cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6406
Views
35
Helpful
19
Replies

Dynamic Vlan assignment in wired network - NPS 2012 server

ITexpert
Level 3
Level 3

Hello Guys,

 

I am in my lab environment,  I have Cisco 800 series router and L2 cisco 2960G switch. I configure Intervlan Routing through switch and Microsoft 2012 server as a DHCP,DNS, AD and NPS server.

 

Everything is working great except Dynamic vlan assignment.I followed this link to implement it.

 

https://mikepembo.wordpress.com/2016/11/07/dynamic-vlan-assignment-cisco-and-nps/comment-page-1/

 

I have a questions :

1.  where aaa commands should be configure , On a Router or Switch ?

I configure everything on switch but its not working.

 

Thanks

 

 

19 Replies 19

This is exactly what is happening,

 

I boot the domain joined machine, I login with username and NPS audit success and PC got right vlan when i signout right away NPS server shows Auth failed and switch moved it to 40 guest vlan. After this even after signin with same username switch never send any packets to NPS server.

 

Is there any command that can enable switch to send reauthenticate everytime when we signin.

 

 

 

Hello Deepak,

 

After removing this command,  authentication event fail authorize vlan 40 (guest vlan)

 

Its working perfect.

 

Only thing is now when i login with local credentials or user name that is not in NPS server policy , port goes down.

 

is there any other way ?

 

Thanks

Users who fail authentication remain in the auth fail VLAN until the next reauthentication attempt. A port in the auth fail VLAN tries to reauthenticate at configured intervals (the default is 60 seconds). If reauthentication fails, the port remains in the auth fail VLAN. If reauthentication is successful, the port moves either to the configured VLAN or to a VLAN sent by the RADIUS server. You can disable reauthentication. If you do this, the only way to restart the authentication process is for the port to receive a link down or EAP logoff event. It is recommended that you keep reauthentication enabled if a client might connect through a hub. When a client disconnects from the hub, the port might not receive the link down or EAP logoff event.

Remove this command

dot1x max-req 1 ! quit trying to re-authenticate after 1 try

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

Hello Deepak,

 

Its working now, I just move that port from multi-host mode to single host mode.

Review Cisco Networking for a $25 gift card