<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need some help with dot1x please in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437721#M88084</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please have a look on a very good docs for 802.1x authentication, configuration and verification commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116506-configure-acs-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116506-configure-acs-00.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Feb 2014 07:52:38 GMT</pubDate>
    <dc:creator>Naveen Kumar</dc:creator>
    <dc:date>2014-02-14T07:52:38Z</dc:date>
    <item>
      <title>Need some help with dot1x please</title>
      <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437718#M88078</link>
      <description>&lt;P&gt;Cisco 2950, ACS 5.3&lt;/P&gt;&lt;P&gt;ACS tested, I created a local account on the ACS and enabled authentication on the 2950. All working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x - not working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Switch#sh run | i dot1x&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authentication dot1x default group tacacs+&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa authorization network default group tacacs+&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;tacacs-server host 172.16.1.175&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;dot1x system-auth-control&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Switch#sh run int f0/2&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Building configuration...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Current configuration : 107 b&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface FastEthernet0/2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport mode access&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; dot1x port-control auto&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Switch#sh dot1x int f0/2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Supplicant MAC &amp;lt;Not Applicable&amp;gt;&lt;/P&gt;&lt;P&gt;AuthSM State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = CONNECTING&lt;/P&gt;&lt;P&gt;BendSM State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = IDLE&lt;/P&gt;&lt;P&gt;Posture&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = N/A&lt;/P&gt;&lt;P&gt;PortStatus&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = UNAUTHORIZED&lt;/P&gt;&lt;P&gt;MaxReq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 2&lt;/P&gt;&lt;P&gt;MaxAuthReq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 2&lt;/P&gt;&lt;P&gt;HostMode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = Single&lt;/P&gt;&lt;P&gt;Port Control&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = Auto&lt;/P&gt;&lt;P&gt;ControlDirection&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = Both&lt;/P&gt;&lt;P&gt;QuietPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 60 Seconds&lt;/P&gt;&lt;P&gt;Re-authentication&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = Disabled&lt;/P&gt;&lt;P&gt;ReAuthPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 3600 Seconds&lt;/P&gt;&lt;P&gt;ServerTimeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 30 Seconds&lt;/P&gt;&lt;P&gt;SuppTimeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 30 Seconds&lt;/P&gt;&lt;P&gt;TxPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 30 Seconds&lt;/P&gt;&lt;P&gt;Guest-Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 0&lt;/P&gt;&lt;P&gt;AuthFail-Vlan&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 0&lt;/P&gt;&lt;P&gt;AuthFail-Max-Attempts = 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And it stays like that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;01:59:21: dot1x-ev:Received QUEUE EVENT in response to AAA Request&lt;/P&gt;&lt;P&gt;01:59:21: dot1x-ev:Dot1x matching request-response id 4294967283 found&lt;/P&gt;&lt;P&gt;01:59:21: dot1x-ev:Length of recv eap packet from radius = 4&lt;/P&gt;&lt;P&gt;01:59:21: dot1x-ev:Received VLAN Id -1&lt;/P&gt;&lt;P&gt;01:59:22: %LINK-3-UPDOWN: Interface FastEthernet0/2, changed state to up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FastEthernet0/2&lt;/P&gt;&lt;P&gt;02:00:38: dot1x-ev:dot1x_post_message_to_auth_sm: removing supplicant 0015.60c3&lt;/P&gt;&lt;P&gt;8613 SM&lt;/P&gt;&lt;P&gt;02:00:38: dot1x-ev:destroy supplicant block for 0015.60c3.8613&lt;/P&gt;&lt;P&gt;02:00:38: dot1x-ev:Enter function dot1x_aaa_acct_end&lt;/P&gt;&lt;P&gt;02:00:38: dot1x-ev:Couldn't find a supplicant block for mac 0015.60c3.8613&lt;/P&gt;&lt;P&gt;02:00:38: dot1x-ev:Couldn't find a supplicant block for mac 0015.60c3.8613&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect my Windows7 client to ask me for a username/pass (dot1x enabled on my NIC card)&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437718#M88078</guid>
      <dc:creator>Mariusz00001</dc:creator>
      <dc:date>2019-03-11T04:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help with dot1x please</title>
      <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437719#M88081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On ACS I can see&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;13011 Invalid TACACS+ request packet - possibly mismatched Shared Secrets&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is not true as I can telnet to this switch using a Tacacs account&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also added a username/pass to my NIC settings. Windows says: 'authentication failed'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Feb 2014 15:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437719#M88081</guid>
      <dc:creator>Mariusz00001</dc:creator>
      <dc:date>2014-02-12T15:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help with dot1x please</title>
      <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437720#M88083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to configure RADIUS for dot1x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;radius-server timeout 3&lt;/P&gt;&lt;P&gt;radius-server key blabla&lt;BR /&gt;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 09:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437720#M88083</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-02-13T09:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help with dot1x please</title>
      <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437721#M88084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please have a look on a very good docs for 802.1x authentication, configuration and verification commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116506-configure-acs-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116506-configure-acs-00.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 07:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437721#M88084</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2014-02-14T07:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need some help with dot1x please</title>
      <link>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437722#M88085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please go through the link&amp;nbsp; below may help you to get verified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_010000.html"&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_010000.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 11:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-some-help-with-dot1x-please/m-p/2437722#M88085</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2014-02-20T11:14:11Z</dc:date>
    </item>
  </channel>
</rss>

