M586539</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please find output of authentication open and closed status.&lt;/P&gt;
&lt;P&gt;If authentication closed configured there is no authentication session starts.&lt;/P&gt;
&lt;P&gt;Auth open status.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mahendervyas35821_0-1705647908627.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207867i153E43B19E67B65C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mahendervyas35821_0-1705647908627.png" alt="Mahendervyas35821_0-1705647908627.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Auth close status.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mahendervyas35821_1-1705648104835.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207870iC1AC79473FDBF9BF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mahendervyas35821_1-1705648104835.png" alt="Mahendervyas35821_1-1705648104835.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 07:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000546#M586539</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-19T07:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000554#M586541</link>
      <description>&lt;P&gt;friend,&amp;nbsp;&lt;BR /&gt;the only reason that in my mind you use VLAN 20 SVI to connect to AAA and this SVI is down when there are no L2 port in that VLAN.&amp;nbsp;&lt;BR /&gt;so I will ask you again are you use VLAN20 as source ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 07:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000554#M586541</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T07:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000571#M586542</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nothing to do with SVI, only issue with MAB.&lt;/P&gt;
&lt;P&gt;Everything works fine if i use dot1x supplicant.If i use MAB supplicant then authentication does not start.&lt;/P&gt;
&lt;P&gt;Even for MAB supplicant if i use authentication open command everything works fine but i dont want to keep authentication open.&lt;/P&gt;
&lt;P&gt;i am not sure why your pointing this issue to SVI as there is nothing to do with SVI or L2 vlan, routing and SVI works fine.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 07:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000571#M586542</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-19T07:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000578#M586543</link>
      <description>&lt;P&gt;&lt;SPAN&gt;try below (you must sure that there is no client already authc/authz in this port )&lt;BR /&gt;interface Ethernet0/X&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;switchport access vlan 20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;switchport mode access&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication order&amp;nbsp; &lt;STRONG&gt;mab dot1x&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication priority&amp;nbsp; &lt;STRONG&gt;mab dot1x&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication port-control auto&lt;BR /&gt;&lt;/SPAN&gt;authentication control-direction both&lt;BR /&gt;authentication host-mode &lt;STRONG&gt;single&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;mab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000578#M586543</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T08:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000582#M586544</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; Tried this as well.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Mahendervyas35821_0-1705651981934.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207886i80402137BC4AEC17/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Mahendervyas35821_0-1705651981934.png" alt="Mahendervyas35821_0-1705651981934.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;No luck same issue.&lt;/P&gt;
&lt;P&gt;Authentication does not start.&lt;/P&gt;
&lt;P&gt;Note :- this is lab environment with eve-ng&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000582#M586544</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-19T08:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000583#M586545</link>
      <description>&lt;P&gt;first what you config is not same as I share&amp;nbsp;&lt;BR /&gt;and if you use same command and&amp;nbsp;&lt;BR /&gt;debug mab all &amp;lt;&amp;lt;- dont see any packets&amp;nbsp;&lt;BR /&gt;then is eve-ng issue not your config issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see same issue week ago.&amp;nbsp;&lt;BR /&gt;sorry this Virtual Lab limitation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000583#M586545</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T08:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000594#M586546</link>
      <description>&lt;P&gt;Hi Think its a EVE-NG limitations,&lt;/P&gt;
&lt;P&gt;if i enable only MAB even then i dont see any packets.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000594#M586546</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-19T08:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000596#M586548</link>
      <description>&lt;P&gt;Yes, sorry for this bad news&amp;nbsp;&lt;BR /&gt;have a nice weekend&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000596#M586548</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T08:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000603#M586549</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; Just wanted to know when you faced similar issue in lab, is it fixed for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 08:46:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000603#M586549</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2024-01-19T08:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch AAA Authencation</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000634#M586550</link>
      <description>&lt;P&gt;what is the ver. of Eve-ng you use ?&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 09:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-aaa-authencation/m-p/5000634#M586550</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-19T09:45:00Z</dc:date>
    </item>
  </channel>
</rss>

