cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1557
Views
0
Helpful
3
Replies

Cisco CE500 with dot1x issue

Edgar Servin
Level 1
Level 1

Hi,

I have a Cisco Switch CE500 and I need to function reliably dot1X. I used the "Network Assistant" and It did not work, dropped all ports connected to PCs that have the certificate. I have a network of switches running Cisco 2950/2960 with dot1x working properly. I access to http "exec mode" of the CE500 and I do comparing the text configuration between the CE500 and 2960, I edited the settings so that CE500 are the same text of 2960 but did not work.

I have the profile for the switch in my RADIUS Server. In the CE500 I have the ip address of the RADIUS, key, AAA RADIUS, "aaa new-model"

If, I eliminate the switch profile for the RADIUS, It logs me the device don't have profile for AAA.

Attached example files

ce500.txt ---- don't work

2960.txt ------ it´s working well

Help me please!

3 Replies 3

Edgar Servin
Level 1
Level 1

Did Somebody already made it work?

in my case the tip from another tread helped me out. The tip was to set on the 2008 NPS in the Connection Policy the Rádius standart Attribut Framed MTU to less than 1400.

In my case that made the deal !

Reiner

Hi Reiner,

You set the "mtu" less than 1400 and the Switch CE500 works with Windows 2008 NPS.

Is that correct?

Do you set the MTU on the switch or the server?

Regards.

Edgar

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card