cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
411
Views
0
Helpful
2
Replies

Takes long time to logon because of authentication

chicagotech
Level 1
Level 1

I have configure Cisco ACS v4.1 to control network accessing. When a domain user logon, it takes a few seconds to logon and map the network drive if it is conencting to a port without configued autnetication. However, it takes around 30 seconds to 1 minute to get the authentication successfully if it is connecting to the configured authentication port. The problem is the computer can't talk to the DHCP and DC before the authentication. The network status shows Limits or not connectivity. The ipconfig shows it uses auto ip address 169.254.x.x. To obtain an IP or talk to the DC, the user needs to enter ipconfig /renew or re-logon.

I have installed wireshark on one of our XP. the capture result can be found this link: http://chicagotech.net/images/acssniffing.gif.

What I did is running wireshark after logon without network and plug the cable. Based on the sniffing, when the computer connects to the authentication port, it starts to talk to the DHCP but can't get an IP until 25 seconds.

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

You are going to need to use machine authentication ie. when the machine boots up it authenticates itself to the network and gets an IP address before the user even tries to log in.

Attached is a link to a doc to get you started but if you do a search on Cisco site with 802.1x machine authentication this should give you quite a bit of info.

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml

Jon

Thnak you for the help. I will post back.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: