Re: [OSL | CCIE_Security] IPV6 First Hop Security

2013-11-15 Thread Piotr Kaluzny
Mark Go ahead and use this document : http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/15.0_2_se/configuration/guide/swipv6.html#wp1130142 Regards, Piotr Kaluzny : Sr Instructor : iPexpert http://www.ipexpert.com CCIE # 25665 :: Security *:: World-Class Cisco

[OSL | CCIE_Security] Freaking stuck on AP (itself )dot1x authentication with Radius server, please help

2013-11-15 Thread jeremy co
All, im trying to authenticate AP with dot1x (NOT MAB) to ISE. my understanding is wlc push 802.1x auth user/pass to AP, then AP tries to respond to switche;s EAP. switch use open authentication so pass user/pass to ISE. I think in my case switch nver received user/pass from AP to pass it on to

Re: [OSL | CCIE_Security] Freaking stuck on AP (itself )dot1x authentication with Radius server, please help

2013-11-15 Thread Kevin Sheahan
If you've been at this for a while, ISE is likely auto-blocking the AP's 802.1x authentication attempts. Go to Administration -- System -- Settings -- Protocols -- Radius -- Uncheck Reject Requests After Detection box. This is a default setting that can hurt during implementations and/or