Dot1x authentification failed (Cisco IOL L3 - Cisco ISE (RADIUS))
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 03:28 AM
So basically I have this problem I have setted policies for Dot1x and MAB on both Cisco IOL L3 (version 15) and Cisco ISE (RADIUS Server) but client do authentificate only with the default method which is MAB (I did set an order for methods on Switch, see full Switch IOL Configuration in images below).
Can anyone guide me!
Troubleshoot Dot1x and Radius in IOS and IOS-XE
authentification host-mode multi-auth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 03:40 AM
If you run
Debug dot1x
Debug radius
And you dont get anything
Then it issue of CML not issue of config
To be honest I never see one success use dot1x in CML eve-ng or gns3
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 04:02 AM
Debug radius command is giving me the below output!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 04:19 AM
This meaning that radius debug is ON
When you try access via endpoint do you see any debug ?
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 05:29 AM - edited 05-11-2024 05:29 AM
now switch is showing me the below outputs :
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 10:55 AM
That good ghe dot1x magically work.
What issue you see'
Do
Show authentication interface session
Check the status of endpoint authc and authz
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 11:09 AM
yeah everything working fine now
but I'm running into another DHCP problem, server could not reach its Gateway and could not give IPs to hosts!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2024 11:22 AM
Can I see
Show authentication session of this interface
MHM
