Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

Dynamic Vlan Assigment on 2950 with acs 4.2

Hello to everyone

We have a problem with Cisco 2950G 48 EI and ACS (version 4.2) providing dynamic Vlan assignment based on groups

On the ACS we configured the following attributes for the specific group

64 = VLAN

65 = 802

81 = VLAN Name

We tried for the 81 attribute both Vlan name and Vlan ID but we get the same results

In detail, we need the machine to be placed on Vlan ID 6 named vlan_sio so we inserted these value in the attribute field

Before we configured the switch to speak with ACS:

aaa new-model

aaa group server radius Switch

                               server auth-port 1812 acct-port 1813

dot1x system-auth-control

                radius-server host auth-port 1812 acct-port 1813 key xxxxxx

radius-server retransmit 3

Configured the ports for the use of dot1.x.

switchport mode access

               dot1x port-control auto

               dot1x guest-vlan 7

               spanning-tree portfast

The users are correctly authenticated but the ports are always connected to the default Vlan of the ports

We tried to debug with the debug dot1.x events command and we get the following errors:

Feb 16 12:00:04.017:         Attribute 64 6 0100000D

Feb 16 12:00:04.017:         Attribute 65 6 01000006

Feb 16 12:00:04.017:         Attribute 81 4 01360806

Feb 16 12:00:04.025: dot1x-ev:Received VLAN is No Vlan

Feb 16 12:00:04.037: dot1x-ev:Received VLAN Id -1

Feb 16 12:00:04.041: dot1x-ev:dot1x_port_authorized: clearing HA table from vlan 1

Feb 16 12:00:04.049: dot1x-ev:dot1x_port_authorized: Added 0006.1bdb.6a09 to HA table on vlan 1

Does anyone know what we could have missed?


Community Member

Re: Dynamic Vlan Assigment on 2950 with acs 4.2


It was just missing the command

aaa authorization network default group XXXX

CreatePlease to create content