Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

802.1x works on 2950 but not 3560 ?

Hi all,

I have a issue where 802.1x is configured on a 2950 switch.

The same config is applied to a 3560 (with new IOS). Both switches are created in ACS 4.x and the 2950 authenticates correctly and changes the port in with the PC is authenticated in the right VLAN. When I try to put this PC into a 802.1x enabled port on the 3560, it gets authenticated/passing postures etc. but the VLAN on the switch doesnt change? on the ACS everything looks ok....but the VLAN doesnt change on the 3560.

Both switches are in the same VTP and can distribute VLANS among them.

Any ideas?


  • AAA Identity and NAC
Cisco Employee

Re: 802.1x works on 2950 but not 3560 ?

This should work.

Do you have the following configured on the 3560?

aaa authorization network default group radius

What is the value for RADIUS attribute[81] you're sending back from ACS in both/either case?

New Member

Re: 802.1x works on 2950 but not 3560 ?

Yes, I have the aaa auth network default group radius in both switches.

What I do not have tho, is

"aaa accounting dot1x default start-stop group radius"...that command it will not accept. But it should work without that I reckon ?

My [81] value is 1 - default vlan.

The Nac/802.1x ports are configged as follows :

switchport access vlan 20

switchport mode access

dot1x port-control auto

dot1x guest-vlan 20

dot1x reauthentication

spanning-tree portfast


I've just tried with another 2950 switch, and that actually have the same I wonder if its something on the acs Im missing....?

Edited :

I debuged the dot1x on both the working switch, and the malfuntioning one : Heres a interesting part of it :

from the working switch

6d00h: dot1x-ev: GuestVlan configured=0

6d00h: dot1x-registry:** dot1x_vp_statechange:

6d00h: dot1x-ev:vlan 1 vp is added on the interface FastEthernet0/10

6d00h: dot1x-registry:dot1x_port_modechange invoked on interface FastEthernet0/10

6d00h: dot1x-ev:dot1x_port_authorized: clearing HA table from vlan 1

from the malfuntioning switch

1w2d: dot1x-ev: GuestVlan configured=0

1w2d: dot1x-registry:** dot1x_vp_statechange:

1w2d: dot1x-ev:vlan 20 vp is added on the interface FastEthernet0/23

1w2d: dot1x-registry:dot1x_port_modechange invoked on interface FastEthernet0/23

1w2d: dot1x-ev:dot1x_port_authorized: clearing HA table from vlan 1

Even though they are the same in the config, and the same profile in ACS.

They should most definately recieve the same VLAN.

Kind regards


Cisco Employee

Re: 802.1x works on 2950 but not 3560 ?

It should work w/o "aaa acounting .." This is for RADIUS accounting, but this should also work depending on your code rev.

If I could ask a dumb question .. why are you bothering to do VLAN assignment, if the port above is already in VLAN1, and you're trying to re-assign it over RADIUS to the same thing?

Just for giggles, try setting it to something other than 1. You may have hit a bug for the scenario.

New Member

Re: 802.1x works on 2950 but not 3560 ?

The port is not in vlan 1...they start in VLAN 20, and on authentication and valid posture, should be assigned to VLAN 1


This widget could not be displayed.