10-22-2019 06:32 AM
Hello All,
I made a wired configuration with windows AD with automatic VLAN assignment on a 2960 switch and router on a stick .
THere is one DC /DNS/CA server and another NPS/DHCP server.
Switch port authentication and authorization succeeds for the Host and the correct IP-address is obtained from DHCP server.
Als the switch port is assigned to the correct vlan.
The host knows the switch vlan interface (arp -a) and vice versa the switch knows the host (show arp).
Firewall on the windows host is turned off. Still I cannot ping the switch (Request timed out).
The authenticator interface on the switch is configured as host-mode multi-host. THe host is a real host (not a VM).
When i put the host in a manually configured acces port, everything is working fine...
Does anyone have an idea where to look?
Thanks, Olivier
10-22-2019 06:35 AM
10-22-2019 06:38 AM
10-22-2019 07:02 AM
10-22-2019 07:15 AM
10-22-2019 07:42 AM
10-22-2019 09:26 AM
I found two commands misssing, please check suggestion below;
sw(config)#: radius-server vsa send authentication
interface FastEthernet0/1
switchport mode access
switchport access-vlan 10
authentication event fail action authorize vlan 98
authentication event no-response action authorize vlan 100
authentication host-mode multi-host
authentication open
authentication port-control auto
authentication periodic
authentication timer reauthenticate 4800
mab
dot1x pae authenticator
dot1x timeout quiet-period 30
!
10-22-2019 09:40 AM
10-22-2019 10:18 AM
Ok, if possible, try it.
From
authentication host-mode multi-host
To
authentication host-mode single-host
10-22-2019 10:25 AM
10-22-2019 11:08 AM
10-22-2019 11:38 AM
10-22-2019 12:12 PM
10-23-2019 01:33 AM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: