<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Authentication Cisco Switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416296#M88366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since radius server is sending access-reject so you need to check the NPS/IAS Event Viewer logs to find the reason of failure. My guess, PAP as an authetication method is not enabled under Remote access policy &amp;gt; properties &amp;gt;authentication. But you still need to check the event viewer logs to determine the exact reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Feb 2014 16:53:19 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2014-02-01T16:53:19Z</dc:date>
    <item>
      <title>Radius Authentication Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416295#M88361</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco 2960 switch and currently trying to setup radius authentication. My microsoft guy does the server side we have matching keys and he says there is no problem on his side, but we still canno get it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config on switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;radius-server host 10.0.0.13 auth-port 1812&lt;BR /&gt;radius-server key 0 test&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;login authentication default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch and radius server are on the same network. I have done a debug and confused on the output. Can anyone point me in the right direction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done a debug aaa authentication and debug radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AccessSwitch#&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00001586):Orig. component type = Exec&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; AAA Unsupported Attr: interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [221] 4&amp;nbsp;&amp;nbsp; 92269176&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00001586): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Config NAS IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Config NAS IPv6: ::&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00001586): acct_session_id: 20&lt;/P&gt;&lt;P&gt;RADIUS(00001586): sending&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE: Best Local IP-Address 10.0.0.56 for Radius-Server 10.0.0.13&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Sending a IPv4 Radius Packet&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Send Access-Request to 10.0.0.13:1812 id 1645/18,len 77&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; authenticator 7C B1 A0 55 62 45 7B AF - F2 E2 48 4C C3 F0 72 98&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 15&amp;nbsp; "james.hoggard"&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty2"&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.0.0.56&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Started 5 sec timeout&lt;/P&gt;&lt;P&gt;RADIUS: Received from id 1645/18 10.0.0.13:1812, Access-Reject, len 20&lt;/P&gt;&lt;P&gt;RADIUS:&amp;nbsp; authenticator 80 CE C9 C2 D6 30 65 A9 - 07 D8 12 4C 9E 80 A9 3C&lt;/P&gt;&lt;P&gt;RADIUS(00001586): Received from id 1645/18&lt;/P&gt;&lt;P&gt;AAA/AUTHEN/LOGIN (00001586): Pick method list 'default'&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00001586): ask "Password: "&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00001586): send packet; GET_PASSWORD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416295#M88361</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2019-03-11T04:20:50Z</dc:date>
    </item>
    <item>
      <title>Radius Authentication Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416296#M88366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since radius server is sending access-reject so you need to check the NPS/IAS Event Viewer logs to find the reason of failure. My guess, PAP as an authetication method is not enabled under Remote access policy &amp;gt; properties &amp;gt;authentication. But you still need to check the event viewer logs to determine the exact reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Feb 2014 16:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416296#M88366</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-02-01T16:53:19Z</dc:date>
    </item>
    <item>
      <title>Radius Authentication Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416297#M88369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAP is unencrypted isn't it? is there a way i can get the cisco device to use an encrypted method?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Feb 2014 19:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416297#M88369</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2014-02-01T19:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication Cisco Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416298#M88377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, PAP always use &lt;SPAN style="font-size: 10pt;"&gt;plain text and that doesn't provide any kind of security.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;However, administrative session with radius doesn't support chap/mschap.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;we can't configure &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;firewall/IOS devices for aministration session like telnet/ssh to authenticate users on mschapv2 authentication method.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need secure communication then you may implement TACACS.&lt;/P&gt;&lt;P&gt; TACACS+ and RADIUS use a shared secret key to provide encryption &lt;SPAN style="font-size: 10pt;"&gt;for communication between the client and the server. RADIUS encrypts the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;user's password when the client made a request to the server. This &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;encryption prevents someone from sniffing the user's password using a &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;packet analyzer. However other information such as username and services &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;that is being performed can be analyzed. TACACS+ encrypts not just only &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;the entire payload when communicating, but it also encrypts the user's &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;password between the client and the server. This makes it more difficult &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;to decipher information about the communication between the client and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;the server. TACACS+ uses MD5 hash function in its encryption and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;decryption algorithm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Feb 2014 20:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-cisco-switch/m-p/2416298#M88377</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-02-01T20:05:45Z</dc:date>
    </item>
  </channel>
</rss>

