<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x Problem on Remote Site in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138791#M28488</link>
    <description>Where is the dhcp-server connected (probably local servers SRV#1 SRV#2 ?, I see no ip-helper configured)&lt;BR /&gt;&lt;BR /&gt;is a different vlan used at the HQ?&lt;BR /&gt;if so is this vlan assigned by the radius server?&lt;BR /&gt;&lt;BR /&gt;see "VLAN Membership Priorities" P11-30 in &lt;BR /&gt;&lt;A href="http://cdn.procurve.com/training/Manuals/2610-Security-Dec2007-59918642.pdf" target="_blank"&gt;http://cdn.procurve.com/training/Manuals/2610-Security-Dec2007-59918642.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;suggestion : try test with local user.&lt;BR /&gt;password port-access user-name Jim secret3&lt;BR /&gt;aaa authentication port-access local</description>
    <pubDate>Mon, 03 Nov 2008 10:19:43 GMT</pubDate>
    <dc:creator>Pieter 't Hart</dc:creator>
    <dc:date>2008-11-03T10:19:43Z</dc:date>
    <item>
      <title>802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138781#M28478</link>
      <description>Hi Everyone,&lt;BR /&gt;&lt;BR /&gt;I have a strange Problem at a Remote Site.&lt;BR /&gt;It's a Branch Office with only one 2610-48-PWR Switch.&lt;BR /&gt;&lt;BR /&gt;The Win XP Clients (with SP3) and the Users are successfully authenticated at the Windows IAS Server and the IDM but the Network Port seems not be change into the right VLAN so that the Clients won't get an IP-Address via DHCP.&lt;BR /&gt;&lt;BR /&gt;If I put static IP-Address to the Client and try to ping Ressources from the right VLAN the will be timed out. So the Client wille be in the wrong VLAN.&lt;BR /&gt;&lt;BR /&gt;This behavior occured also on the AP530 Access Point at this site.&lt;BR /&gt;&lt;BR /&gt;I tested the RADIUS Authentication and get all right informations for the User. So it might be something between the RADIUS Server and the Remote Site I think.&lt;BR /&gt;&lt;BR /&gt;I hope you can help me. Thanx.&lt;BR /&gt;&lt;BR /&gt;Alen</description>
      <pubDate>Sat, 01 Nov 2008 14:48:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138781#M28478</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-01T14:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138782#M28479</link>
      <description>hi Alen please send me sh run print</description>
      <pubDate>Sat, 01 Nov 2008 15:39:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138782#M28479</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-01T15:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138783#M28480</link>
      <description>and can you see about authentication any log on switch or IAS server</description>
      <pubDate>Sat, 01 Nov 2008 15:40:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138783#M28480</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-01T15:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138784#M28481</link>
      <description>if you can see authentication successfull but not dhcp assign ip address to client&lt;BR /&gt;&lt;BR /&gt;check &lt;BR /&gt;ip helper address command on switch &lt;BR /&gt;&lt;BR /&gt;check &lt;BR /&gt;config)# sh vlans ports xxx &lt;BR /&gt;with command port vlan status &lt;BR /&gt;&lt;BR /&gt;check &lt;BR /&gt;remote active directory rule (in radius service)for user or user group rule&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 01 Nov 2008 16:04:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138784#M28481</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-01T16:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138785#M28482</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I attached you the # sh run Output.&lt;BR /&gt;&lt;BR /&gt;The IAS Server Log said, that the User was granted, so the authentication will be successfully.&lt;BR /&gt;&lt;BR /&gt;The IP-Helper on the switch is not active because it's not a routing switch. I installed a DHCP Relay on the Firewall wich works fine for the Guests-VLAN.&lt;BR /&gt;&lt;BR /&gt;# sh vlans ports xxx cannot check at the moment because I am back in the Headquarter.&lt;BR /&gt;&lt;BR /&gt;I can check the same issue next week at a another Branch Office.&lt;BR /&gt;&lt;BR /&gt;Alen</description>
      <pubDate>Sun, 02 Nov 2008 11:07:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138785#M28482</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-02T11:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138786#M28483</link>
      <description>I can see two radius server &lt;BR /&gt;&lt;BR /&gt;I think one radius server headquarter residing  and one radius server residing  branch office&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;where is residing dhcp server/servers</description>
      <pubDate>Mon, 03 Nov 2008 06:18:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138786#M28483</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-03T06:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138787#M28484</link>
      <description>if you can send me all topology layout&lt;BR /&gt;and all switch sh run print &lt;BR /&gt;&lt;BR /&gt;I check all config for you</description>
      <pubDate>Mon, 03 Nov 2008 06:33:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138787#M28484</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-03T06:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138788#M28485</link>
      <description>Both RADIUS Server are in the Headquarter.&lt;BR /&gt;&lt;BR /&gt;Here the Topology Layout&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;AP530 --&amp;gt; 2610-48-PWR --&amp;gt; Firewall Branch&lt;BR /&gt;&lt;BR /&gt;Firewall Branch --&amp;gt; VPN --&amp;gt; Firewall HQ&lt;BR /&gt;&lt;BR /&gt;FirwaÃ¶Ã¶ HQ --&amp;gt; IAS1 / IAS2</description>
      <pubDate>Mon, 03 Nov 2008 08:21:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138788#M28485</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-03T08:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138789#M28486</link>
      <description>IAS has two default policies "Microsoft RRAS" and "other RAS".&lt;BR /&gt;if the microsoft policiy has been changed from the default settings, sometimes the wrong policy is used&lt;BR /&gt;&lt;BR /&gt;see &lt;A href="http://technet.microsoft.com/en-us/library/cc786978.aspx" target="_blank"&gt;http://technet.microsoft.com/en-us/library/cc786978.aspx&lt;/A&gt; search for "third party"&lt;BR /&gt;&lt;BR /&gt;reset the microsoft RRAS policy to the defaults (or maybe change policy order or even delete).&lt;BR /&gt;&lt;BR /&gt;hope this helps&lt;BR /&gt;Pieter</description>
      <pubDate>Mon, 03 Nov 2008 08:28:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138789#M28486</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2008-11-03T08:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138790#M28487</link>
      <description>Hi Pieter,&lt;BR /&gt;&lt;BR /&gt;no the RADIUS Server will work fine.&lt;BR /&gt;I tested it yesterday in the Headquarter.&lt;BR /&gt;&lt;BR /&gt;The authentication is correct and the VLAN's on the switches in the HQ were also set correctly but not at the Branch Office Side :(&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 03 Nov 2008 08:30:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138790#M28487</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-03T08:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138791#M28488</link>
      <description>Where is the dhcp-server connected (probably local servers SRV#1 SRV#2 ?, I see no ip-helper configured)&lt;BR /&gt;&lt;BR /&gt;is a different vlan used at the HQ?&lt;BR /&gt;if so is this vlan assigned by the radius server?&lt;BR /&gt;&lt;BR /&gt;see "VLAN Membership Priorities" P11-30 in &lt;BR /&gt;&lt;A href="http://cdn.procurve.com/training/Manuals/2610-Security-Dec2007-59918642.pdf" target="_blank"&gt;http://cdn.procurve.com/training/Manuals/2610-Security-Dec2007-59918642.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;suggestion : try test with local user.&lt;BR /&gt;password port-access user-name Jim secret3&lt;BR /&gt;aaa authentication port-access local</description>
      <pubDate>Mon, 03 Nov 2008 10:19:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138791#M28488</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2008-11-03T10:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138792#M28489</link>
      <description>you have four vlan &lt;BR /&gt;vlan 1 managemet&lt;BR /&gt;vlan 1008 voip vlan &lt;BR /&gt;vlan 1009 office vlan &lt;BR /&gt;vlan 1007 guest vlan &lt;BR /&gt;&lt;BR /&gt;Ä± want dynamical assign vlan member each vlan with 802.1x &lt;BR /&gt;(only vlan 1008 for voip device static)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ip routing &lt;BR /&gt;vlan 1 &lt;BR /&gt;   name "DEFAULT_VLAN" &lt;BR /&gt;   untagged 1-34,41,50 &lt;BR /&gt;   ip address 172.16.1.4 255.255.255.0 &lt;BR /&gt;   no untagged 35-40 &lt;BR /&gt;   ip igmp high-priority-forward &lt;BR /&gt;   exit &lt;BR /&gt;vlan 1008 &lt;BR /&gt;   name "VoIP" &lt;BR /&gt;   untagged 35-40 &lt;BR /&gt;   ip address 172.16.2.4 255.255.255.0 &lt;BR /&gt;   qos priority 6 &lt;BR /&gt;   voice &lt;BR /&gt;   ip igmp high-priority-forward &lt;BR /&gt;   exit &lt;BR /&gt;vlan 1009 &lt;BR /&gt;   name "Office" &lt;BR /&gt;   ip address 172.16.3.4 255.255.255.0&lt;BR /&gt;   ip helper address (dhcp server address) &lt;BR /&gt;   exit &lt;BR /&gt;vlan 1007 &lt;BR /&gt;   name "Guests" &lt;BR /&gt;   ip address 172.16.5.4 255.255.255.192&lt;BR /&gt;   ip helper address (dhcp server address)&lt;BR /&gt;   exit&lt;BR /&gt;ip routing 0.0.0.0 0.0.0.0 172.16.1.5 *********this address firewall lan ip  &lt;BR /&gt;aaa authentication port-access eap-radius &lt;BR /&gt;aaa accounting network start-stop radius &lt;BR /&gt;radius-server host &lt;IP radius="" server=""&gt; key &lt;RADIUS-KEY&gt;&lt;BR /&gt;radius-server host &lt;IP radius="" server=""&gt; &lt;RADIUS-KEY&gt;&lt;BR /&gt;aaa port-access authenticator 30&lt;BR /&gt;aaa port-access authenticator 30 reauth-period 300&lt;BR /&gt;aaa port-access authenticator 30 unauth-vid 1007&lt;BR /&gt;aaa port-access authenticator 30 client-limit 1&lt;BR /&gt;aaa port-access authenticator active&lt;BR /&gt;aaa port-access 30 &lt;BR /&gt;&lt;BR /&gt;interface 30 resiade vlan 1 untagged member &lt;BR /&gt;when to take radius authentication packet this port dynamically change vlan status&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;you have to create redius active directory rules in radius servis for all domain users  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;for vlan 1009 office users&lt;BR /&gt;important 3 attribute&lt;BR /&gt;tunnel medium type ---radius standart---802 includes all....&lt;BR /&gt;tunnel pvd group id---radius standart--1009  (this number very important because definition vlan) &lt;BR /&gt;tunnel type-----------radius standart--virtual lans (vlan)&lt;BR /&gt;&lt;BR /&gt;each domain user connect any port(except int 35-40)assign to dynamically vlan 1009&lt;BR /&gt;&lt;BR /&gt;other user (nondomain)want connect any port (except int 35-40)assign to dynamically vlan 1007&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;create for vlan 1009 and 1007 dhcp scobe on dhcp server &lt;BR /&gt;&lt;BR /&gt;scobe 1&lt;BR /&gt;name forvlan1009&lt;BR /&gt;ip range 172.16.3.10.....50 &lt;BR /&gt;subnet mask 255.255.255.0&lt;BR /&gt;default route 172.16.3.4&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;scobe 2&lt;BR /&gt;name forvlan1007&lt;BR /&gt;ip range 172.16.5.10.....50 &lt;BR /&gt;subnet mask 255.255.255.0&lt;BR /&gt;default route 172.16.5.4&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;please watch this video &lt;BR /&gt;&lt;A href="http://www.dosya.tc/802.1x_dynamicvlan.rar.html" target="_blank"&gt;http://www.dosya.tc/802.1x_dynamicvlan.rar.html&lt;/A&gt; &lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/RADIUS-KEY&gt;&lt;/IP&gt;&lt;/RADIUS-KEY&gt;&lt;/IP&gt;</description>
      <pubDate>Mon, 03 Nov 2008 13:09:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138792#M28489</guid>
      <dc:creator>cenk sasmaztin</dc:creator>
      <dc:date>2008-11-03T13:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138793#M28490</link>
      <description>Hi Thanx for your config, but I don't want that switch routes everything. The Frewall will plays DHCP Relay.&lt;BR /&gt;&lt;BR /&gt;On which VLAN will be the client did the 802.1x request ?</description>
      <pubDate>Tue, 04 Nov 2008 20:21:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138793#M28490</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-04T20:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Problem on Remote Site</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138794#M28491</link>
      <description>Hi at all,&lt;BR /&gt;&lt;BR /&gt;I found the solution for the problem.&lt;BR /&gt;The main problem was the Framed MTU Size. The Microsoft KB Article 883389 (&lt;A href="http://support.microsoft.com/kb/883389/en-us)" target="_blank"&gt;http://support.microsoft.com/kb/883389/en-us)&lt;/A&gt; described how to reduced the EAP packet size.&lt;BR /&gt;&lt;BR /&gt;I say thank to all which tries to help.&lt;BR /&gt;&lt;BR /&gt;Alen</description>
      <pubDate>Wed, 05 Nov 2008 19:59:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/802-1x-problem-on-remote-site/m-p/5138794#M28491</guid>
      <dc:creator>Alen Ahja</dc:creator>
      <dc:date>2008-11-05T19:59:45Z</dc:date>
    </item>
  </channel>
</rss>

