<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP 802.1X switched port-authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259314#M17199</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer I've already tried without success!...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm asking myself if this is possible since EAP authentication is happening between the client and the AP...How could the AP authenticate to the switch since the switch port is waiting for EAP packets but the AP is sending RADIUS packet ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is not the case that multi-host is working ONLY if the EAP authentication is happening between client and the switch, bypassing EAP authentication on AP where it's role is to act as a "Relay"???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Omar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Feb 2004 14:46:11 GMT</pubDate>
    <dc:creator>oguarisco</dc:creator>
    <dc:date>2004-02-10T14:46:11Z</dc:date>
    <item>
      <title>AP 802.1X switched port-authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259312#M17197</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've setup EAP authentication (PEAP) to authenticate WLAN client on an AP. &lt;/P&gt;&lt;P&gt;The AP is connected to a switch where the port is not configured for 802.1X. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On this switched port I enabled, in multi-host, 802.1X to authenticate also the AP as a client, but since it's enabled I've not been able to authenticate anymore the WLAN client due to the fact that the port will not transition to Authorized&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I connect on the same port a PC using 802.1X,this is working fine..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something to configure on the switch or AP ???&lt;/P&gt;&lt;P&gt;Any suggestion are appreciated&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Omar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259312#M17197</guid>
      <dc:creator>oguarisco</dc:creator>
      <dc:date>2021-07-04T16:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: AP 802.1X switched port-authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259313#M17198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think U will need to add this line to that interface port which your AP is connected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; dot1x host-mode multi-host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2004 14:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259313#M17198</guid>
      <dc:creator>mcnaz-yeo</dc:creator>
      <dc:date>2004-02-10T14:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: AP 802.1X switched port-authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259314#M17199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer I've already tried without success!...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm asking myself if this is possible since EAP authentication is happening between the client and the AP...How could the AP authenticate to the switch since the switch port is waiting for EAP packets but the AP is sending RADIUS packet ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is not the case that multi-host is working ONLY if the EAP authentication is happening between client and the switch, bypassing EAP authentication on AP where it's role is to act as a "Relay"???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Omar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2004 14:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259314#M17199</guid>
      <dc:creator>oguarisco</dc:creator>
      <dc:date>2004-02-10T14:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: AP 802.1X switched port-authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259315#M17200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Omar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's a gotcha with this...most likely a trunk issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a snippet for EAPOL guidelines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication Configuration Guidelines&lt;/P&gt;&lt;P&gt;This section provides the guidelines for configuring 802.1x authentication on the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;802.1x will work with other protocols, but we recommend that you use RADIUS with a remotely located authentication server. &lt;/P&gt;&lt;P&gt;802.1x is supported only on Ethernet ports. &lt;/P&gt;&lt;P&gt;Software release 7.5(1) supports two in-band management interfaces, sc0 and sc1. &lt;/P&gt;&lt;P&gt;802.1x authentication always uses the sc0 interface as the identifier for the authenticator when communicating with the RADIUS server. &lt;/P&gt;&lt;P&gt;802.1x authentication is not supported with the sc1 interface. &lt;/P&gt;&lt;P&gt;You cannot enable 802.1x on a trunk port until you turn off the trunking feature on that port. &lt;/P&gt;&lt;P&gt;You cannot enable trunking on an 802.1x port. &lt;/P&gt;&lt;P&gt;You cannot enable 802.1x on a dynamic port until you turn off the DVLAN feature on that port. &lt;/P&gt;&lt;P&gt;You cannot enable DVLAN on an 802.1x port. &lt;/P&gt;&lt;P&gt;You cannot enable 802.1x on a channeling port until you turn off the channeling feature on that port. You cannot enable channeling on an 802.1x port. &lt;/P&gt;&lt;P&gt;You cannot enable 802.1x on a switched port analyzer (SPAN) destination port. You cannot configure SPAN destination on an 802.1x port. However, you can configure an 802.1x port as a SPAN source port. &lt;/P&gt;&lt;P&gt;You cannot set the auxiliary VLAN to dot1p or untagged and the auxiliary VLAN should not be equal to the native VLAN on the 802.1x-enabled port. &lt;/P&gt;&lt;P&gt;You cannot enable the multiple-authentication option on an 802.1x-enabled auxiliary VLAN port. Enabling the multiple-host option on an 802.1x-enabled auxiliary VLAN is not recommended. &lt;/P&gt;&lt;P&gt;Do not assign a guest VLAN equal to an auxiliary VLAN because an 802.1x-enabled auxiliary VLAN port will not be put into the guest VLAN if the auxiliary VLAN on the port is the same as the guest VLAN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the url for the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080121d12.html#1029697" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/hw/switches/ps708/products_configuration_guide_chapter09186a0080121d12.html#1029697&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Mar 2004 20:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259315#M17200</guid>
      <dc:creator>emcpherson</dc:creator>
      <dc:date>2004-03-24T20:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: AP 802.1X switched port-authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259316#M17201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the info...already checked...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I receive info from Cisco that this feature will be implemented during this year on IOS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically what I wanted to do is that the client use 802.1X EAP to authenticate to AP....and not to the switch seeing the bypassing oppurtunity (1 client authenticate for all!!!)...but this left open the port where the AP is connected to the switch...so it was nice that AP also authenticate itself to the switch using EAP...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now this feature is configrable only on WLAN where an AP act as a Repeater which can authenticate itself to the root AP using EAP (only LEAP!!!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Omar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2004 07:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-802-1x-switched-port-authentication/m-p/259316#M17201</guid>
      <dc:creator>oguarisco</dc:creator>
      <dc:date>2004-03-25T07:24:43Z</dc:date>
    </item>
  </channel>
</rss>

