cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1666
Views
0
Helpful
0
Replies

AAA Authentication problem

mlada16548
Level 1
Level 1

Hello,

 

Today i was configuring 802.1X in Cisco 3650 with ios version 3.7.05E, before i configure 802.1X in this same model but in ios version 16.9. When i copy all configuration  my device was no authenticatech when i using "show access-session" i see: 

 

Interface   MAC Address      Method      Domain           Status              Fg Session ID
Gi1/0/36   ####.####.####   N/A       UNKNOWN        Unauth C0A823050000004A2DF3CABE

 

in debug aaa authentication i have:

AAA/AUTHEN/8021X (00000000): Pick method list 'default'
AAA/AUTHEN(00000000): There is no General DBReply Method Index details may not be specified

 

my interface configuration:

interface GigabitEthernet1/0/36
switchport mode access
switchport port-security
authentication periodic
authentication timer reauthenticate server
access-session port-control auto
mab
dot1x pae authenticator
spanning-tree portfast
service-policy type control subscriber 802.1X

 

policy configuration:

event session-started match-all
10 class always do-until-failure
10 authenticate using dot1x priority 10
event agent-found match-all
10 class always do-until-failure
30 authenticate using dot1x priority 10
event authentication-failure match-first
10 class always do-until-failure
event authentication-success match-all
10 class always do-until-failure
10 activate service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE

 

and aaa configuration:

aaa new-model
aaa group server radius SRV-ADS-RAD
aaa authentication login default group SRV-ADS-RAD local
aaa authentication enable default group radius
aaa authentication dot1x default group radius group SRV-ADS-RAD
aaa authorization exec default group radius if-authenticated
aaa authorization network default group radius if-authenticated
aaa accounting identity default start-stop group radius
aaa accounting system default start-stop group radius
aaa session-id common

 

Thanks for Help.

 

0 Replies 0
Review Cisco Networking for a $25 gift card