<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with DOT1X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149270#M1073798</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have two cisco C3650, in one of them i was configure sucessful 802.1x but in second i want use IBNS 2.0, im create tempalte for dot1x but when i configure port and restart then i have always this same information about cred fail. I'm using windows NPS, AD and CA, if i connect one host to first switch his authenticate sucesfull but in second when i use "show access-session" i see: Method Dot1x, Domain Unknown, Status UnAuth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for help.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Sep 2020 16:42:52 GMT</pubDate>
    <dc:creator>mlada16548</dc:creator>
    <dc:date>2020-09-10T16:42:52Z</dc:date>
    <item>
      <title>Problem with DOT1X</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149270#M1073798</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have two cisco C3650, in one of them i was configure sucessful 802.1x but in second i want use IBNS 2.0, im create tempalte for dot1x but when i configure port and restart then i have always this same information about cred fail. I'm using windows NPS, AD and CA, if i connect one host to first switch his authenticate sucesfull but in second when i use "show access-session" i see: Method Dot1x, Domain Unknown, Status UnAuth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for help.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 16:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149270#M1073798</guid>
      <dc:creator>mlada16548</dc:creator>
      <dc:date>2020-09-10T16:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with DOT1X</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149518#M1073815</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please share the configuration you did on the second switch?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 03:34:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149518#M1073815</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-09-11T03:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with DOT1X</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149545#M1073818</link>
      <description>&lt;P&gt;interface GigabitEthernet1/0/11&lt;BR /&gt;description ######&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport port-security violation restrict&lt;BR /&gt;switchport port-security mac-address sticky&lt;BR /&gt;switchport port-security mac-address sticky ####.####.####&lt;BR /&gt;switchport port-security&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;service-policy type control subscriber TEST&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map type control subscriber TEST&lt;/P&gt;&lt;P&gt;event session-started match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 authenticate using dot1x priority 10&lt;BR /&gt;event agent-found match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;30 authenticate using dot1x priority 10&lt;BR /&gt;event authentication-failure match-first&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius server radius&lt;BR /&gt;address ipv4 192.168.40.45 auth-port 1645 acct-port 1646 key ######&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;BR /&gt;dot1x auth-fail eapol&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;BR /&gt;aaa authentication enable default group radius&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization exec default group radius if-authenticated&lt;BR /&gt;aaa authorization network default group radius if-authenticated&lt;BR /&gt;aaa accounting identity default start-stop group radius&lt;BR /&gt;aaa accounting system default start-stop group radius&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 06:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149545#M1073818</guid>
      <dc:creator>mlada16548</dc:creator>
      <dc:date>2020-09-11T06:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with DOT1X</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149549#M1073819</link>
      <description>&lt;P&gt;in logg i have only one messange:&lt;/P&gt;&lt;P&gt;%DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (xxxx.xxxx.xxxx) with reason (Cred Fail) on Interface Gi1/0/11 AuditSessionID C0A8230E00013533E1B44AC2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 06:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149549#M1073819</guid>
      <dc:creator>mlada16548</dc:creator>
      <dc:date>2020-09-11T06:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with DOT1X</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149584#M1073822</link>
      <description>&lt;P&gt;Ok i now what i have a problem, in secon switch im using wrong radius server name in configuration. Sorry for waisting your time.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 08:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-dot1x/m-p/4149584#M1073822</guid>
      <dc:creator>mlada16548</dc:creator>
      <dc:date>2020-09-11T08:21:07Z</dc:date>
    </item>
  </channel>
</rss>

