<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic configuring 802.1x with juniper radius server in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/configuring-802-1x-with-juniper-radius-server/m-p/5683021#M30869</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;i have HP switch 4500 , the switch configured as a radius client for the juniper radius server (UAC), the switch connected to the juniper radius as a client succesfully.&lt;BR /&gt;&lt;BR /&gt;i configured the dot1x on the switch and on one of the ports but the authentication on the client failed (there is a EAP-Failure messages sent from the switch to the client).&lt;BR /&gt;&lt;BR /&gt;below is the switch configuration.&lt;BR /&gt;&lt;BR /&gt;========================================&lt;BR /&gt;&lt;BR /&gt;radius scheme system&lt;BR /&gt;&amp;nbsp;server-type standard&lt;BR /&gt;&amp;nbsp;primary authentication 127.0.0.1 1645&lt;BR /&gt;&amp;nbsp;primary accounting 127.0.0.1 1646&lt;BR /&gt;&amp;nbsp;user-name-format without-domain&lt;BR /&gt;radius scheme radius1&lt;BR /&gt;&amp;nbsp;primary authentication 172.16.10.10 1812&lt;BR /&gt;&amp;nbsp;key authentication 123123&lt;BR /&gt;&amp;nbsp;timer 5&lt;BR /&gt;&amp;nbsp;retry 5&lt;BR /&gt;&amp;nbsp;user-name-format without-domain&lt;BR /&gt;&lt;BR /&gt;domain sudatel.net&lt;BR /&gt;&amp;nbsp;radius-scheme radius1&lt;BR /&gt;&amp;nbsp;access-limit disable&lt;BR /&gt;&amp;nbsp;state active&lt;BR /&gt;&amp;nbsp;vlan-assignment-mode integer&lt;BR /&gt;&amp;nbsp;idle-cut enable 20 2000&lt;BR /&gt;&amp;nbsp;self-service-url disable&lt;BR /&gt;&amp;nbsp;messenger time disable&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;domain system&lt;BR /&gt;&amp;nbsp; radius-scheme radius1&lt;BR /&gt;&amp;nbsp; access-limit disable&lt;BR /&gt;&amp;nbsp; state active&lt;BR /&gt;&amp;nbsp; vlan-assignment-mode integer&lt;BR /&gt;&amp;nbsp; idle-cut disable&lt;BR /&gt;&amp;nbsp; self-service-url disable&lt;BR /&gt;&amp;nbsp; messenger time disable&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; domain default enable sudatel.net&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; local-server nas-ip 127.0.0.1 key 123123&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;local-user admin&lt;BR /&gt;&amp;nbsp; password simple admin&lt;BR /&gt;&amp;nbsp; service-type lan-access&lt;BR /&gt;&amp;nbsp; service-type telnet level 3&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;local-user lanuser&lt;BR /&gt;&amp;nbsp; password cipher RQ4NJ=aZ$3GL&amp;gt;K8=@9OLY!!!&lt;BR /&gt;&amp;nbsp; service-type telnet level 3&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; dot1x&lt;BR /&gt;&amp;nbsp; dot1x authentication-method eap&lt;BR /&gt;&amp;nbsp; undo dot1x handshake enable&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; monitor-port Ethernet0/4 no-filt&lt;BR /&gt;&amp;nbsp; mirroring-port Ethernet0/3 both&lt;BR /&gt;&amp;nbsp; mirroring-port Ethernet0/2 both&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; queue-scheduler wrr 1 2 4 8&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 1&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 10&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 110&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 120&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 203&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Vlan-interface10&lt;BR /&gt;&amp;nbsp; ip address 172.16.10.11 255.255.255.0&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Aux0/0&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp; description TO SHQ_S6506_A&lt;BR /&gt;&amp;nbsp; duplex full&lt;BR /&gt;&amp;nbsp; speed 100&lt;BR /&gt;&amp;nbsp; port link-type trunk&lt;BR /&gt;&amp;nbsp; port trunk permit vlan 1 10 110 120 203&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp; port access vlan 10&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp; port access vlan 110&lt;BR /&gt;&amp;nbsp; dot1x port-method portbased&lt;BR /&gt;&amp;nbsp; dot1x guest-vlan 203&lt;BR /&gt;&amp;nbsp; dot1x&lt;BR /&gt;&lt;BR /&gt;=====================================&lt;BR /&gt;&lt;BR /&gt;any ideas?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Mahmoud&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jun 2012 06:39:10 GMT</pubDate>
    <dc:creator>eng_mahmood48</dc:creator>
    <dc:date>2012-06-07T06:39:10Z</dc:date>
    <item>
      <title>configuring 802.1x with juniper radius server</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/configuring-802-1x-with-juniper-radius-server/m-p/5683021#M30869</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;i have HP switch 4500 , the switch configured as a radius client for the juniper radius server (UAC), the switch connected to the juniper radius as a client succesfully.&lt;BR /&gt;&lt;BR /&gt;i configured the dot1x on the switch and on one of the ports but the authentication on the client failed (there is a EAP-Failure messages sent from the switch to the client).&lt;BR /&gt;&lt;BR /&gt;below is the switch configuration.&lt;BR /&gt;&lt;BR /&gt;========================================&lt;BR /&gt;&lt;BR /&gt;radius scheme system&lt;BR /&gt;&amp;nbsp;server-type standard&lt;BR /&gt;&amp;nbsp;primary authentication 127.0.0.1 1645&lt;BR /&gt;&amp;nbsp;primary accounting 127.0.0.1 1646&lt;BR /&gt;&amp;nbsp;user-name-format without-domain&lt;BR /&gt;radius scheme radius1&lt;BR /&gt;&amp;nbsp;primary authentication 172.16.10.10 1812&lt;BR /&gt;&amp;nbsp;key authentication 123123&lt;BR /&gt;&amp;nbsp;timer 5&lt;BR /&gt;&amp;nbsp;retry 5&lt;BR /&gt;&amp;nbsp;user-name-format without-domain&lt;BR /&gt;&lt;BR /&gt;domain sudatel.net&lt;BR /&gt;&amp;nbsp;radius-scheme radius1&lt;BR /&gt;&amp;nbsp;access-limit disable&lt;BR /&gt;&amp;nbsp;state active&lt;BR /&gt;&amp;nbsp;vlan-assignment-mode integer&lt;BR /&gt;&amp;nbsp;idle-cut enable 20 2000&lt;BR /&gt;&amp;nbsp;self-service-url disable&lt;BR /&gt;&amp;nbsp;messenger time disable&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;domain system&lt;BR /&gt;&amp;nbsp; radius-scheme radius1&lt;BR /&gt;&amp;nbsp; access-limit disable&lt;BR /&gt;&amp;nbsp; state active&lt;BR /&gt;&amp;nbsp; vlan-assignment-mode integer&lt;BR /&gt;&amp;nbsp; idle-cut disable&lt;BR /&gt;&amp;nbsp; self-service-url disable&lt;BR /&gt;&amp;nbsp; messenger time disable&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; domain default enable sudatel.net&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; local-server nas-ip 127.0.0.1 key 123123&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;local-user admin&lt;BR /&gt;&amp;nbsp; password simple admin&lt;BR /&gt;&amp;nbsp; service-type lan-access&lt;BR /&gt;&amp;nbsp; service-type telnet level 3&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;local-user lanuser&lt;BR /&gt;&amp;nbsp; password cipher RQ4NJ=aZ$3GL&amp;gt;K8=@9OLY!!!&lt;BR /&gt;&amp;nbsp; service-type telnet level 3&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; dot1x&lt;BR /&gt;&amp;nbsp; dot1x authentication-method eap&lt;BR /&gt;&amp;nbsp; undo dot1x handshake enable&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; monitor-port Ethernet0/4 no-filt&lt;BR /&gt;&amp;nbsp; mirroring-port Ethernet0/3 both&lt;BR /&gt;&amp;nbsp; mirroring-port Ethernet0/2 both&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp; queue-scheduler wrr 1 2 4 8&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 1&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 10&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 110&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 120&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;vlan 203&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Vlan-interface10&lt;BR /&gt;&amp;nbsp; ip address 172.16.10.11 255.255.255.0&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Aux0/0&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp; description TO SHQ_S6506_A&lt;BR /&gt;&amp;nbsp; duplex full&lt;BR /&gt;&amp;nbsp; speed 100&lt;BR /&gt;&amp;nbsp; port link-type trunk&lt;BR /&gt;&amp;nbsp; port trunk permit vlan 1 10 110 120 203&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp; port access vlan 10&lt;BR /&gt;&amp;nbsp;#&lt;BR /&gt;&amp;nbsp;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp; port access vlan 110&lt;BR /&gt;&amp;nbsp; dot1x port-method portbased&lt;BR /&gt;&amp;nbsp; dot1x guest-vlan 203&lt;BR /&gt;&amp;nbsp; dot1x&lt;BR /&gt;&lt;BR /&gt;=====================================&lt;BR /&gt;&lt;BR /&gt;any ideas?&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Mahmoud&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2012 06:39:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/configuring-802-1x-with-juniper-radius-server/m-p/5683021#M30869</guid>
      <dc:creator>eng_mahmood48</dc:creator>
      <dc:date>2012-06-07T06:39:10Z</dc:date>
    </item>
  </channel>
</rss>

