<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Wrong Interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285787#M596116</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/237724"&gt;M02@rt37&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping is succeeded&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hs08_0-1745818806622.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244219i8FD1B439D3C73AA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="hs08_0-1745818806622.png" alt="hs08_0-1745818806622.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Apr 2025 05:40:38 GMT</pubDate>
    <dc:creator>hs08</dc:creator>
    <dc:date>2025-04-28T05:40:38Z</dc:date>
    <item>
      <title>Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285758#M596112</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I setup Network Policy Server as Radius server to authenticate all my cisco ssh login.&lt;/P&gt;
&lt;P&gt;I found one issue with my C9300 where i already set command 'ip radius source-interface Loopback0' and my loopback ip is 10.107.107.1&lt;/P&gt;
&lt;P&gt;But when this request come to the NPS, the source come from different ip address. The NPS detect request come from ip 10.4.3.254 where this ip belong to interface vlan1. Anyone know why?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hs08_0-1745811000936.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244208iDFEEA588E57052EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hs08_0-1745811000936.png" alt="hs08_0-1745811000936.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hs08_1-1745811030725.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244209iAE8C29727DE86EAE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hs08_1-1745811030725.png" alt="hs08_1-1745811030725.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 03:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285758#M596112</guid>
      <dc:creator>hs08</dc:creator>
      <dc:date>2025-04-28T03:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285761#M596113</link>
      <description>&lt;P&gt;Hi friend,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You assigned source under radius group are you use this group in authc/authz&lt;/P&gt;
&lt;P&gt;Also why this group don't have and server host?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 04:08:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285761#M596113</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-28T04:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285777#M596114</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here my radius config&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ADRADIUS&lt;BR /&gt;server-private 10.103.248.31 key 7 xxxxx&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login ADRADIUS local group ADRADIUS&lt;BR /&gt;aaa authorization exec ADRADIUS local group ADRADIUS&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;ip radius source-interface Loopback0&lt;/P&gt;
&lt;P&gt;line vty 0 4&lt;BR /&gt;authorization exec ADRADIUS&lt;BR /&gt;login authentication ADRADIUS&lt;BR /&gt;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;authorization exec ADRADIUS&lt;BR /&gt;login authentication ADRADIUS&lt;BR /&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;and here debug message&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hs08_0-1745818014076.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244216iEBCF1E8324C43F90/image-size/large?v=v2&amp;amp;px=999" role="button" title="hs08_0-1745818014076.png" alt="hs08_0-1745818014076.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 05:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285777#M596114</guid>
      <dc:creator>hs08</dc:creator>
      <dc:date>2025-04-28T05:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285782#M596115</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1437984"&gt;@hs08&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you try to ping radius server with lo0 as source ip address ?&lt;/P&gt;
&lt;P&gt;ping 10.103.248.31 source Loopback0&lt;/P&gt;
&lt;P&gt;If it fails, that’s 100% why your radius is sourced from vlan1 instead of your loopback0.&lt;/P&gt;
&lt;P&gt;Regarding your log:&lt;/P&gt;
&lt;P&gt;The C9300 send the packet multiple times (retransmissions) but receive no reply:&amp;nbsp;Request timed out!&lt;BR /&gt;No response from (10.103.248.31:1645)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 05:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285782#M596115</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-04-28T05:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285787#M596116</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/237724"&gt;M02@rt37&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ping is succeeded&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hs08_0-1745818806622.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/244219i8FD1B439D3C73AA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="hs08_0-1745818806622.png" alt="hs08_0-1745818806622.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 05:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285787#M596116</guid>
      <dc:creator>hs08</dc:creator>
      <dc:date>2025-04-28T05:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285794#M596117</link>
      <description>&lt;P&gt;Mmm OK&lt;/P&gt;
&lt;P&gt;This log, &lt;EM&gt;NAS-IP-Address [4] 6 10.107.107.1&lt;/EM&gt;,&amp;nbsp;shows that the switch is sending the RADIUS Access-Request with loopback0 as the source ip...&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_radatt/configuration/xe-16/sec-usr-radatt-xe-16-book/sec-rad-nas-ip-cfg.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_radatt/configuration/xe-16/sec-usr-radatt-xe-16-book/sec-rad-nas-ip-cfg.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What is you IOS-xe version please ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 06:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285794#M596117</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-04-28T06:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285797#M596118</link>
      <description>&lt;P&gt;Do debug ip packet &amp;lt;list&amp;gt;&lt;/P&gt;
&lt;P&gt;In list specify the udp port you use for radius and IP.&lt;/P&gt;
&lt;P&gt;Let see if device send from correct IP or there is something else drop traffic.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 06:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285797#M596118</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-28T06:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285848#M596120</link>
      <description>&lt;P&gt;my version is 16.12.4&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 08:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285848#M596120</guid>
      <dc:creator>hs08</dc:creator>
      <dc:date>2025-04-28T08:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Wrong Interface</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285858#M596121</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1437984"&gt;@hs08&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;you need to configure the radius source-interface under the server-group you created:&lt;/P&gt;
&lt;P&gt;aaa group server radius ADRADIUS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip radius source-interface Loopback0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server-private 10.103.248.31 key 7 xxxxx&lt;/P&gt;
&lt;P&gt;You configured this command in global config mode so that it would be used by the default server-group "radius".&lt;BR /&gt;However, you created your own server group ADRADIUS so that this command must be issued in config-sg-radius mode because each server group uses its own radius source-interface.&lt;/P&gt;
&lt;P&gt;As you noticed a ping can only test the IP reachability of the radius server.&lt;BR /&gt;However, in order to test the reachability of the radius &lt;U&gt;service&lt;/U&gt; you can use the following command:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;test aaa group ADRADIUS &amp;lt;username&amp;gt; &amp;lt;password&amp;gt; [new-code|legacy]&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;Whether you need to use new-code or legacy depends on your radius server and in some cases both options might work.&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 09:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-wrong-interface/m-p/5285858#M596121</guid>
      <dc:creator>Jens Albrecht</dc:creator>
      <dc:date>2025-04-28T09:00:28Z</dc:date>
    </item>
  </channel>
</rss>

