<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Switches, Hubs, and Modems中的主题 Re: Port-access mac-based Problem</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309568#M16592</link>
    <description>Hi Gernot,&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;Printers go immediatly offline if authentication is actived - with no requests to IAS send.&lt;BR /&gt;Both use the same IAS-policies.&lt;BR /&gt;&lt;UNQUOTE&gt;&lt;BR /&gt;What do you mean? are the printer offline as seen from a printeserver? or does the printer itself goes offline?&lt;BR /&gt;&lt;BR /&gt;Are the printers setup as DHCP or static adress?&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;As long as a MAC is supplied the client shouldn't matter, or I'm wrong?&lt;BR /&gt;&lt;UNQUOTE&gt;&lt;BR /&gt;in dhcp-requests there can be a "vendor-specific" field (option 43?). wich can result in different handling of the request.&lt;BR /&gt;&lt;BR /&gt;maybe the output from &lt;BR /&gt;show port-access mac-based config&lt;BR /&gt;and&lt;BR /&gt;show port-access mac-based clients&lt;BR /&gt;instead of the current status will help.&lt;/UNQUOTE&gt;&lt;/QUOTE&gt;&lt;/UNQUOTE&gt;&lt;/QUOTE&gt;</description>
    <pubDate>Thu, 20 Nov 2008 10:15:13 GMT</pubDate>
    <dc:creator>Pieter 't Hart</dc:creator>
    <dc:date>2008-11-20T10:15:13Z</dc:date>
    <item>
      <title>Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309567#M16591</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I'm configuring several 2626 (H.10.45) and 5308xl  (E.11.03)switches for mac-based authentication and would be very happy about some hints :)&lt;BR /&gt;&lt;BR /&gt;Scenario:&lt;BR /&gt;Multiple thinclients and printers should be authenticated via MAC. &lt;BR /&gt;There are several clients and printers on each switch.&lt;BR /&gt;&lt;BR /&gt;Problem:&lt;BR /&gt;Thinclients work, Printers don't (mostly HP LJ 1000 - 4000 Series). There's one exception: a &lt;BR /&gt;Samsung ML-2550, altough the same model on a differnt switch doesn't work, haven't found any differences yet. As long as a MAC is supplied the client shouldn't matter, or I'm wrong?&lt;BR /&gt;&lt;BR /&gt;Activated Ports with printers connected are shown under *show port-access mac-based* but both "Authenticated Clients" and "Unauthenticated Clients" are 0. Thinclients have "Authenticated Clients" 1.&lt;BR /&gt;&lt;BR /&gt;I have no clue why :(&lt;BR /&gt;&lt;BR /&gt;There are no authentication attempts on IAS-Servers (MS IAS), thinclients are sucessfully logged. Apparently the switches don't send requests for printers.&lt;BR /&gt;&lt;BR /&gt;Summary:&lt;BR /&gt;MAC-based authentication works for thinclients, not for printers on the same switch.&lt;BR /&gt;Thinclients authenticate sucessfully.&lt;BR /&gt;Printers go immediatly offline if authentication is actived -  with no requests to IAS send.&lt;BR /&gt;Both use the same IAS-policies.&lt;BR /&gt;&lt;BR /&gt;My only hints so far are:&lt;BR /&gt;&lt;BR /&gt;Logging:&lt;BR /&gt;"18:02:44 ports: port H1 is Blocked by AAA"&lt;BR /&gt;"18:02:47 ports: port H1 is Blocked by STP"&lt;BR /&gt;&lt;BR /&gt;show port-acces mac-based:&lt;BR /&gt; Port Access MAC-Based Status&lt;BR /&gt;&lt;BR /&gt;        Authenticated Unauthenticated Current  RADIUS ACL&lt;BR /&gt;  Port  Clients       Clients         VLAN ID  Applied?&lt;BR /&gt;  ----- ------------- --------------- -------- -----------&lt;BR /&gt;  H1    0             0               1        No&lt;BR /&gt;&lt;BR /&gt;I've read this guide, but it hasn't given me any pointers:&lt;BR /&gt;&lt;A href="http://cdn.procurve.com/training/Manuals/2900-ASG-Jan08-3-WebMacAuth.pdf" target="_blank"&gt;http://cdn.procurve.com/training/Manuals/2900-ASG-Jan08-3-WebMacAuth.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hopefully somebody has experience with this behavior :)&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;BR /&gt;&lt;BR /&gt;Gernot</description>
      <pubDate>Wed, 19 Nov 2008 17:36:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309567#M16591</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-11-19T17:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309568#M16592</link>
      <description>Hi Gernot,&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;Printers go immediatly offline if authentication is actived - with no requests to IAS send.&lt;BR /&gt;Both use the same IAS-policies.&lt;BR /&gt;&lt;UNQUOTE&gt;&lt;BR /&gt;What do you mean? are the printer offline as seen from a printeserver? or does the printer itself goes offline?&lt;BR /&gt;&lt;BR /&gt;Are the printers setup as DHCP or static adress?&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;As long as a MAC is supplied the client shouldn't matter, or I'm wrong?&lt;BR /&gt;&lt;UNQUOTE&gt;&lt;BR /&gt;in dhcp-requests there can be a "vendor-specific" field (option 43?). wich can result in different handling of the request.&lt;BR /&gt;&lt;BR /&gt;maybe the output from &lt;BR /&gt;show port-access mac-based config&lt;BR /&gt;and&lt;BR /&gt;show port-access mac-based clients&lt;BR /&gt;instead of the current status will help.&lt;/UNQUOTE&gt;&lt;/QUOTE&gt;&lt;/UNQUOTE&gt;&lt;/QUOTE&gt;</description>
      <pubDate>Thu, 20 Nov 2008 10:15:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309568#M16592</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2008-11-20T10:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309569#M16593</link>
      <description>Hello Pieter,&lt;BR /&gt;&lt;BR /&gt;thank you for your reply.&lt;BR /&gt;&lt;BR /&gt;Output *show port-access mac-based config*:&lt;BR /&gt;&lt;BR /&gt; Port Access MAC-Based Configuration&lt;BR /&gt;&lt;BR /&gt;  MAC Address Format : no-delimiter&lt;BR /&gt;  Allow RADIUS-assigned dynamic (GVRP) VLANs [No] : No&lt;BR /&gt;&lt;BR /&gt;                 Client Client Logoff    Re-Auth   Unauth   Auth     Cntrl&lt;BR /&gt;  Port  Enabled  Limit  Moves  Period    Period    VLAN ID  VLAN ID  Dir&lt;BR /&gt;  ----- -------- ------ ------ --------- --------- -------- -------- -----&lt;BR /&gt;  H1    Yes       1      No     300       0         0        0        both&lt;BR /&gt;&lt;BR /&gt;###############&lt;BR /&gt;&lt;BR /&gt;Output *show port-access mac-based clients*:&lt;BR /&gt;&lt;BR /&gt; Port Access MAC-Based Client Status&lt;BR /&gt;&lt;BR /&gt;  Port  MAC Address   Session Status        Time&lt;BR /&gt;  ----- ------------- --------------------- --------&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, it's empty, working clients are shown properly:&lt;BR /&gt;&lt;BR /&gt; Port Access MAC-Based Client Status&lt;BR /&gt;&lt;BR /&gt;  Port MAC Address   Session Status        Time&lt;BR /&gt;  ---- ------------- --------------------- --------&lt;BR /&gt;  24   0000f0-a345fd authenticated         67,211&lt;BR /&gt;&lt;BR /&gt;###########&lt;BR /&gt;&lt;BR /&gt;Printers are immediatly not reachable per ping. And port is displayed as closed.&lt;BR /&gt;Clients have static IPs, no DHCP-Voodoo :)&lt;BR /&gt;&lt;BR /&gt;Kind Regards,&lt;BR /&gt;&lt;BR /&gt;Gernot</description>
      <pubDate>Thu, 20 Nov 2008 11:08:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309569#M16593</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-11-20T11:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309570#M16594</link>
      <description>Has nobody an idea?</description>
      <pubDate>Mon, 24 Nov 2008 08:50:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309570#M16594</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-11-24T08:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309571#M16595</link>
      <description>Still nobody?</description>
      <pubDate>Mon, 01 Dec 2008 18:47:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309571#M16595</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-12-01T18:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309572#M16596</link>
      <description>There is a controlled directions feature for aaa, try changing that to 'in'. (That way an unauthenticated client will still receive broadcast/multicast traffic from the network which is what the printer might need to see before it sends any return traffic to kick off the mac-auth process).&lt;BR /&gt;&lt;BR /&gt;Also, make sure you update to the latest version firmware.</description>
      <pubDate>Tue, 02 Dec 2008 11:41:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309572#M16596</guid>
      <dc:creator>Matt Hobbs</dc:creator>
      <dc:date>2008-12-02T11:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309573#M16597</link>
      <description>Hello Matt,&lt;BR /&gt;&lt;BR /&gt;i've tried in, out and both, nothing worked. All working clients (Thinclients) have both configured. &lt;BR /&gt;Firmware is 10.45 for 2626 and 11.03 for 5308.&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;BR /&gt;&lt;BR /&gt;Gernot</description>
      <pubDate>Tue, 09 Dec 2008 07:41:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309573#M16597</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-12-09T07:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309574#M16598</link>
      <description>H.10.45 is not the latest software, you should rather try H.10.74</description>
      <pubDate>Tue, 09 Dec 2008 20:30:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309574#M16598</guid>
      <dc:creator>Krzysztof Oledzki</dc:creator>
      <dc:date>2008-12-09T20:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309575#M16599</link>
      <description>I have been working over the last week to keep my jetdirects authenticated with MAC based auth all the time, and I have been quite sucessful with the following.&lt;BR /&gt;&lt;BR /&gt;Upgraded all jetdirects to their latest firmware, DOWNgraded any jetdirect J7949E on firmware v33.15 to v33.14 (.15 is horribly broken and crashes after a couple of minutes usually).&lt;BR /&gt;&lt;BR /&gt;I have enabled SLP protocol on all the print servers, I have then telneted into the jetdirect to set slp-keep-alive (available with the firmware updates) to a value of 2 (2 minutes between slp anouncments).&lt;BR /&gt;&lt;BR /&gt;I have changed the MAC age time on all the switches to 900 seconds from the default 300.&lt;BR /&gt;&lt;BR /&gt;Jetdirects now announce themselves every 2 minutes stopping the switch forgetting that they exist. I have added a logoff-period of 1800 seconds to a single port with a Xerox printer on it which stops it reauthenticating every 10 minutes (unable to change slp interval on it).&lt;BR /&gt;&lt;BR /&gt;This may or may not help, but I've had the printers on line for the last week now and when I ping, they are still there!</description>
      <pubDate>Wed, 10 Dec 2008 22:38:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309575#M16599</guid>
      <dc:creator>DMcCoy_1</dc:creator>
      <dc:date>2008-12-10T22:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Port-access mac-based Problem</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309576#M16600</link>
      <description>Thank you for your input.&lt;BR /&gt;I have upgraded my Firmware, but still same behavior. &lt;BR /&gt;@DMCCoy: excellent tips :)&lt;BR /&gt;Time out problems would be cool, at least I would be one step further...</description>
      <pubDate>Wed, 17 Dec 2008 14:08:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/port-access-mac-based-problem/m-p/4309576#M16600</guid>
      <dc:creator>MP2</dc:creator>
      <dc:date>2008-12-17T14:08:06Z</dc:date>
    </item>
  </channel>
</rss>

