10-30-2022 06:12 AM
i am deploying a 3rd party nac solution with a cisco sg250 10port switch
on the gui interface of the cisco sg250 switch i see 802.1x configuration which was properly configured
however when a user connects to the interface of the switch for 802.1x, on the 3rd party nac solution i see radius authentication rejected for username\domain
please advise if the cisco sg250 switch is considerable for 802.1x or just has basic 802.1x functionality
thanks
Solved! Go to Solution.
10-30-2022 10:27 AM - edited 10-30-2022 10:29 AM
check the Emulator i do see the option :
https://www.cisco.com/assets/sol/sb/SG220_Emulators/SG220_Emulator_v1-0-0-18_20140626/home.html
check admin guide :
10-31-2022 06:36 AM - edited 10-31-2022 06:36 AM
>>> on the 3rd party nac solution i see radius authentication rejected for username\domain <<<
looks like the switch is talking properly to the 3rd party NAC device
but the radius request from this device to AD gets a "rejected" response
-> the NAC profile is not properly matchet or the user does not belong to the correct group to use NAC
-->> check your AD setitngs (not switch)
10-30-2022 06:27 AM
how is your user source configured on the NAC (is this from AD?)
other than just basic config on the switch side and switch added to your NAC, that should work as expected :
below for reference in case you missed any options - as per the message look like far end issue (I am in guess)
10-30-2022 06:35 AM
Thank you balaj
user source is from AD
We have done the configuration based on that article you share
However we are not completely sure if the cisco SG250 switch is compatible for an 802.1x
10-30-2022 06:44 AM
as per the switch concerns the switch capable of 802.1x, you need to check with NAC ( I am sure they do support I guess)
i see radius authentication rejected for username\domain - this means the request was processed and failed somewhere in the path.
10-30-2022 08:32 AM
Thank you
This article you posted is for SX 220 will the same configuration work for SG250?
Also while reading the article below it appears the SG250 might work for radius auth but definitely not for VLAN Assignment
10-30-2022 10:27 AM - edited 10-30-2022 10:29 AM
check the Emulator i do see the option :
https://www.cisco.com/assets/sol/sb/SG220_Emulators/SG220_Emulator_v1-0-0-18_20140626/home.html
check admin guide :
10-31-2022 06:36 AM - edited 10-31-2022 06:36 AM
>>> on the 3rd party nac solution i see radius authentication rejected for username\domain <<<
looks like the switch is talking properly to the 3rd party NAC device
but the radius request from this device to AD gets a "rejected" response
-> the NAC profile is not properly matchet or the user does not belong to the correct group to use NAC
-->> check your AD setitngs (not switch)
10-31-2022 07:07 AM
Thank you for you response
yes you are correct we had issues with the AD connection this is now resolved
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide