<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x configuration - cannot authenticate to Microsoft NPS in Security e-Series</title>
    <link>https://community.hpe.com/t5/security-e-series/802-1x-configuration-cannot-authenticate-to-microsoft-nps/m-p/6907078#M677</link>
    <description>&lt;P&gt;Setting up initial dot1x configuration on HP 5500 HI - Comware vers 5.20.99&lt;/P&gt;&lt;P&gt;Problem is that cannot get user PC to authenticate using EAP to Microsoft NPS.&amp;nbsp; I do&amp;nbsp;NOT see EAPoL or Radius packets hitting the NPS from the switch.&amp;nbsp; I can SSH to the switch using radius authentication, so I know the radius config on the switch is working.&lt;/P&gt;&lt;P&gt;Error in switch log: 8021X/6/DOT1X_AUTH_FAILURE:&lt;/P&gt;&lt;P&gt;Port config&lt;BR /&gt;&amp;nbsp;port link-mode bridge&lt;BR /&gt;&amp;nbsp;port access vlan 144&lt;BR /&gt;&amp;nbsp;undo voice vlan mode auto&lt;BR /&gt;&amp;nbsp;broadcast-suppression pps 3000&lt;BR /&gt;&amp;nbsp;undo jumboframe enable&lt;BR /&gt;&amp;nbsp;lldp compliance admin-status cdp txrx&lt;BR /&gt;&amp;nbsp;qos trust dot1p&lt;BR /&gt;&amp;nbsp;undo dot1x handshake&lt;BR /&gt;&amp;nbsp;dot1x mandatory-domain tos.x.x.x.x&lt;BR /&gt;&amp;nbsp;dot1x port-method portbased&lt;BR /&gt;&amp;nbsp;dot1x&lt;BR /&gt;&amp;nbsp;dot1x eapol untag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port dot1x config&lt;/P&gt;&lt;P&gt;Equipment 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;EAP authentication is enabled&lt;BR /&gt;&amp;nbsp;EAD quick deploy is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;Configuration: Transmit Period&amp;nbsp;&amp;nbsp; 30 s,&amp;nbsp; Handshake Period&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quiet Period&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 s,&amp;nbsp; Quiet Period Timer is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Supp Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 s,&amp;nbsp; Server Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reauth Period&amp;nbsp;&amp;nbsp; 3600 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The maximal retransmitting times&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;&amp;nbsp;EAD quick deploy configuration:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EAD timeout:&amp;nbsp;&amp;nbsp; 30 m&lt;/P&gt;&lt;P&gt;&amp;nbsp;The maximum 802.1X user resource number is 2048 per slot&lt;BR /&gt;&amp;nbsp;Total current used 802.1X resource number is 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;GigabitEthernet1/0/19&amp;nbsp; is link-up&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Handshake is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Handshake secure is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X unicast-trigger is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X user-ip freeze is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Periodic reauthentication is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The port is an authenticator&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Authentication Mode is Auto&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Port Control Type is Port-based&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X Multicast-trigger is enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Mandatory authentication domain: tosx.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Guest VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Auth-Fail VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Critical VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Critical recovery-action: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Voice VLAN: NOT configured&lt;/P&gt;&lt;P&gt;Global dot1x config&lt;/P&gt;&lt;P&gt;Equipment 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;EAP authentication is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like someone to verify my switch configuration and let me know if there a problem with it.&amp;nbsp; Also any troubleshooting steps I can take to help isolate the problem.&amp;nbsp; Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2016 19:29:11 GMT</pubDate>
    <dc:creator>T-squared</dc:creator>
    <dc:date>2016-10-12T19:29:11Z</dc:date>
    <item>
      <title>802.1x configuration - cannot authenticate to Microsoft NPS</title>
      <link>https://community.hpe.com/t5/security-e-series/802-1x-configuration-cannot-authenticate-to-microsoft-nps/m-p/6907078#M677</link>
      <description>&lt;P&gt;Setting up initial dot1x configuration on HP 5500 HI - Comware vers 5.20.99&lt;/P&gt;&lt;P&gt;Problem is that cannot get user PC to authenticate using EAP to Microsoft NPS.&amp;nbsp; I do&amp;nbsp;NOT see EAPoL or Radius packets hitting the NPS from the switch.&amp;nbsp; I can SSH to the switch using radius authentication, so I know the radius config on the switch is working.&lt;/P&gt;&lt;P&gt;Error in switch log: 8021X/6/DOT1X_AUTH_FAILURE:&lt;/P&gt;&lt;P&gt;Port config&lt;BR /&gt;&amp;nbsp;port link-mode bridge&lt;BR /&gt;&amp;nbsp;port access vlan 144&lt;BR /&gt;&amp;nbsp;undo voice vlan mode auto&lt;BR /&gt;&amp;nbsp;broadcast-suppression pps 3000&lt;BR /&gt;&amp;nbsp;undo jumboframe enable&lt;BR /&gt;&amp;nbsp;lldp compliance admin-status cdp txrx&lt;BR /&gt;&amp;nbsp;qos trust dot1p&lt;BR /&gt;&amp;nbsp;undo dot1x handshake&lt;BR /&gt;&amp;nbsp;dot1x mandatory-domain tos.x.x.x.x&lt;BR /&gt;&amp;nbsp;dot1x port-method portbased&lt;BR /&gt;&amp;nbsp;dot1x&lt;BR /&gt;&amp;nbsp;dot1x eapol untag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port dot1x config&lt;/P&gt;&lt;P&gt;Equipment 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;EAP authentication is enabled&lt;BR /&gt;&amp;nbsp;EAD quick deploy is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;Configuration: Transmit Period&amp;nbsp;&amp;nbsp; 30 s,&amp;nbsp; Handshake Period&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quiet Period&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 s,&amp;nbsp; Quiet Period Timer is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Supp Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 s,&amp;nbsp; Server Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 100 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reauth Period&amp;nbsp;&amp;nbsp; 3600 s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The maximal retransmitting times&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;&amp;nbsp;EAD quick deploy configuration:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EAD timeout:&amp;nbsp;&amp;nbsp; 30 m&lt;/P&gt;&lt;P&gt;&amp;nbsp;The maximum 802.1X user resource number is 2048 per slot&lt;BR /&gt;&amp;nbsp;Total current used 802.1X resource number is 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;GigabitEthernet1/0/19&amp;nbsp; is link-up&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Handshake is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Handshake secure is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X unicast-trigger is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X user-ip freeze is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Periodic reauthentication is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The port is an authenticator&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Authentication Mode is Auto&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Port Control Type is Port-based&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 802.1X Multicast-trigger is enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Mandatory authentication domain: tosx.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Guest VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Auth-Fail VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Critical VLAN: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Critical recovery-action: NOT configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Voice VLAN: NOT configured&lt;/P&gt;&lt;P&gt;Global dot1x config&lt;/P&gt;&lt;P&gt;Equipment 802.1X protocol is enabled&lt;BR /&gt;&amp;nbsp;EAP authentication is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like someone to verify my switch configuration and let me know if there a problem with it.&amp;nbsp; Also any troubleshooting steps I can take to help isolate the problem.&amp;nbsp; Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 19:29:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/802-1x-configuration-cannot-authenticate-to-microsoft-nps/m-p/6907078#M677</guid>
      <dc:creator>T-squared</dc:creator>
      <dc:date>2016-10-12T19:29:11Z</dc:date>
    </item>
  </channel>
</rss>

