cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1277
Views
5
Helpful
1
Replies

Dynamic Vlan Assigment on 2950 with acs 4.2

access-cc0
Level 1
Level 1

Hello to everyone

We have a problem with Cisco 2950G 48 EI and ACS (version 4.2) providing dynamic Vlan assignment based on groups

On the ACS we configured the following attributes for the specific group

64 = VLAN

65 = 802

81 = VLAN Name

We tried for the 81 attribute both Vlan name and Vlan ID but we get the same results

In detail, we need the machine to be placed on Vlan ID 6 named vlan_sio so we inserted these value in the attribute field

Before we configured the switch to speak with ACS:

aaa new-model

aaa group server radius Switch

                               server 172.16.0.93 auth-port 1812 acct-port 1813

dot1x system-auth-control

                radius-server host 172.16.0.93 auth-port 1812 acct-port 1813 key xxxxxx

radius-server retransmit 3

Configured the ports for the use of dot1.x.

switchport mode access

               dot1x port-control auto

               dot1x guest-vlan 7

               spanning-tree portfast

The users are correctly authenticated but the ports are always connected to the default Vlan of the ports

We tried to debug with the debug dot1.x events command and we get the following errors:

Feb 16 12:00:04.017:         Attribute 64 6 0100000D

Feb 16 12:00:04.017:         Attribute 65 6 01000006

Feb 16 12:00:04.017:         Attribute 81 4 01360806

Feb 16 12:00:04.025: dot1x-ev:Received VLAN is No Vlan

Feb 16 12:00:04.037: dot1x-ev:Received VLAN Id -1

Feb 16 12:00:04.041: dot1x-ev:dot1x_port_authorized: clearing HA table from vlan 1

Feb 16 12:00:04.049: dot1x-ev:dot1x_port_authorized: Added 0006.1bdb.6a09 to HA table on vlan 1

Does anyone know what we could have missed?

Thank’s

1 Reply 1

access-cc0
Level 1
Level 1

solved

It was just missing the command

aaa authorization network default group XXXX

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: