07-14-2010 01:10 PM - edited 03-10-2019 05:15 PM
Trying to set up 802.1x dynamic VLAN switching, and have a question. I think I've gotten it working except for one part. The VLAN on a protected interface is never getting switched. I can see an entry in the ACS stating that it applied the appropriate VLAN via RADIUS response, but it never changes on the switch.
Environment:
ACS Express 5.0.1
C3550 running c3550-ipbasek9-mz.122-44.SE6.bin
Switch config:
aaa new-model
aaa group server radius dot1x
server-private 10.10.1.4 auth-port 1645 acct-port 1646 key 7 071C244F5C0C0D544541
07-15-2010 10:24 AM
The output of "debug radius" should help, can you capture it and post it?
07-15-2010 10:49 AM
It looks like "aaa authorization network default group dot1x" was the missing command I needed to get this working.
The only issue I'm having now is that if the client fails to meet the authentication requirements, the line status gets set as "down"
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: