<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x Authentication fail E63018 in IMC</title>
    <link>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849253#M2815</link>
    <description>&lt;P&gt;OK - first I'm running 7.1 so there may be slight difference.&lt;/P&gt;&lt;P&gt;Sorry but your english is unclear, but I think you want to have login be &lt;STRONG&gt;user@domain.com&lt;/STRONG&gt;, correct? Aplogoies if I misunderstand.&lt;/P&gt;&lt;P&gt;Looks like your switch has sent has sent &lt;STRONG&gt;user@domain.com&lt;/STRONG&gt; - that is login name&lt;/P&gt;&lt;P&gt;But your LDAP has brought over just &lt;STRONG&gt;user&lt;/STRONG&gt; as account name. So you need to remove&amp;nbsp;@domain.com&lt;/P&gt;&lt;P&gt;I don't think your switch config is doing that - even though it looks like you have tried. Check with wireshark packets sent to imc.&lt;/P&gt;&lt;P&gt;To remove &lt;STRONG&gt;@domain.com&lt;/STRONG&gt;&amp;nbsp;in imc go to&amp;nbsp;User &amp;gt; User Access Policy &amp;gt; LDAP Service &amp;gt; LDAP Server &amp;gt; your server&lt;/P&gt;&lt;P&gt;for account format use Remove Suffix and delimter&amp;nbsp;@&lt;/P&gt;&lt;P&gt;You can't edit current setup so create new.&lt;/P&gt;&lt;P&gt;Hope I understand correctly and this helps you.&lt;/P&gt;</description>
    <pubDate>Sat, 09 Apr 2016 01:25:15 GMT</pubDate>
    <dc:creator>NeilR</dc:creator>
    <dc:date>2016-04-09T01:25:15Z</dc:date>
    <item>
      <title>Dot1x Authentication fail E63018</title>
      <link>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849106#M2811</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;first. i'm sory for my english is no good&lt;/P&gt;&lt;P&gt;I configured iMC (7.2) witch UAM and already sync user from ldap server and ldap policy.&lt;/P&gt;&lt;P&gt;when client authentication to switch log of iMC present in picture 1&lt;/P&gt;&lt;P&gt;and this is configured on switch hp 5500&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;dot1x&lt;BR /&gt;dot1x timer handshake-period 30&lt;BR /&gt;dot1x authentication-method eap&lt;BR /&gt;dot1x domain-delimiter @\&lt;/P&gt;&lt;P&gt;radius scheme accessuser&lt;BR /&gt;server-type extended&lt;BR /&gt;primary authentication xx.xx.xx.xx key cipher -&lt;BR /&gt;primary accounting xx.xx.xx.xx key cipher -&lt;BR /&gt;timer response-timeout 5&lt;BR /&gt;user-name-format without-domain&lt;BR /&gt;nas-ip xx.xx.xx.xx&lt;BR /&gt;retry 5&lt;BR /&gt;accounting-on enable&lt;/P&gt;&lt;P&gt;domain lab&lt;BR /&gt;authentication default radius-scheme mac-authen&lt;BR /&gt;authorization default radius-scheme mac-authen&lt;BR /&gt;accounting default radius-scheme mac-authen&lt;BR /&gt;authentication login radius-scheme mgmt-switch local&lt;BR /&gt;authorization login radius-scheme mgmt-switch local&lt;BR /&gt;accounting login radius-scheme mgmt-switch local&lt;BR /&gt;authentication lan-access radius-scheme accessuser&lt;BR /&gt;authorization lan-access radius-scheme accessuser&lt;BR /&gt;accounting lan-access radius-scheme accessuser&lt;BR /&gt;access-limit disable&lt;BR /&gt;state active&lt;BR /&gt;idle-cut disable&lt;BR /&gt;self-service-url disable&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;port link-mode bridge&lt;BR /&gt;port link-type trunk&lt;BR /&gt;port trunk permit vlan 1 743&lt;BR /&gt;port trunk pvid vlan 743&lt;BR /&gt;voice vlan 104 enable&lt;BR /&gt;poe enable&lt;BR /&gt;port-security max-mac-count 3&lt;BR /&gt;port-security intrusion-mode disableport-temporarily&lt;BR /&gt;undo dot1x handshake&lt;BR /&gt;undo dot1x multicast-trigger&lt;BR /&gt;dot1x&lt;BR /&gt;#&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if i configured ldap derver with add prefix domain/ it can be done. but i want to delimiter domain&lt;/P&gt;&lt;P&gt;thank you&amp;nbsp; and please help&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 11:49:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849106#M2811</guid>
      <dc:creator>Pingkung</dc:creator>
      <dc:date>2016-04-08T11:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x Authentication fail E63018</title>
      <link>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849253#M2815</link>
      <description>&lt;P&gt;OK - first I'm running 7.1 so there may be slight difference.&lt;/P&gt;&lt;P&gt;Sorry but your english is unclear, but I think you want to have login be &lt;STRONG&gt;user@domain.com&lt;/STRONG&gt;, correct? Aplogoies if I misunderstand.&lt;/P&gt;&lt;P&gt;Looks like your switch has sent has sent &lt;STRONG&gt;user@domain.com&lt;/STRONG&gt; - that is login name&lt;/P&gt;&lt;P&gt;But your LDAP has brought over just &lt;STRONG&gt;user&lt;/STRONG&gt; as account name. So you need to remove&amp;nbsp;@domain.com&lt;/P&gt;&lt;P&gt;I don't think your switch config is doing that - even though it looks like you have tried. Check with wireshark packets sent to imc.&lt;/P&gt;&lt;P&gt;To remove &lt;STRONG&gt;@domain.com&lt;/STRONG&gt;&amp;nbsp;in imc go to&amp;nbsp;User &amp;gt; User Access Policy &amp;gt; LDAP Service &amp;gt; LDAP Server &amp;gt; your server&lt;/P&gt;&lt;P&gt;for account format use Remove Suffix and delimter&amp;nbsp;@&lt;/P&gt;&lt;P&gt;You can't edit current setup so create new.&lt;/P&gt;&lt;P&gt;Hope I understand correctly and this helps you.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2016 01:25:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849253#M2815</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-04-09T01:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x Authentication fail E63018</title>
      <link>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849399#M2818</link>
      <description>&lt;P&gt;thank you for reply&lt;STRONG&gt;&lt;SPAN class="lia-panel-heading-bar-title"&gt; &lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/549529"&gt;@NeilR﻿&lt;/a&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I want to remove @domain.com&amp;nbsp; on my switch before send to imc by use this command&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;dot1x domain-delimiter @\&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;but when switch send username to iMC its include @domain.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;so how can i remove @domain.com before sending to iMC&lt;/P&gt;&lt;P&gt;sory for may English is not clear.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Apr 2016 16:36:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849399#M2818</guid>
      <dc:creator>Pingkung</dc:creator>
      <dc:date>2016-04-10T16:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x Authentication fail E63018</title>
      <link>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849669#M2820</link>
      <description>&lt;P&gt;No worries on english - I understand you wish to remove&amp;nbsp;@domain.com from userid sent from switch to imc&lt;/P&gt;&lt;P&gt;My apologies as I have all my 802.1x users running on Procurve switch not comware. We get full user name.&lt;/P&gt;&lt;P&gt;My comware is limited to server side switches, but looking at documentation&amp;nbsp;I have, I don't see info on dot1x delimiter for my versions&lt;/P&gt;&lt;P&gt;But they do say as pre-requisite to "Configure an ISP domain and AAA scheme (local or RADIUS authentication) for 802.1X users" and I do not see that in your configuration - only for MAC authentication. So you might look at that.&lt;/P&gt;&lt;P&gt;My comment above was on&amp;nbsp;how to remove&amp;nbsp;@domain.com AFTER it got sent to imc.&lt;/P&gt;&lt;P&gt;If you want to remove BEFORE it is sent to imc then the comware configuration is the issue. My comware knowldege is too limited to help you. So Sorry.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 17:06:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/dot1x-authentication-fail-e63018/m-p/6849669#M2820</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2016-04-11T17:06:57Z</dc:date>
    </item>
  </channel>
</rss>

