<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x authentication issue on HP 5412 switch in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594342#M21663</link>
    <description>FiluFreeman said: 1 question though: in this authentication conversation, who initiates it first? which device sends the FIRST request? The switch? The wks? The NAP server?&lt;BR /&gt;&lt;BR /&gt;Jeff reply: when a switch port is configured for 802.1X auth, and then a device (computer in this case) is connected, the switch basically sends an "EAP Identity Request" packet to the device, if the device is configured correctly, then it will send an "EAP Identity Response", then the switch will repackage that info and send to radius a "RADIUS Access Reuqest".&lt;BR /&gt;&lt;BR /&gt;These comms between the client and switch are all at layer2, as there is no IP address available yet. This is what EAP provides, layer2 comms.&lt;BR /&gt;&lt;BR /&gt;So, it looks to me like the issue is with the client-to-switch initial comms.&lt;BR /&gt;&lt;BR /&gt;hth...Jeff</description>
    <pubDate>Thu, 04 Mar 2010 14:26:23 GMT</pubDate>
    <dc:creator>Jeff Carrell</dc:creator>
    <dc:date>2010-03-04T14:26:23Z</dc:date>
    <item>
      <title>802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594339#M21660</link>
      <description>Hi, &lt;BR /&gt;&lt;BR /&gt;I have a switch HP 5412zl. I have a NAP w2k8 r2 server. I have a wired w7 wks. I have HP Procurve with IDM 3.&lt;BR /&gt;&lt;BR /&gt; I used&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=8a0925ee-ee06-4dfb-bba2-07605eff0608&amp;amp;displaylang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=8a0925ee-ee06-4dfb-bba2-07605eff0608&amp;amp;displaylang=en&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/AN-S5_ProCurve-IDM-NAP-integration-final-081108.pdf" target="_blank"&gt;http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/AN-S5_ProCurve-IDM-NAP-integration-final-081108.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;and I can't see any auth conversation, nothing gets to the NAP/Radius, I used Net Monitor 3.3 to see what's going on. And as far as I can see my configurations are right, see the HP switch config attached &lt;BR /&gt;&lt;BR /&gt;Anyways, I don't know...&lt;BR /&gt;&lt;BR /&gt;Thanks!!</description>
      <pubDate>Wed, 03 Mar 2010 18:16:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594339#M21660</guid>
      <dc:creator>FiluFreeman</dc:creator>
      <dc:date>2010-03-03T18:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594340#M21661</link>
      <description>hmmm...&lt;BR /&gt;&lt;BR /&gt;As I see it, your switch config looks ok.&lt;BR /&gt;&lt;BR /&gt;You say no authentication requests seem to be coming from the switch to the server, so that really indicates either switch config, switch can't talk to the server, or client config.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;A good resource for client configs is here: &lt;A href="http://tinyurl.com/8021X-supplicant-1" target="_blank"&gt;http://tinyurl.com/8021X-supplicant-1&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If the client config is good and the switch can ping the server, then something has to be happening (I read that somewhere ;-)&lt;BR /&gt;&lt;BR /&gt;So, if all above looks good, then try the following:&lt;BR /&gt;&lt;BR /&gt;1) If the IDM agent is "started" on the W2K8/NAP server, shut that service down and troubleshoot this problem one step at a time.&lt;BR /&gt;&lt;BR /&gt;2) Look at the "radius log" to see if radius (NAP) is even trying to authenticate the client request and/or what (if any) errors it is generating?&lt;BR /&gt;&lt;BR /&gt;On the W2K8 server, look at:&lt;BR /&gt; event viewer/custom views/server roles/network policy and access services  and see if any switch-to-NAP (radius) transactions are occurring.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Most common radius (NAP)/AD issues are (after basic switch-to-radius comms work):&lt;BR /&gt; 1) switch is not defined as a radius client&lt;BR /&gt; 2) NAP policy, either "connection request policies" and/or "network policies" are not configured correctly, meaning a failure to pass a test&lt;BR /&gt; 3) AD uid/pw/group membership issue&lt;BR /&gt;&lt;BR /&gt;If you resolve any issues that are in radius/AD, then restart the IDM Agent service and then see what the radius log info indicates, as well as what the IDM log indicates.&lt;BR /&gt;&lt;BR /&gt;Troubleshooting IDM can get really tricky and especially more so if you have a fundamental radius problem before IDM can even do its testing.&lt;BR /&gt;&lt;BR /&gt;hth...Jeff</description>
      <pubDate>Wed, 03 Mar 2010 23:12:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594340#M21661</guid>
      <dc:creator>Jeff Carrell</dc:creator>
      <dc:date>2010-03-03T23:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594341#M21662</link>
      <description>that's my problem, I can't see any logs anywhere, and I really know where to look ;). So NAP events = 0. HP switch events = 0. IDM events = 0. Netmonitor shows nothing EAP related. so this is why I'm really lost. I already took IDM out of the picture, to see switch-NAP conversation. and nothing. and I swear I put the correct RADIUS clients. and passwords. I'm completely lost, I really don't know where to start to troubleshoot. 1 question though: in this authentication conversation, who initiates it first? which device sends the FIRST request? The switch? The wks? The NAP server?&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Thu, 04 Mar 2010 02:07:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594341#M21662</guid>
      <dc:creator>FiluFreeman</dc:creator>
      <dc:date>2010-03-04T02:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594342#M21663</link>
      <description>FiluFreeman said: 1 question though: in this authentication conversation, who initiates it first? which device sends the FIRST request? The switch? The wks? The NAP server?&lt;BR /&gt;&lt;BR /&gt;Jeff reply: when a switch port is configured for 802.1X auth, and then a device (computer in this case) is connected, the switch basically sends an "EAP Identity Request" packet to the device, if the device is configured correctly, then it will send an "EAP Identity Response", then the switch will repackage that info and send to radius a "RADIUS Access Reuqest".&lt;BR /&gt;&lt;BR /&gt;These comms between the client and switch are all at layer2, as there is no IP address available yet. This is what EAP provides, layer2 comms.&lt;BR /&gt;&lt;BR /&gt;So, it looks to me like the issue is with the client-to-switch initial comms.&lt;BR /&gt;&lt;BR /&gt;hth...Jeff</description>
      <pubDate>Thu, 04 Mar 2010 14:26:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594342#M21663</guid>
      <dc:creator>Jeff Carrell</dc:creator>
      <dc:date>2010-03-04T14:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594343#M21664</link>
      <description>after some more investigation I found some interesting EAP conversation&lt;BR /&gt;&lt;BR /&gt;source my workstations MAC - destination 01-80-c2-00-00-03&lt;BR /&gt;&lt;BR /&gt;source my switch MAC - destination 01-80-c2-00-00-03&lt;BR /&gt;&lt;BR /&gt;That's all I found. What is this? I have no idea where to start to troubleshoot. I mean I googled the MAC address 01-80-c2-00-00-03 and I found out it's a standard of some sort, but how do I make it work?&lt;BR /&gt;&lt;BR /&gt;This is all so exciting, but it shows that I don't really know too much about networking...</description>
      <pubDate>Thu, 04 Mar 2010 16:45:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594343#M21664</guid>
      <dc:creator>FiluFreeman</dc:creator>
      <dc:date>2010-03-04T16:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594344#M21665</link>
      <description>Also, please take a look at the attachment. Thank you!!</description>
      <pubDate>Thu, 04 Mar 2010 16:50:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594344#M21665</guid>
      <dc:creator>FiluFreeman</dc:creator>
      <dc:date>2010-03-04T16:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x authentication issue on HP 5412 switch</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594345#M21666</link>
      <description>The switch is sending, it looks as if the client side is not properly replying.&lt;BR /&gt;&lt;BR /&gt;So I'd say it looks like client is not properly configured for 802.1X.&lt;BR /&gt;&lt;BR /&gt;The full trace and the mac addresses of switch and client would help alot in troubleshooting this issue.&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Mar 2010 17:42:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-authentication-issue-on-hp-5412-switch/m-p/4594345#M21666</guid>
      <dc:creator>Jeff Carrell</dc:creator>
      <dc:date>2010-03-04T17:42:01Z</dc:date>
    </item>
  </channel>
</rss>

