<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Define RADIUS Server per Switchport in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388231#M88428</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I correct here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You want (for example) RADIUS server at 10.1.1.1 to handle switch ports GigabitEthernet 1-24 and RADIUS server 10.2.2.2 handle GigabitEthernet 25-48.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that's the case, then define multiple authentication methods, and assign those methods to each port as appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius RAD1&lt;/P&gt;&lt;P&gt; server 10.1.1.1&lt;/P&gt;&lt;P&gt;aaa group server radius RAD2&lt;/P&gt;&lt;P&gt; server 10.2.2.2&lt;/P&gt;&lt;P&gt;aaa authenticaiton dot1x RAD1 group RADSER1&lt;/P&gt;&lt;P&gt;aaa authentication dot1x RAD2 group RADSER2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now assign RAD1 to interfaces GigE 1-24 and RAD2 to interfaces GigE 25-48&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2014 23:40:11 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2014-01-29T23:40:11Z</dc:date>
    <item>
      <title>Define RADIUS Server per Switchport</title>
      <link>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388230#M88427</link>
      <description>&lt;P&gt;Afternoon all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been experimenting with dot1x on switchports, we have two seperate systems handling AAA at the moment and one of them is tied into the firewall/webfilter (school environment).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to use the RADIUS server on that appliance to handle AAA for certain switchports in locations with personal devices attached, and then our internal Windows NPS to handle AAA for school devices in locations where personal devices will not be attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this thread: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2080794" target="_blank"&gt;https://supportforums.cisco.com/thread/2080794&lt;/A&gt;&lt;SPAN&gt; from 2011 stating that it would not be possible (in the same kind of scenario) is this still the case in IOS 15? Can't find options to do it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies if this is a stupid question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388230#M88427</guid>
      <dc:creator>shillier.tha</dc:creator>
      <dc:date>2019-03-11T04:20:03Z</dc:date>
    </item>
    <item>
      <title>Define RADIUS Server per Switchport</title>
      <link>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388231#M88428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I correct here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You want (for example) RADIUS server at 10.1.1.1 to handle switch ports GigabitEthernet 1-24 and RADIUS server 10.2.2.2 handle GigabitEthernet 25-48.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that's the case, then define multiple authentication methods, and assign those methods to each port as appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius RAD1&lt;/P&gt;&lt;P&gt; server 10.1.1.1&lt;/P&gt;&lt;P&gt;aaa group server radius RAD2&lt;/P&gt;&lt;P&gt; server 10.2.2.2&lt;/P&gt;&lt;P&gt;aaa authenticaiton dot1x RAD1 group RADSER1&lt;/P&gt;&lt;P&gt;aaa authentication dot1x RAD2 group RADSER2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now assign RAD1 to interfaces GigE 1-24 and RAD2 to interfaces GigE 25-48&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 23:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388231#M88428</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2014-01-29T23:40:11Z</dc:date>
    </item>
    <item>
      <title>Define RADIUS Server per Switchport</title>
      <link>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388232#M88429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Javier&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is exactly it, thank you! I have come co close - I have the groups, servers and aaa config ready but do not know how to assign RAD1 to &lt;SPAN style="font-size: 10pt;"&gt;GigE 1-24 and RAD2 to interfaces GigE 25-48.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;How do you achieve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Many thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Steve&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jan 2014 06:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/define-radius-server-per-switchport/m-p/2388232#M88429</guid>
      <dc:creator>shillier.tha</dc:creator>
      <dc:date>2014-01-30T06:28:02Z</dc:date>
    </item>
  </channel>
</rss>

