<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Afer deep investigation I in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/3706801#M73835</link>
    <description>Hello,

Whether your issue have resovled?
I have occured the same problem,PC-IP Phone-SW2960L-Auth server
the MAC can pass,but when enter 802.1X process,the auth status will go to stoped.
for example:
#show authentication sessions interface g0/1 details 
Method status list: 
      Method            State 

      dot1x              Stopped
      mab                Stopped

Other config info:
 
interface GigabitEthernet0/1
 switchport access vlan 100
 switchport mode access
 switchport voice vlan 59
 authentication event fail action authorize vlan 266
 authentication event no-response action authorize vlan 266
 authentication host-mode multi-domain
 authentication port-control auto
 authentication violation protect
 mab
 dot1x pae authenticator
 dot1x timeout quiet-period 5
 dot1x timeout tx-period 3
 dot1x timeout supp-timeout 5
 dot1x max-req 1
 dot1x max-reauth-req 1
 spanning-tree portfast edge
!</description>
    <pubDate>Fri, 14 Sep 2018 02:00:10 GMT</pubDate>
    <dc:creator>Rps-Cheers</dc:creator>
    <dc:date>2018-09-14T02:00:10Z</dc:date>
    <item>
      <title>802.1x authentication problem on C2960S-48TS-L with Linux clients</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650116#M73815</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Due to implementing wired 802.1x in my company I fased with &lt;STRONG&gt;problem of authentication&lt;/STRONG&gt; of some Linux computers (Ubuntu 13.10+) via mab at the one of my Access switches(C2960S-48TS-L). The problem exist on IOS 12.55 and&amp;nbsp;15.0(2)SE6.&lt;/P&gt;&lt;P&gt;It seems that Authenticator can't detect MAC address of supplicant. In debug the MAC address is&amp;nbsp;(Unknown MAC) or&amp;nbsp;(0000.0000.0000).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before authentication I could&amp;nbsp;see&amp;nbsp;registered MAC address&amp;nbsp;on the switchport interface(without 802.1x settings on the port):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;sh mac address-table interface g1/0/2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;"before 802.1x authentication"&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;Vlan &amp;nbsp; &amp;nbsp;Mac Address &amp;nbsp; &amp;nbsp; &amp;nbsp; Type &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Ports&lt;BR /&gt;---- &amp;nbsp; &amp;nbsp;----------- &amp;nbsp; &amp;nbsp; &amp;nbsp; -------- &amp;nbsp; &amp;nbsp;-----&lt;BR /&gt;&amp;nbsp; &amp;nbsp;2 &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;0015.990f.60d9&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp;STATIC &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi1/0/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The host should get to Vlan 2 after failed authentication(according to port settings). But actually after trying to authenticate the h&lt;U&gt;ost on this port &lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;loses connection&lt;/U&gt; with network and doesn't get in 2 Vlan&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14px;"&gt;sh mac address-table interface g1/0/2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/EM&gt;&lt;STRONG style="font-size: 14px;"&gt;&lt;EM&gt;"after&amp;nbsp;802.1x authentication"&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR style="font-size: 14px;" /&gt;Vlan &amp;nbsp; &amp;nbsp;Mac Address &amp;nbsp; &amp;nbsp; &amp;nbsp; Type &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Ports&lt;BR style="font-size: 14px;" /&gt;---- &amp;nbsp; &amp;nbsp;----------- &amp;nbsp; &amp;nbsp; &amp;nbsp; -------- &amp;nbsp; &amp;nbsp;-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh authentication sessions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Interface &amp;nbsp;MAC Address &amp;nbsp; &amp;nbsp; Method &amp;nbsp; Domain &amp;nbsp; Status &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Session ID&lt;BR /&gt;Gi1/0/24 &amp;nbsp; (unknown) &amp;nbsp; &amp;nbsp; &amp;nbsp; dot1x &amp;nbsp; &amp;nbsp;DATA &amp;nbsp; &amp;nbsp; Authz Success &amp;nbsp;6A7D1FAF0000000000023E32&lt;BR /&gt;Gi1/0/25 &amp;nbsp; (unknown) &amp;nbsp; &amp;nbsp; &amp;nbsp; dot1x &amp;nbsp; &amp;nbsp;DATA &amp;nbsp; &amp;nbsp; Authz Success &amp;nbsp;6A7D1FAF0000000200024193&lt;BR /&gt;Gi1/0/2 &amp;nbsp; &amp;nbsp;(unknown) &amp;nbsp; &amp;nbsp; &amp;nbsp; mab &amp;nbsp; &amp;nbsp; &amp;nbsp;UNKNOWN &amp;nbsp;Running &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6A7D1FAF000000280011BA1A&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh dot1x interface g1/0/2 details&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet1/0/2&lt;BR /&gt;-----------------------------------&lt;BR /&gt;PAE &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = AUTHENTICATOR&lt;BR /&gt;QuietPeriod &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = 5&lt;BR /&gt;ServerTimeout &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = 0&lt;BR /&gt;SuppTimeout &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = 30&lt;BR /&gt;ReAuthMax &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; = 2&lt;BR /&gt;MaxReq &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= 2&lt;BR /&gt;TxPeriod &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;= 3&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh run int g1/0/2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/2&lt;BR /&gt;&amp;nbsp;description ## User Port ##&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 5&lt;BR /&gt;&amp;nbsp;switchport port-security maximum 5&lt;BR /&gt;&amp;nbsp;switchport port-security&lt;BR /&gt;&amp;nbsp;switchport port-security aging time 2&lt;BR /&gt;&amp;nbsp;switchport port-security aging type inactivity&lt;BR /&gt;&amp;nbsp;ip arp inspection limit rate 120&lt;BR /&gt;&amp;nbsp;authentication event fail retry 0 action authorize vlan 2&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 2&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 2&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-host&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate 3900&lt;BR /&gt;&amp;nbsp;authentication timer inactivity 300&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout quiet-period 5&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 3&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 1.00&lt;BR /&gt;&amp;nbsp;storm-control multicast level 1.00&lt;BR /&gt;&amp;nbsp;storm-control action trap&lt;BR /&gt;&amp;nbsp;no cdp enable&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;&amp;nbsp;spanning-tree guard root&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to change &amp;nbsp;authentication host-mode to multi-domain but the problem remains.&lt;/P&gt;&lt;P&gt;"debug dot1x all" in the attached file.&lt;/P&gt;&lt;P&gt;Please help me to resolve this issue&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650116#M73815</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2019-03-11T05:35:26Z</dc:date>
    </item>
    <item>
      <title>Also in this case switch</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650117#M73816</link>
      <description>&lt;P&gt;Also in this case switch doesn't send any authentication information to NPS server(Windows Server 2008 R2)&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 08:46:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650117#M73816</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T08:46:40Z</dc:date>
    </item>
    <item>
      <title>You should remove any port</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650118#M73817</link>
      <description>&lt;P&gt;You should remove any port-security settings before enabling dot1x on a port, these two functions will not work well together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jan.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650118#M73817</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-03-26T14:10:43Z</dc:date>
    </item>
    <item>
      <title>Cisco support 802.1x + port</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650119#M73819</link>
      <description>&lt;P&gt;I have removed port security but still have failed authentication on the port&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;002262: Mar 26 16:23:26.516: dot1x-ev(Gi1/0/2): Deleting client 0x9A000053 (0000.0000.0000)&lt;BR /&gt;002263: Mar 26 16:23:26.516: dot1x-ev:Delete auth client (0x9A000053) message&lt;BR /&gt;002264: Mar 26 16:23:26.516: dot1x-ev:Auth client ctx destroyed&lt;BR /&gt;002265: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: initial state auth_initialize has enter&lt;BR /&gt;002266: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_initialize_enter called&lt;BR /&gt;002267: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: during state auth_initialize, got event 0(cfg_auto)&lt;BR /&gt;002268: Mar 26 16:23:26.715: @@@ dot1x_auth Gi1/0/2: auth_initialize -&amp;gt; auth_disconnected&lt;BR /&gt;002269: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_disconnected_enter called&lt;BR /&gt;002270: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: idle during state auth_disconnected&lt;BR /&gt;002271: Mar 26 16:23:26.715: @@@ dot1x_auth Gi1/0/2: auth_disconnected -&amp;gt; auth_restart&lt;BR /&gt;002272: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_restart_enter called&lt;BR /&gt;002273: Mar 26 16:23:26.715: dot1x-ev(Gi1/0/2): Sending create new context event to EAP for 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002274: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: initial state auth_bend_initialize has enter&lt;BR /&gt;002275: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_initialize_enter called&lt;BR /&gt;002276: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: initial state auth_bend_initialize has idle&lt;BR /&gt;002277: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: during state auth_bend_initialize, got event 16383(idle)&lt;BR /&gt;002278: Mar 26 16:23:26.715: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_initialize -&amp;gt; auth_bend_idle&lt;BR /&gt;002279: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_idle_enter called&lt;BR /&gt;002280: Mar 26 16:23:26.715: dot1x-ev(Gi1/0/2): Created a client entry (0x6D000054)&lt;BR /&gt;002281: Mar 26 16:23:26.715: dot1x-ev(Gi1/0/2): Dot1x authentication started for 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002282: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): Posting !EAP_RESTART on Client 0x6D000054&lt;BR /&gt;002283: Mar 26 16:23:26.715: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: during state auth_restart, got event 6(no_eapRestart)&lt;BR /&gt;002284: Mar 26 16:23:26.715: @@@ dot1x_auth Gi1/0/2: auth_restart -&amp;gt; auth_connecting&lt;BR /&gt;002285: Mar 26 16:23:26.715: dot1x-sm(Gi1/0/2): 0x6D000054:auth_connecting_enter called&lt;BR /&gt;002286: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): 0x6D000054:auth_restart_connecting_action called&lt;BR /&gt;002287: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): Posting RX_REQ on Client 0x6D000054&lt;BR /&gt;002288: Mar 26 16:23:26.721: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: during state auth_connecting, got event 10(eapReq_no_reAuthMax)&lt;BR /&gt;002289: Mar 26 16:23:26.721: @@@ dot1x_auth Gi1/0/2: auth_connecting -&amp;gt; auth_authenticating&lt;BR /&gt;002290: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): 0x6D000054:auth_authenticating_enter called&lt;BR /&gt;002291: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): 0x6D000054:auth_connecting_authenticating_action called&lt;BR /&gt;002292: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): Posting AUTH_START for 0x6D000054&lt;BR /&gt;002293: Mar 26 16:23:26.721: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: during state auth_bend_idle, got event 4(eapReq_authStart)&lt;BR /&gt;002294: Mar 26 16:23:26.721: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_idle -&amp;gt; auth_bend_request&lt;BR /&gt;002295: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_enter called&lt;BR /&gt;002296: Mar 26 16:23:26.721: dot1x-ev(Gi1/0/2): Sending EAPOL packet to group PAE address&lt;BR /&gt;002297: Mar 26 16:23:26.721: dot1x-ev(Gi1/0/2): Role determination not required&lt;BR /&gt;002298: Mar 26 16:23:26.721: dot1x-registry:registry:dot1x_ether_macaddr called&lt;BR /&gt;002299: Mar 26 16:23:26.721: dot1x-ev(Gi1/0/2): Sending out EAPOL packet&lt;BR /&gt;002300: Mar 26 16:23:26.721: EAPOL pak dump Tx&lt;BR /&gt;002301: Mar 26 16:23:26.721: EAPOL Version: 0x3 &amp;nbsp;type: 0x0 &amp;nbsp;length: 0x0005&lt;BR /&gt;002302: Mar 26 16:23:26.721: EAP code: 0x1 &amp;nbsp;id: 0x1 &amp;nbsp;length: 0x0005 type: 0x1&lt;BR /&gt;002303: Mar 26 16:23:26.721: dot1x-packet(Gi1/0/2): EAPOL packet sent to client 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002304: Mar 26 16:23:26.721: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_idle_request_action called&lt;BR /&gt;002305: Mar 26 16:23:29.814: dot1x-sm(Gi1/0/2): Posting EAP_REQ for 0x6D000054&lt;BR /&gt;002306: Mar 26 16:23:29.814: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: during state auth_bend_request, got event 7(eapReq)&lt;BR /&gt;002307: Mar 26 16:23:29.814: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_request -&amp;gt; auth_bend_request&lt;BR /&gt;002308: Mar 26 16:23:29.814: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_request_action called&lt;BR /&gt;002309: Mar 26 16:23:29.814: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_enter called&lt;BR /&gt;002310: Mar 26 16:23:29.814: dot1x-ev(Gi1/0/2): Sending EAPOL packet to group PAE address&lt;BR /&gt;002311: Mar 26 16:23:29.814: dot1x-ev(Gi1/0/2): Role determination not required&lt;BR /&gt;002312: Mar 26 16:23:29.814: dot1x-registry:registry:dot1x_ether_macaddr called&lt;BR /&gt;002313: Mar 26 16:23:29.814: dot1x-ev(Gi1/0/2): Sending out EAPOL packet&lt;BR /&gt;002314: Mar 26 16:23:29.814: EAPOL pak dump Tx&lt;BR /&gt;002315: Mar 26 16:23:29.814: EAPOL Version: 0x3 &amp;nbsp;type: 0x0 &amp;nbsp;length: 0x0005&lt;BR /&gt;002316: Mar 26 16:23:29.814: EAP code: 0x1 &amp;nbsp;id: 0x1 &amp;nbsp;length: 0x0005 type: 0x1&lt;BR /&gt;002317: Mar 26 16:23:29.814: dot1x-packet(Gi1/0/2): EAPOL packet sent to client 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002318: Mar 26 16:23:32.907: dot1x-sm(Gi1/0/2): Posting EAP_REQ for 0x6D000054&lt;BR /&gt;002319: Mar 26 16:23:32.907: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: during state auth_bend_request, got event 7(eapReq)&lt;BR /&gt;002320: Mar 26 16:23:32.907: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_request -&amp;gt; auth_bend_request&lt;BR /&gt;002321: Mar 26 16:23:32.907: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_request_action called&lt;BR /&gt;002322: Mar 26 16:23:32.907: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_enter called&lt;BR /&gt;002323: Mar 26 16:23:32.913: dot1x-ev(Gi1/0/2): Sending EAPOL packet to group PAE address&lt;BR /&gt;002324: Mar 26 16:23:32.913: dot1x-ev(Gi1/0/2): Role determination not required&lt;BR /&gt;002325: Mar 26 16:23:32.913: dot1x-registry:registry:dot1x_ether_macaddr called&lt;BR /&gt;002326: Mar 26 16:23:32.913: dot1x-ev(Gi1/0/2): Sending out EAPOL packet&lt;BR /&gt;002327: Mar 26 16:23:32.913: EAPOL pak dump Tx&lt;BR /&gt;002328: Mar 26 16:23:32.913: EAPOL Version: 0x3 &amp;nbsp;type: 0x0 &amp;nbsp;length: 0x0005&lt;BR /&gt;002329: Mar 26 16:23:32.913: EAP code: 0x1 &amp;nbsp;id: 0x1 &amp;nbsp;length: 0x0005 type: 0x1&lt;BR /&gt;002330: Mar 26 16:23:32.913: dot1x-packet(Gi1/0/2): EAPOL packet sent to client 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002331: Mar 26 16:23:36.001: dot1x-ev(Gi1/0/2): Received an EAP Timeout&lt;BR /&gt;002332: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): Posting EAP_TIMEOUT for 0x6D000054&lt;BR /&gt;002333: Mar 26 16:23:36.001: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: during state auth_bend_request, got event 12(eapTimeout)&lt;BR /&gt;002334: Mar 26 16:23:36.001: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_request -&amp;gt; auth_bend_timeout&lt;BR /&gt;002335: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_timeout_enter called&lt;BR /&gt;002336: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_request_timeout_action called&lt;BR /&gt;002337: Mar 26 16:23:36.001: &amp;nbsp; &amp;nbsp; dot1x_auth_bend Gi1/0/2: idle during state auth_bend_timeout&lt;BR /&gt;002338: Mar 26 16:23:36.001: @@@ dot1x_auth_bend Gi1/0/2: auth_bend_timeout -&amp;gt; auth_bend_idle&lt;BR /&gt;002339: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): 0x6D000054:auth_bend_idle_enter called&lt;BR /&gt;002340: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): Posting AUTH_TIMEOUT on Client 0x6D000054&lt;BR /&gt;002341: Mar 26 16:23:36.001: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: during state auth_authenticating, got event 14(authTimeout)&lt;BR /&gt;002342: Mar 26 16:23:36.001: @@@ dot1x_auth Gi1/0/2: auth_authenticating -&amp;gt; auth_authc_result&lt;BR /&gt;002343: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): 0x6D000054:auth_authenticating_exit called&lt;BR /&gt;002344: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): 0x6D000054:auth_authc_result_enter called&lt;BR /&gt;002345: Mar 26 16:23:36.001: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi1/0/2 AuditSessionID 6A7D1FAF0000006001916AC3&lt;BR /&gt;002346: Mar 26 16:23:36.001: dot1x-ev(Gi1/0/2): Sending event (2) to Auth Mgr for 0000.0000.0000&lt;BR /&gt;002347: Mar 26 16:23:36.001: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/2 AuditSessionID 6A7D1FAF0000006001916AC3&lt;BR /&gt;002348: Mar 26 16:23:36.001: dot1x-ev(Gi1/0/2): Received Authz fail for the client &amp;nbsp;0x6D000054 (0000.0000.0000)&lt;BR /&gt;002349: Mar 26 16:23:36.001: dot1x-ev(Gi1/0/2): Deleting client 0x6D000054 (0000.0000.0000)&lt;BR /&gt;002350: Mar 26 16:23:36.001: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Gi1/0/2 AuditSessionID 6A7D1FAF0000006001916AC3&lt;BR /&gt;002351: Mar 26 16:23:36.001: dot1x-sm(Gi1/0/2): Posting_AUTHZ_FAIL on Client 0x6D000054&lt;BR /&gt;002352: Mar 26 16:23:36.001: &amp;nbsp; &amp;nbsp; dot1x_auth Gi1/0/2: during state auth_authc_result, got event 22(authzFail)&lt;BR /&gt;002353: Mar 26 16:23:36.006: @@@ dot1x_auth Gi1/0/2: auth_authc_result -&amp;gt; auth_held&lt;BR /&gt;002354: Mar 26 16:23:36.006: dot1x-ev:Delete auth client (0x6D000054) message&lt;BR /&gt;002355: Mar 26 16:23:36.006: dot1x-ev:Auth client ctx destroyed&lt;BR /&gt;002356: Mar 26 16:23:36.006: dot1x-ev:Aborted posting message to authenticator state machine: Invalid client&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650119#M73819</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T14:26:19Z</dc:date>
    </item>
    <item>
      <title>Port security normally works</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650120#M73821</link>
      <description>&lt;P&gt;Port security normally works with 802.1x. &lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/50sg/configuration/guide/Wrapper-46SG/dot1x.html#wp1151392"&gt;link&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650120#M73821</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T14:27:18Z</dc:date>
    </item>
    <item>
      <title>I see that, however that is a</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650121#M73823</link>
      <description>&lt;P&gt;I see that, however that is a very old software and the document also, i have had plenty of problems with running port-security and dot1x/mab on the same port, some of them very similar to yours. Multiple Cisco people have told me that you should not run port sec and dot1x on the port at the same time. Also try to reboot the switch after you enable dot1x on the ports, i have seen the "unknown" status many times, which only got solved by rebooting the switch after enabling dot1x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650121#M73823</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-03-26T14:33:52Z</dc:date>
    </item>
    <item>
      <title>Looks like your switch is not</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650122#M73825</link>
      <description>&lt;P&gt;Looks like your switch is not even trying mab. What do you get if you do "show auth sess int g1/0/2 det"&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650122#M73825</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-03-26T14:35:40Z</dc:date>
    </item>
    <item>
      <title>I just noticed, you are</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650123#M73827</link>
      <description>&lt;P&gt;I just noticed, you are missing the following commands on your interface .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;authentication order dot1x mab&lt;/P&gt;&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650123#M73827</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-03-26T14:37:18Z</dc:date>
    </item>
    <item>
      <title>sh authentication sessions</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650124#M73829</link>
      <description>&lt;P&gt;sh authentication sessions interface g1/0/2 (there is no option 'det' in this command)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;GigabitEthernet1/0/2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;Unknown&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;Unknown&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Running&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;UNKNOWN&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;multi-host&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;both&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;6A7D1FAF00000064019FAD1E&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x0000006C&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0xE4000065&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Failed over&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mab &amp;nbsp; &amp;nbsp; &amp;nbsp;Running&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650124#M73829</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T14:41:23Z</dc:date>
    </item>
    <item>
      <title>The problem remains with this</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650125#M73830</link>
      <description>&lt;P&gt;The problem remains with this 2 commands.&lt;/P&gt;&lt;P&gt;It seems that 802.1x on switch cannot detect MAC address of the client. And tryes&amp;nbsp;0000.0000.0000. And finally block port:&lt;/P&gt;&lt;P&gt;&amp;nbsp;dot1x-ev:Auth client ctx destroyed&lt;BR /&gt;&amp;nbsp;dot1x-ev:Aborted posting message to authenticator state machine: Invalid client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650125#M73830</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T14:46:27Z</dc:date>
    </item>
    <item>
      <title>Have you tried rebooting the</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650126#M73831</link>
      <description>&lt;P&gt;Have you tried rebooting the switch ?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650126#M73831</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-03-26T14:49:41Z</dc:date>
    </item>
    <item>
      <title>Yes, I tried. I have even</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650127#M73832</link>
      <description>&lt;P&gt;Yes, I tried. I have even updated IOS from 12.55 to &lt;SPAN style="font-size: 14.3999996185303px;"&gt;15.0(2)SE6&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2015 14:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650127#M73832</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-26T14:52:02Z</dc:date>
    </item>
    <item>
      <title>Afer deep investigation I</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650128#M73833</link>
      <description>&lt;P&gt;Afer deep investigation I found that the problem doesn't depends on switch. It problem with host. I configured span and&amp;nbsp;ran Wireshark. I&amp;nbsp;found that after starting "authentication port-control auto" on port the host after failed 802.1x authentication doesn't sent any packages that is why switch cannot detect source mac address for mab. I found this device. It is Samsung Printer ML-551x 651x series. Soon I will try to configure 802.1x authentication on this printer via web interface.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2015 09:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/2650128#M73833</guid>
      <dc:creator>maksim.sidorchuk</dc:creator>
      <dc:date>2015-03-27T09:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Afer deep investigation I</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/3706801#M73835</link>
      <description>Hello,

Whether your issue have resovled?
I have occured the same problem,PC-IP Phone-SW2960L-Auth server
the MAC can pass,but when enter 802.1X process,the auth status will go to stoped.
for example:
#show authentication sessions interface g0/1 details 
Method status list: 
      Method            State 

      dot1x              Stopped
      mab                Stopped

Other config info:
 
interface GigabitEthernet0/1
 switchport access vlan 100
 switchport mode access
 switchport voice vlan 59
 authentication event fail action authorize vlan 266
 authentication event no-response action authorize vlan 266
 authentication host-mode multi-domain
 authentication port-control auto
 authentication violation protect
 mab
 dot1x pae authenticator
 dot1x timeout quiet-period 5
 dot1x timeout tx-period 3
 dot1x timeout supp-timeout 5
 dot1x max-req 1
 dot1x max-reauth-req 1
 spanning-tree portfast edge
!</description>
      <pubDate>Fri, 14 Sep 2018 02:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-authentication-problem-on-c2960s-48ts-l-with-linux/m-p/3706801#M73835</guid>
      <dc:creator>Rps-Cheers</dc:creator>
      <dc:date>2018-09-14T02:00:10Z</dc:date>
    </item>
  </channel>
</rss>

