Apologies Jason, The version I replied with below is for the Cisco 2960, which is showing the error below: 18w5d: %DOT1X_SWITCH-5-ERR_ADDING_ADDRESS: Unable to add address 0024.5442.8604 on Fa0/2
The 2950 is showing: > RADIUS: EAP-login: length of eap packet = 4 > 3d03h: RADIUS: Tunnel-MType, [00] 00 00 06 > 3d03h: RADIUS: tag='00', consider the attribute untagged. > 3d03h: RADIUS: TAS(0) created and enqueued. > 3d03h: RADIUS: Tunnel-Type, [00] 00 00 0D > 3d03h: RADIUS: Tunnel-GID, [00] 741 > 3d03h: RADIUS: unrecognized Microsoft VSA type 17 > 3d03h: RADIUS: unrecognized Microsoft VSA type 16 > 3d03h: RADIUS: TAS(0) takes precedence over tagged attributes, > tunnel_type=13 > 3d03h: RADIUS: free TAS(0) > 3d03h: RADIUS: no appropriate authorization type for user. And is version: IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(22)EA14, RELEASE SOFTWARE (fc1) -----Original Message----- From: Morris, Andi [mailto:[email protected]] Sent: 05 December 2013 15:45 To: '[email protected]' Subject: Re: [PacketFence-users] dot1x being denied on wired clients It is; Cisco IOS Software, C2960 Software (C2960-LANBASE-M), Version 12.2(35)SE5, RELEASE SOFTWARE (fc1) However, until 2 weeks ago it worked with no issues so I'd be very surprised if it's because of the switch not supporting 802.1x. Cheers, Andi -----Original Message----- From: Jason Frisvold [mailto:[email protected]] Sent: 05 December 2013 15:38 To: [email protected] Subject: Re: [PacketFence-users] dot1x being denied on wired clients Morris, Andi wrote: > To add, as I think they may well be of use, these are the lines above the > line I have mentioned in the switch debug: > > RADIUS: EAP-login: length of eap packet = 4 > 3d03h: RADIUS: Tunnel-MType, [00] 00 00 06 > 3d03h: RADIUS: tag='00', consider the attribute untagged. > 3d03h: RADIUS: TAS(0) created and enqueued. > 3d03h: RADIUS: Tunnel-Type, [00] 00 00 0D > 3d03h: RADIUS: Tunnel-GID, [00] 741 > 3d03h: RADIUS: unrecognized Microsoft VSA type 17 > 3d03h: RADIUS: unrecognized Microsoft VSA type 16 > 3d03h: RADIUS: TAS(0) takes precedence over tagged attributes, > tunnel_type=13 > 3d03h: RADIUS: free TAS(0) > 3d03h: RADIUS: no appropriate authorization type for user. What version of IOS is this? It appears that this version doesn't have the proper support. Per Cisco, it has to support NAC - L2 IEEE 802.1x ... -- --------------------------- Jason 'XenoPhage' Frisvold [email protected] --------------------------- "Any sufficiently advanced magic is indistinguishable from technology.\" - Niven's Inverse of Clarke's Third Law ------------------------------------------------------------------------------ Sponsored by Intel(R) XDK Develop, test and display web and hybrid apps with a single code base. Download it for free now! http://pubads.g.doubleclick.net/gampad/clk?id=111408631&iu=/4140/ostg.clktrk _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users ------------------------------------------------------------------------------ Sponsored by Intel(R) XDK Develop, test and display web and hybrid apps with a single code base. Download it for free now! http://pubads.g.doubleclick.net/gampad/clk?id=111408631&iu=/4140/ostg.clktrk _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users ------------------------------------------------------------------------------ Sponsored by Intel(R) XDK Develop, test and display web and hybrid apps with a single code base. Download it for free now! http://pubads.g.doubleclick.net/gampad/clk?id=111408631&iu=/4140/ostg.clktrk _______________________________________________ PacketFence-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/packetfence-users
