<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The command is used to in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/3374360#M73105</link>
    <description>&lt;P&gt;HI,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would happen in this scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access port configured into VLAN50 "&lt;STRONG&gt;switchport access vlan 50&lt;/STRONG&gt;"&amp;nbsp; but the radius server dead configuration "&lt;STRONG class="cCN_CmdName"&gt;authentication event server dead action&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;vlan 10.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;Vlan 10 does not exist on the switch however, only vlan 50.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've come across this config and it seemed to cause a problem, i'm just trying to find out why.&amp;nbsp; This was the issue.&amp;nbsp; ISE went unreachable&amp;nbsp;from local switch.&amp;nbsp; Only phones on the switch stayed authenticated.&amp;nbsp; The PCs dropped off the network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When ISE came back up the PCs still didn't authenticate correctly.&amp;nbsp; On ISE we saw the users as authenticated. But on the switchport, they were showing in an unknown state "show authentication sessions".&amp;nbsp; Bouncing the port caused the users to re-authenticate, but still the port stayed in unknown state.&amp;nbsp; The only work around was to remove the&amp;nbsp;&lt;STRONG class="cCN_CmdName"&gt;authentication event server dead action&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;vlan 10 &lt;/STRONG&gt;and then bounce the port.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I am trying to work out why this config may have caused this issue?&amp;nbsp; Any ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2018 09:08:29 GMT</pubDate>
    <dc:creator>Stuart C</dc:creator>
    <dc:date>2018-04-27T09:08:29Z</dc:date>
    <item>
      <title>authentication event server dead action for radius group</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546202#M73092</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Need help to understand "authentication event server dead " on interface configuration of the IOS.&lt;/P&gt;&lt;P&gt;I found this applies globally, I mean this condition is triggered if all radius servers are dead.&lt;/P&gt;&lt;P&gt;How if we want to make this condition for only one group of radius?&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Tomi&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546202#M73092</guid>
      <dc:creator>tomi.sirait</dc:creator>
      <dc:date>2019-03-11T05:01:13Z</dc:date>
    </item>
    <item>
      <title>The command is used to</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546203#M73094</link>
      <description>&lt;P&gt;The command is used to configure action(s) that will be taken for ports configured for&amp;nbsp;&lt;STRONG&gt;authentication&amp;nbsp;&lt;/STRONG&gt;in the event when all Radius servers become unavailable. For instance:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-weight: bold; line-height: normal;"&gt;authentication event server dead action authorize vlan 55&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-weight: bold; line-height: normal;"&gt;authentication event server alive action reinitialize&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;With the above syntax, the configured port will be authorized/fail-open to VLAN 55 if/when the globally configured Radius servers become unavailable. Once the server(s) become available again all of the configured ports will be re-initialized, thus forcing them to perform regular dot1x/mab authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command is configured per-port and cannot be tied to a set of Radius servers. The radius servers used are configured under your global aaa commands.&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 00:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546203#M73094</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-09-16T00:36:32Z</dc:date>
    </item>
    <item>
      <title>http://www.cisco.com/c/en/us</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546204#M73098</link>
      <description>&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/12-2_55_se/configuration/guide/3750xscg/sw8021x.html#wp1274284&lt;/P&gt;&lt;P&gt;link explains the following command&lt;/P&gt;&lt;P&gt;authentication event server dead action {authorize | reinitialize} vlan vlan-id&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;this is interface level&amp;nbsp; command&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2014 11:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546204#M73098</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2014-09-16T11:24:47Z</dc:date>
    </item>
    <item>
      <title>hi Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546205#M73101</link>
      <description>&lt;P&gt;hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;one small query here.&lt;/P&gt;
&lt;P&gt;now the command also gives &amp;lt;cr&amp;gt; on&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;authentication event server dead action authorize ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;so if i do not specify any VLAN what happens then???&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;Nick&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 May 2016 08:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/2546205#M73101</guid>
      <dc:creator>niketan sutar</dc:creator>
      <dc:date>2016-05-15T08:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: The command is used to</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/3374360#M73105</link>
      <description>&lt;P&gt;HI,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would happen in this scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access port configured into VLAN50 "&lt;STRONG&gt;switchport access vlan 50&lt;/STRONG&gt;"&amp;nbsp; but the radius server dead configuration "&lt;STRONG class="cCN_CmdName"&gt;authentication event server dead action&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;vlan 10.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;Vlan 10 does not exist on the switch however, only vlan 50.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've come across this config and it seemed to cause a problem, i'm just trying to find out why.&amp;nbsp; This was the issue.&amp;nbsp; ISE went unreachable&amp;nbsp;from local switch.&amp;nbsp; Only phones on the switch stayed authenticated.&amp;nbsp; The PCs dropped off the network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When ISE came back up the PCs still didn't authenticate correctly.&amp;nbsp; On ISE we saw the users as authenticated. But on the switchport, they were showing in an unknown state "show authentication sessions".&amp;nbsp; Bouncing the port caused the users to re-authenticate, but still the port stayed in unknown state.&amp;nbsp; The only work around was to remove the&amp;nbsp;&lt;STRONG class="cCN_CmdName"&gt;authentication event server dead action&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;vlan 10 &lt;/STRONG&gt;and then bounce the port.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I am trying to work out why this config may have caused this issue?&amp;nbsp; Any ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 09:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/3374360#M73105</guid>
      <dc:creator>Stuart C</dc:creator>
      <dc:date>2018-04-27T09:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: authentication event server dead action for radius group</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/4434083#M568495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is critical auth for multi-domain:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan &amp;lt;X&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authentication host-mode multi-domain&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authentication event server dead action authorize&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authentication event server dead action authorize voice&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No need to specify the VLAN. It is the access port VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is critical auth for multi-auth:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan &amp;lt;X&amp;gt;&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authentication host-mode multi-auth&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authentication event server dead action reinitialize vlan &amp;lt;X&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;authentication event server dead action authorize voice&lt;/P&gt;&lt;P&gt;authentication event server alive action reinitialize&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check you switchport config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Octavian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 22:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/4434083#M568495</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2021-07-15T22:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: authentication event server dead action for radius group</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/5340509#M598630</link>
      <description>&lt;P&gt;Hi Octavian,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually, at least on newer IOS versions(17.12+), in case of multi-domain, you might want to stay away from authorizing also the voice:&lt;/P&gt;
&lt;P&gt;switchport mode access&lt;/P&gt;
&lt;P&gt;switchport access vlan &amp;lt;X&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;authentication host-mode multi-domain&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;authentication event server dead action authorize&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;authentication event server alive action reinitialize&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you also add 'authentication event server dead action authorize voice' your data vlan users will get authorized on both data and voice VLANs and their MAC addresses will show up in both VLANs. Works for end user, but very messy.&lt;/P&gt;
&lt;P&gt;For this setup suggest using also:&lt;/P&gt;
&lt;P&gt;radius server ISE1&lt;BR /&gt;automate-tester username Test_User ignore-acct-port probe-on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This way your switch stops assuming radius server is back up after the deadtime expires, which will not cause the reinitialize from alive action that would have caused few seconds of downtime on the endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Bogdan&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2025 10:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-event-server-dead-action-for-radius-group/m-p/5340509#M598630</guid>
      <dc:creator>bogdan.sileanu</dc:creator>
      <dc:date>2025-10-21T10:33:37Z</dc:date>
    </item>
  </channel>
</rss>

