cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1545
Views
6
Helpful
24
Replies

Configure Radius on Cisco 9300 to Allow Hosts to Access the Internet

candidolevy
Level 1
Level 1

I upgraded cisco switch 2960x to 9300 and copied all configurations from 2960x to 9300 and I didn't have any syntax errors, however the hosts cannot be authenticated by ISE when they try to access the Internet. On the intranet everything is fine.

I ask for your support in resolving this problem.

I want the hosts to access the internet

 

Best regards

1 Accepted Solution

Accepted Solutions

@candidolevy can you see any log entries on ISE Live Logs?

Please provide your switch configuration and the ouput of the following commands:-

show authentication session
show dot1x
show dot1x statistics
show aaa server

 

 

View solution in original post

24 Replies 24

@candidolevy can you see any log entries on ISE Live Logs?

Please provide your switch configuration and the ouput of the following commands:-

show authentication session
show dot1x
show dot1x statistics
show aaa server

 

 

Does ISE use dynamic vlan?

Hello,

ISE is not using a dynamic vlan

candidolevy
Level 1
Level 1

candidolevy_5-1683716281358.png

 

 

 

candidolevy_1-1683715724545.png

candidolevy_2-1683715788065.pngcandidolevy_3-1683715942216.png

candidolevy_6-1683716350012.png

 

candidolevy_4-1683716117657.png

 

 

please share the interface config 
and the show ACL you apply to interface

Hello,

candidolevy_0-1683717592423.pngcandidolevy_1-1683718036042.png

 

voice + data vlan 

But you use multi-auth

You need to config multi-domian 

Ok Sir.

candidolevy_0-1683720013149.png

 

Let me see the result

Hello @MHM Cisco World,

I still don't have internet access

Shut no shut the interface' to re-authz the host 

waiting your reply 
thanks 

Hello Mr. @MHM Cisco World 

I was at a meeting scheduled at the last minute.

Pardon me.

But even after restarting the interface, I still have no internet access

show ip access-list interface X <<- 

I need to see the acl after success Authz 

candidolevy_0-1683729250610.png