Good day.
I have several Cisco Switchs with IOS 12.2, 15.0 and 15.2. My ACS is Microsoft Windows Server 2008 (NPS).
The configuration basically is the same in all models, but in switches with IOS 15.2 the RADIUS authentication doesn't work.
And apparently the command "radius-server host x.x.x.x" was deprecated.
The config is:
***IOS 12.2 / 15.0***
aaa new-model
aaa authentication dot1x default group radius
aaa session-id common
dot1x system-auth-control
!
interface GigabitEthernet0/XX
switchport access vlan 10
switchport mode access
authentication port-control auto
dot1x pae authenticator
spanning-tree portfast edge
!
radius-server dead-criteria time 5 tries 3
radius-server deadtime 5
!
radius server RAD1
address ipv4 192.168.0.X auth-port 1812 acct-port 1813
automate-tester username dummy
key XXXXXXX
!
radius server RAD2
address ipv4 192.168.0.Y auth-port 1812 acct-port 1813
automate-tester username dummy
key XXXXXXX
***IOS 15.2***
aaa new-model
aaa authentication dot1x default group radius
aaa session-id common
dot1x system-auth-control
!
interface GigabitEthernet0/XX
switchport access vlan 10
switchport mode access
authentication port-control auto
dot1x pae authenticator
spanning-tree portfast edge
!
radius-server dead-criteria time 5 tries 3
radius-server deadtime 5
!
radius server RAD1
address ipv4 192.168.0.X auth-port 1812 acct-port 1813
automate-tester username dummy
key XXXXXXX
!
radius server RAD2
address ipv4 192.168.0.Y auth-port 1812 acct-port 1813
automate-tester username dummy
key XXXXXXX
!
In the ACS's log I have:
***IOS 12.2 / 15.0*** (Connection OK)
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,,,0,"311 1 192.168.0.X 11/30/2017 19:14:22 10273",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,,,0,"311 1 192.168.0.X 11/30/2017 19:14:22 10273",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,,,0,"311 1 192.168.0.X 11/30/2017 19:14:22 10274",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,,,0,"311 1 192.168.0.X 11/30/2017 19:14:22 10274",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"DOMAIN\COMPUTER1","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10275",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"0x01454449464943494F53",,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10275",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"DOMAIN\COMPUTER1","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10276",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10276",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"DOMAIN\COMPUTER1","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10277",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10277",60,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10278",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10278",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10279",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10279",60,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10280",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,5,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10280",60,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10281",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"0x01454449464943494F53",,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:51,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,,,,,,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10281",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:52,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","20-F5-EC-83-8E-21","54-E5-D7-4B-09-9F",,,,"192.168.1.X",50133,0,"192.168.1.X","SW ADMIN",,,15,,,2,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10282",,,,"Microsoft: Secured password (EAP-MSCHAP v2)",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/04/2017,13:11:52,2,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.1.X","SW ADMIN",,1,,,1,2,11,"NAP (Ethernet) Domain",0,"311 1 192.168.0.X 11/30/2017 19:14:22 10282",,,,"Microsoft: Secured password (EAP-MSCHAP v2)",,,,,,,,,,,,,,,6,,,,,,,,,,,,"0x01454449464943494F53",,,"802.1X (Ethernet)",1,,,,
***IOS 15.2*** (Not Authorized)
"RADIUS1","IAS",12/05/2017,16:51:19,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","A8-7B-29-FF-CF-89","9C-A7-0E-66-26-59",,,,"192.168.0.X",50109,0,"192.168.0.X","SW CONT",,,15,,,2,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 662",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:19,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.0.X","SW CONT",,,,,,,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 662",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:19,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","A8-7B-29-FF-CF-89","9C-A7-0E-66-26-59",,,,"192.168.0.X",50109,0,"192.168.0.X","SW CONT",,,15,,,2,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 663",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:19,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.0.X","SW CONT",,,,,,,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 663",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:37,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","A8-7B-29-FF-CF-89","9C-A7-0E-66-26-59",,,,"192.168.0.X",50109,0,"192.168.0.X","SW CONT",,,15,,,2,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 664",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:37,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.0.X","SW CONT",,,,,,,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 664",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:37,1,"host/COMPUTER1.DOMAIN","DOMAIN\COMPUTER1","A8-7B-29-FF-CF-89","9C-A7-0E-66-26-59",,,,"192.168.0.X",50109,0,"192.168.0.X","SW CONT",,,15,,,2,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 665",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
"RADIUS1","IAS",12/05/2017,16:51:37,11,,"DOMAIN\COMPUTER1",,,,,,,,0,"192.168.0.X","SW CONT",,,,,,,,,0,"311 1 192.168.10.X 12/05/2017 17:55:31 665",30,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"802.1X (Ethernet)",1,,,,
Anybody have an idea for me? Any suggestion or modification for my config?
Thank you and sorry for my bad english :)