<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Share your switch config. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622475#M74709</link>
    <description>&lt;P&gt;Share your switch config..following is sample switch config and check NAD OS compatibility with ISE&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/compatibility/ise_sdt.html&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;radius-server host isexxxxx auth-port 1812 acct-port 1813&lt;BR /&gt;radius-server key xxxx&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;ip radius source-interface gxx&lt;BR /&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;interface range gxx&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;mab&lt;BR /&gt;authentication open&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;switchport access vlan x&lt;BR /&gt;switchport voice vlan x&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;no shutdown&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;ip device tracking&lt;BR /&gt;ip dhcp snooping&lt;/P&gt;</description>
    <pubDate>Wed, 18 Feb 2015 15:14:46 GMT</pubDate>
    <dc:creator>Venkatesh Attuluri</dc:creator>
    <dc:date>2015-02-18T15:14:46Z</dc:date>
    <item>
      <title>Cisco ISE some Radius issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622473#M74707</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;Dear guys,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I deployed Cisco ISE for Network Access Control. My topology as described as attached image. I configured Cisco ISE as Radius Server for Client Access Control. But, I got some problems such as:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;No Accounting Start. (I have configured accouting on Switch 2960).&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;Radius Request Dropped (attached image). These NAS IP Address are Servers on same subnet with Cisco ISE.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; color: #000000; font-style: normal; font-size: 10pt; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;I would greatly appreciate any help you can give me in working this problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; color: #000000; font-style: normal; font-size: 10pt; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;Have a nice day,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-indent: 0px; color: #000000; font-style: normal; font-size: 10pt; font-family: arial,helvetica,sans-serif; font-weight: normal;"&gt;Thanks and Regrads,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622473#M74707</guid>
      <dc:creator>lhviet001</dc:creator>
      <dc:date>2019-03-11T05:25:17Z</dc:date>
    </item>
    <item>
      <title>Just to clarify, you have of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622474#M74708</link>
      <description>&lt;P&gt;Just to clarify, you have of course created your switches in the device list in ISE, and used the samme password both in the switch and in ise for radius ?&lt;/P&gt;&lt;P&gt;How does your radius config look in your switches ?&lt;/P&gt;&lt;P&gt;What software are you running on the switches ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2015 17:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622474#M74708</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-02-06T17:22:21Z</dc:date>
    </item>
    <item>
      <title>Share your switch config.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622475#M74709</link>
      <description>&lt;P&gt;Share your switch config..following is sample switch config and check NAD OS compatibility with ISE&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/compatibility/ise_sdt.html&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;radius-server host isexxxxx auth-port 1812 acct-port 1813&lt;BR /&gt;radius-server key xxxx&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;ip radius source-interface gxx&lt;BR /&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;interface range gxx&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;mab&lt;BR /&gt;authentication open&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;switchport access vlan x&lt;BR /&gt;switchport voice vlan x&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;no shutdown&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;ip device tracking&lt;BR /&gt;ip dhcp snooping&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 15:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622475#M74709</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2015-02-18T15:14:46Z</dc:date>
    </item>
    <item>
      <title>Sorry for late reply.Here is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622476#M74710</link>
      <description>&lt;P&gt;Sorry for late reply.&lt;/P&gt;&lt;P&gt;Here is my switch config.&lt;/P&gt;&lt;TABLE border="1" cellpadding="1" cellspacing="1" style="width: 500px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Current configuration : 8630 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Switch&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;no logging console&lt;BR /&gt;enable password ******************&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa authorization auth-proxy default group radius&lt;BR /&gt;aaa accounting delay-start all&lt;BR /&gt;aaa accounting auth-proxy default start-stop group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;aaa accounting network default start-stop group radius&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;&amp;nbsp;client A.B.C.D server-key keystrings&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp snooping&lt;BR /&gt;ip device tracking&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-447922560&lt;BR /&gt;&amp;nbsp;enrollment selfsigned&lt;BR /&gt;&amp;nbsp;subject-name cn=IOS-Self-Signed-Certificate-447922560&lt;BR /&gt;&amp;nbsp;revocation-check none&lt;BR /&gt;&amp;nbsp;rsakeypair TP-self-signed-447922560&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-447922560&lt;BR /&gt;&amp;nbsp;certificate self-signed 01&lt;BR /&gt;&amp;nbsp; xxxxx&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;vlan 139,153,401-402,999,1501-1502&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt;&amp;nbsp;switchport access vlan 139&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication open&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer inactivity 180&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt;&amp;nbsp;switchport access vlan 139&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;ip access-group ACL-ALLOW in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 139&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication open&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication timer inactivity 180&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan139&lt;BR /&gt;&amp;nbsp;ip address E.F.G.H 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway I.J.K.L&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended ACL-ALLOW&lt;BR /&gt;&amp;nbsp;permit ip any any&lt;BR /&gt;ip access-list extended ACL-DEFAULT&lt;BR /&gt;&amp;nbsp;remark Allow DHCP&lt;BR /&gt;&amp;nbsp;permit udp any eq bootpc any eq bootps&lt;BR /&gt;&amp;nbsp;remark Allow DNS&lt;BR /&gt;&amp;nbsp;permit udp any any eq domain&lt;BR /&gt;&amp;nbsp;permit icmp any any&lt;BR /&gt;&amp;nbsp;permit tcp any host A.B.C.D eq 8443&lt;BR /&gt;&amp;nbsp;permit tcp any host A.B.C.D eq 443&lt;BR /&gt;&amp;nbsp;permit tcp any host A.B.C.D eq www&lt;BR /&gt;&amp;nbsp;permit tcp any host A.B.C.D eq 8905&lt;BR /&gt;&amp;nbsp;permit tcp any host A.B.C.D eq 8909&lt;BR /&gt;&amp;nbsp;permit udp any host A.B.C.D eq 8905&lt;BR /&gt;&amp;nbsp;permit udp any host A.B.C.D eq 8909&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any any&lt;BR /&gt;ip access-list extended ACL-WEBAUTH-REDIRECT&lt;BR /&gt;&amp;nbsp;permit tcp any any eq www&lt;BR /&gt;&amp;nbsp;permit tcp any any eq 443&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; ip any any&lt;BR /&gt;ip radius source-interface Vlan139&lt;BR /&gt;snmp-server community keystrings RW&lt;BR /&gt;snmp-server enable traps snmp linkdown linkup&lt;BR /&gt;snmp-server enable traps mac-notification change move&lt;BR /&gt;snmp-server host A.B.C.D version 2c keystrings&amp;nbsp; mac-notification&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server host A.B.C.D auth-port 1812 acct-port 1813 key STRINGSKEY&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 5 15&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;My switch version is&lt;/P&gt;&lt;P&gt;WS-2960 &amp;nbsp; 12.2(55)SE5 C2960-LANBASEK9-M&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#000000; font-style:normal; font-size:10pt; font-family:arial,helvetica,sans-serif; font-weight:normal"&gt;I would greatly appreciate any help you can give me in working this problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 12:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-some-radius-issues/m-p/2622476#M74710</guid>
      <dc:creator>lhviet001</dc:creator>
      <dc:date>2015-03-03T12:59:40Z</dc:date>
    </item>
  </channel>
</rss>

