802.1x, 350AP, 3550 Switch, and ACS 3.0

Yikes!
Whatta mess I got myself into! Im trying to implement a couple of security features (at the same time) due to higher corporate directives. I am trying to implement Radius, 802.1x port authentication on a Cat 3550 switch, and mac address athuentication for wireless clients. The idea was:
1. The 3550 has port based authentication on it and should authenticate access points as well as any workstations that will/may connect to it.
2. The wireless clients will be MAC authenticated via the access point passing requests to the radius server.
Confused? I am too, help!
Thanks

Nilesh, Thanks for the reply.
But I do have a few further questions if you are willing:
1. Getting the AP to use 802.1x and talk with the radius server seems to be the big problem. I have not been able to find clear enough instructions on how to set the AP to do 802.1x through the switch. I do realize the LEAP is just cisco's implementation of 802.1x but we are trying to use non-proprietary protocols.
2. We already have the clients MAC addresses in the AP's but want to get away from this (network mgt issues) by using the ACS server.
I guess what makes this confusing for me is the chain of events and if they are possible to do. Here are the steps as I see them, please advise if this is not possible to do.
1. Access point is plugged into 3550 and uses 802.1x authentication with radius through the switch. Once the switchport is authorized, then the wireless clients can try to associate with AP. To do this the MAC address of the client , is sent to ACS for authorization and when authorized allowed to communicate. Then the wireless client retrieves an IP address through DHCP.
Whew.

Similar Messages

  • 802.1x authentication switch and AD

    Hello,
    I want to know if Cisco has solved the problem (MD5) between ACS and Active Directory?? because I want to configure 802.1x in a switch and it will integrate with Active Directory (Data Base)
    The Solution is:
    Switch <--> ACS (Authentication)<--> AD (Data Base)
    Also i want to know if exist any solution no NAC Appliance that can use 802.1x integrate with AD in switch infraestructure??
    Best Regards

    I have hit the same challenge, where I need to authenticate the users against AD and I don't want to use the local CiscoSecure Database in ACS. For hundreds of users, there is no way I'm going to manage a database in ACS for user access. I have to manage the users in AD. I opened a case with Cisco and MS-CHAP is not supported by Cisco ACS, as I was provided this URL link:
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/o.html#wpxref846
    Additionally, I was directed to the URL: http://www.ciscotaccc.com/kaidara-advisor/security/showcase?case=K24308566
    I'm so stuck...there has to be way to use IEEE 802.1x with an external database such as LDAP.

  • Using Catalyst 3550 Switch with Linksys Home Router and Cable Internet

    I've about pulled what little hair I have out of my head on this one, and need some configuration help.
    I have a Cisco Catalyst 3550 switch with five Windows 7 desktops, an Avaya PBX and five Avaya IP phones attached.  All of these devices are on a 192.168.0.0/24 subnet, and are communicating properly.  I will refer to this as network # 1. I also have SEPARATE network, we'll call network # 2, using AT&T ADSL service and a Netgear 4-port/wireless router/ADSL modem combo device, which is functioning properly with a couple of other Windows 7 desktops over its own wired Ethernet network, using DHCP, and also on a 192.168.0.0/24 subnet.  I thought it would be a simple integration, just plugging one of the 3550's ports to one of the DSL router's ports, in order to give the five Windows 7 desktop computers on network # 1 internet access via the DSL modem. Guess I was wrong.  When I connect the two switches together, although I get a good connectivity (green lights on both ports) and am able to ping the DSL router's gateway address (192.168.0.252) from network # 1's computers, the computers on network # 1 cannot access the internet. Also, the working computers on network # 2 lose their internet access as long as the two switches are connected together. I am not a Cisco guru, but there's got to be a way to make this scenario work.  Can someone provide me with a 3550 configuration that will allow me to extend my internet service from network # 2 on the DSL router to my 3550 switch and their computers?  Here's what I am looking for:
    INTERNET ---> ADSL MODEM ---> NETGEAR ROUTER ---> CISCO 3550 SWITCH ---> NETWORK DEVICES WITH INTERNET ACCESS

    The Netgear router is probably what's doing the natting. Is the 3550 configured for routing or is it straight L2? If you have the 3550 configured as L3, then it's going to be easy to do what you want. Just add a static route on the Netgear to point the subnet that it doesn't know about to the 3550. For example, if the Netgear is addressed at 192.168.1.1 and the Cisco 3550 is addressed at 192.168.1.2, but it also knows about the 192.168.0.0/24 (separate vlan), then you would put a static route on your Netgear for 192.168.0.0/24 to go to 192.168.1.2.
    The way that I would do it is to create a separate vlan on the 3550 and assign an address to it. Once you do that, make the port that the other switch connects to an access port of that vlan. (It would need to be on the same subnet as the existing equipment.) All of your devices would use it as a default gateway and then you would do the rest as above. You could also use RIP between the Netgear and Cisco if you can't do static routing.
    HTH,
    John

  • Mitel phone 802.1x with Cat 3560 and Cisco ACS5.2 problem

    I am piloting an 802.1x implementation for a client who has Mitel IP Phones.  I have setup the switch and ACS based on previous experience and a windows PC can authenticate onto the network OK.  When I use a Mitel phone however, it seems to skip past the first 802.1x LCD message and goes straight to LLDP and DHCP discovery, which obviously fails.  The phone are 5224s and the controller is on the original v10 release.  I have cleared the 802.1x config on the phone and rebooting as per Mitel documentation which leads me to believe it should then prompt for a user/pass on next reboot.  It does not do this.
    I known the ACS is setup to support EAP-MD5 and I have tried all the various types of host modes including the default and Multi-Auth, Multi-Domain and none of them seem to make any difference.  I have tried with and without a PC attached to the phone as well.
    A wireshark shows the EAP identity request from the switch, and I see an EAP response from the phone, although it is slightly different to the PC's response.  In the end the phone issues an EAP 4 failure message.  So something in that EAP conversation doesnt seem to work.  Does anybody have an experience of this?

    A wireshark capture shows a difference in the EAP request message from a Cisco Cat 3560 (12.2.55) to the Mitel, compared to a HP Procurve to the Mitel which the Mitel responds to:
    Cisco EAP Request trace:
    Frame 17 (60 bytes on wire, 60 bytes captured)
    Ethernet II, Src: Cisco_99:06:84 (00:1e:49:99:06:84), Dst: Mitel_2c:ad:3b (08:00:0f:2c:ad:3b)
        Destination: Mitel_2c:ad:3b (08:00:0f:2c:ad:3b)
        Source: Cisco_99:06:84 (00:1e:49:99:06:84)
        Type: 802.1X Authentication (0x888e)
        Trailer: 000000000000000000000000000000000000000000000000...
    802.1X Authentication
       Version: 3
        Type: EAP Packet (0)
        Length: 5
        Extensible Authentication Protocol
            Code: Request (1)
            Id: 1
            Length: 5
            Type: Identity [RFC3748] (1)
    HP EAP Request trace:
    Frame 36 (60 bytes on wire, 60 bytes captured)
    Ethernet II, Src: Procurve_03:b7:40 (00:1b:3f:03:b7:40), Dst: Mitel_42:f5:21 (08:00:0f:42:f5:21)
        Destination: Mitel_42:f5:21 (08:00:0f:42:f5:21)
        Source: Procurve_03:b7:40 (00:1b:3f:03:b7:40)
        Type: 802.1X Authentication (0x888e)
        Trailer: 000000000000000000000000000000000000000000000000...
    802.1X Authentication
        Version: 1
        Type: EAP Packet (0)
        Length: 15
        Extensible Authentication Protocol
            Code: Request (1)
            Id: 1
            Length: 15
            Type: Identity [RFC3748] (1)
            Identity (10 bytes): User name:
    The HP seems to be requesting a User name as a string in the Identity field, whcih the Mitel phone then responds with an EAP response packet with an identity of MITEL.
    The other difference seems to be that a Version code of 3 is being used by the Catalyst but Version 1 by the HP and Mitel phone.
    Any ideas anyone?

  • 802.1x Dynamic VLAN Switching Question

    Trying to set up 802.1x dynamic VLAN switching, and have a question. I think I've gotten it working except for one part. The VLAN on a protected interface is never getting switched. I can see an entry in the ACS stating that it applied the appropriate VLAN via RADIUS response, but it never changes on the switch.
    Environment:
    ACS Express 5.0.1
    C3550 running c3550-ipbasek9-mz.122-44.SE6.bin
    Switch config:
    aaa new-model
    aaa group server radius dot1x
    server-private 10.10.1.4 auth-port 1645 acct-port 1646 key 7 071C244F5C0C0D544541
    aaa authentication dot1x default group dot1x
    dot1x system-auth-control
    dot1x guest-vlan supplicant
    interface FastEthernet0/3
    switchport access vlan 3
    switchport mode access
    speed 100
    duplex full
    dot1x pae authenticator
    dot1x port-control auto
    dot1x violation-mode protect
    dot1x timeout tx-period 5
    dot1x timeout supp-timeout 5
    spanning-tree portfast
    ip radius source-interface FastEthernet0/1 vrf default!
    radius-server host 10.10.1.4 auth-port 1645 acct-port 1646 key 7 01000307490E125E731F
    Am I missing something easy?

    It looks like "aaa authorization network default group dot1x" was the missing command I needed to get this working.
    The only issue I'm having now is that if the client fails to meet the authentication requirements, the line status gets set as "down"

  • Defining DNS on a 3550 switch

    I have three 3550 switches and want to define a DNS server on one of my switches (172.16.2.10). I have done the following in the DNS switch:
    3550(config)#ip domain-lookup
    3550(config)#ip host Setad 172.16.8.2
    3550(config)#ip host MAVAD 172.16.5.2
    3550(config)#ip domain-name cressnet.com
    I have done the following on the 172.16.5.2 (MAVAD) switch (one that is not a DNS):
    3550(config)#ip domain-lookup
    3550(config)#ip name-server 172.16.2.10
    3550(config)#ip domain-name cressnet.com
    In normal operation I can telnet from 172.16.5.2 to 172.16.8.2; but in this situation, when I issue the "Setad" to telnet Setad (172.16.8.2) from the 172.16.5.2, nothing happens.
    Please help!
    Thanks.

    Thanks for your reply.
    My DNS server switch hostname is "MUT-FIBER-SWITCH" and its IP address is 172.16.2.10. Look at the DNS configuration in this switch:
    MUT-FIBER-SWITCH#sh hosts
    Default domain is not set
    Name/address lookup uses domain service
    Name servers are 255.255.255.255
    Host Port Flags Age Type Address(es)
    Setad None (perm, OK) 44 IP 172.16.8.2
    MAVAD None (perm, OK) 0 IP 172.16.5.2
    I have set the following configuration in the MAVAD switch:
    MAVAD(config)#ip domain-lookup
    MAVAD(config)#ip name-server 172.16.2.10
    and
    MAVAD:#ping 172.16.2.10
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.16.2.10, timeout is 2 seconds:
    Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms
    and
    MAVAD:#ping 172.16.8.2
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.16.8.2, timeout is 2 seconds:
    Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
    and
    MAVAD:#telnet 172.16.8.2
    Trying 172.16.8.2 ... Open
    Welcome To Master Switch In SETAD
    Username: Malek
    Password:
    SETAD>exit
    but
    MAVAD:#Setad
    Translating "Setad"...domain server (172.16.2.10)
    % Unknown command or computer name, or unable to find computer address
    and
    MAVAD:#ping setad
    Translating "setad"...domain server (172.16.2.10)
    % Unrecognized host or address, or protocol not running.

  • AAA authentication is fail on cisco 4505 switch with acs

    i am new in AAA . i want to login switch which authentication come from cisco acs 5.1 but i configure both switch and acs 5.1. when i telnet
    switch it display % Authentication fails. can anybody help me regurding this issue!!!
    on cisco switch end conf:
    aaa new-modle
    aaa authentication  login default group tacacs+
    aaa authentication  login TACASE group tacacs+
    aaa authentication  exec default group tacacs+
    tacacs-server host 10.10.10.1
    tacacs-server key Password!@#
    line vty 0 4
    login  authentication TACASE
    on acs 5.1 side i add switch on its vlan ip address which is connect acs 5.1 but
    BUT when i login using putty terminal its show % Authentication fails.
    Please help me regurding this issue!!!

    Hi,
    what is the error message reported on ACS?
    Are you sure that you are using the same key on ACS and cat4k?
    Can you configure "ip tacacs source-interface " with the vlan interface you are using as source?
    You can also collect these debugs:
    - deb aaa authentication
    - deb tacacs
    Cheers
    Marco

  • 3550 Switch -Fiber interface VLAN question

    Hello,
    I will deploying two Cisco 3550 Switches and connecting them via a ordinary multimode fiber with GBIC 1000BASE-SX - transceivers installed on each switch. Here is my question: I will be configureing about half of the ports on each of the switches to be in one of two VLANS. I would like to configure the two vlans to run over the single fiber line. Is is possible to configure one fiber port, with the GBIC 1000BASE-SX - transceiver installed, with two vlans and/or subinterfaces each with half of the 1000mb of bandwidth, or will I need to run an additional fiber line connected to the second fiber interface on the 3550 to accomplish this. I really hope not to as I don't have the funds to run a second line at this time. If this configuration is possible could someone please point me to documentation on how to configure this and\or give some advice. Thank you.
    Regards,
    JPS

    Just set up the link as a trunk , this allows you to send as many vlans across that link as you want . On each side just do the following.
    switchport
    switchport trunk encapsulation dot1q
    switchport trunk mode dynamic desirable
    Verify trunk status with the "show int trunk " command.
    More info at http://www.cisco.com/en/US/products/hw/switches/ps5528/products_configuration_guide_chapter09186a00803a9af5.html#wp1200245

  • 802.1x between Switch 3750 and ACS 4.2 Authentication faild --need help

    I configured the Switch 3750 and ACS for 802.1x authentication.
    when I used the windows as the 802.1x client, it prompted "click here to enter user name and pasword for the network " as normal.
    The problem is that after I entered username and password (i am sure i enter the identical username and password as in ACS) the authentication failed,
    What is the most possibly problem?
    Thx in advance!!!
    The configuration is Sw3750 is:
    aaa new-model
    aaa authentication login default local
    aaa authentication enable default line
    aaa authentication dot1x default group radius
    aaa authorization network default group radius
    dot1x system-auth-control
    interface GigabitEthernet1/0/18
    description Link to test 802.1x
    switchport access vlan 119
    switchport mode access
    dot1x pae authenticator
    dot1x port-control auto
    spanning-tree portfast
    radius-server host 10.1.1.333 auth-port 1645 acct-port 1646
    radius-server source-ports 1645-1646
    radius-server key keepopen0
    In the ACS:
    Network Configuration -->aaa client ip address: 10.1.119.1(the vlan 119's ip address), shared secret: keepopen0
    user setup -->real name:test1, password: test1.
    Attached is the debug information

    What do you see in acs failed attempts?

  • Cisco switches and 802.1.x

    Hi, there !
    I have a question for you.
    Cisco all switches, is it impossible to present for 802.1x ?
    I try to put a network access server in our network to authenticate.
    Thanks.
    I will wait your answer.
    Regards.

    Most Cisco switches will handle 802.1x, but it depends on the switch and the OS. Which specific ones are you considering?
    Wes

  • 4500 Series Switches and 802.1x MAB

    My organization has multiple 4500 series switches experiencing the same problem when attempting to authenticate devices via MAB.  The issue is that the "show mab interface fax/x details" shows the Client MAC in a waiting status.  The device is never sending the switch it's MAC in order to proceed with MAB authentication, so of course the port never forwards traffic.  However, if we remove authentication port-control auto the port starts forwarding and the device gains connectivity.  Below is the interface configuration command and the MAB details.  The IOS version of this current switch is 15.0(2)SG8.  Are we missing something special for a 4500 as far as configuration is concerned.
    interface FastEthernet8/16
     description USER 
     switchport access vlan 600
     switchport mode access
     switchport nonegotiate
     duplex full
     authentication host-mode multi-domain
     authentication port-control auto
     authentication periodic
     mab
     dot1x pae authenticator
     dot1x timeout tx-period 5
    end
    SWITCH-4510R#sh mab interface fa8/16 details
    MAB details for FastEthernet8/16
    Mac-Auth-Bypass           = Enabled
    MAB Client List
    Client MAC                = Waiting
    Session ID                = 841AF6D100002931AF99B827
    MAB SM state              = ACQUIRING
    Auth Status               = UNAUTHORIZED

    hello,
    in my organization we have multiple 3560/2960 series switches and some 4500 with MAB.
    the interfaces have the following config:
     authentication host-mode multi-auth
     authentication order mab dot1x
     authentication priority mab dot1x
     authentication port-control auto
     authentication periodic
     authentication timer restart 120
     authentication timer reauthenticate server
     authentication timer inactivity 600
     mab
     dot1x pae authenticator
    Good luck

  • Wireless Virtual LAN - SSID and ACS User Mapping

    Hi Everybody
    We have the following senario:
    - WLC 4402 and ACS 3.3
    - 2 SSID's , One for Emploies - one for gests
    - All users are (guest and emploies) are authentication against the ACS Server.
    We would like to only permit Guest users to use the Guest SSID.
    I've been reading the Wireless Virtual LAN Deployment Guide :
    http://www.cisco.com/warp/public/cc/pd/witc/ao1200ap/prodlit/wvlan_an.pdf
    and have tried to use methode 1.
    - RADIUS-based SSID access control:
    "Upon successful 802.1X or MAC address authentication, the RADIUS server
    passes back the allowed SSID list for the WLAN user to the access point or bridge. If the user used an SSID on the allowed SSID list, then the user is allowed to associate to the WLAN. Otherwise, the user is disassociated from the access point or bridge."
    "This is configured by enableling the ?[026/009/001] cisco-av-pair? option. On the ACS Server
    - Enable and configure Cisco IOS/PIX RADIUS Attribute,
    009\001 cisco-av-pair
    - Example: ssid=LEAP_WEP"
    I've tried this, but regardless of wich SSID the user(-group) has configured, it sill can access all SSID's?
    Does anyone have any idea of what I'm doing wrong?
    Does this setting only apply to Accesspoint, or is it also valid for the WLC 44xx series?
    Greetings
    Jarle

    Hi I'm sorry but this still does not help.
    We have now upgraded ACS to version 4.0 and I'm still having the same problems.
    This is what i have configured:
    WLC:
    - WLAN
    - SSID : Public
    - WLAN id = 3
    - L2 Security : 802.1x
    - Interface Name : GuestVLAN
    - Controller - Interface
    - management - Untagged
    - GuestVLAN - VLAN 112
    - Security
    - RADIUS Servers
    When authenticating a Guest(belonging to the proper group in acs) - the right VLAN is used, IP Adresses from DHCP is recieved, and the Guest can access internet.
    Switch:
    - Port connected to WLC uses Trunking.
    - Guests are connected to VLAN 112 and "native VLAN" is used to connect the Private Users.
    ACS:
    - AAA Client is the WLC, Authenticating using Cisco Airespace
    - Guest Users are member of Group 11
    - Private Users are member of Group 1
    Group 11
    - Use Per Group NAR to only allow WLAN Access
    - Cisco Airespace RADIUS Attributes
    x 14179\001 - Aire-WLAN-ID = 3
    - Cisco IOS / PIX RADIUS Attributes
    x 009\001 Ciso-av-pair = "ssid=Public"
    - IETF Radius Attributes
    x 006 Service Type = Login
    x 007 Framed-Prot = ppp
    x 064 Tunnel-Type = VLAN
    x 065 Tunnel-Medium-tye = 802.1x
    x 081 Tunnel-Private-Group-ID = 112
    Group (default Group)
    - Cisco Airespace RADIUS
    x 14179\001 Aire-WLAN-ID = 1
    - Cisco IOS/PIX Radius Attrib
    x 009\001 Cisco-av-pair = "ssid=Private"
    - IETF RADIUS
    x 008 Service-type = Login
    x 064 Tunnel-Type = VLAN
    x 065 Tunnel-Medium-tye = 802.1x
    x 081 Tunnel-Private-Group-ID = 1
    Do you have any idea of what i should change?
    Greetings
    Jarle

  • 802.1x Authentication on Wired and Wireless LAN

    I have successfully configured 802.1x authentication on wired and wireless Lan. We have Cisco Switches, ACS SE and Windows AD.
    But i have one issue regarding the Single Sign on while authentication using the 802.1x with Windows Active directory the users that are login first time not able to logon but the users that have their profiles already existed in their PC then there is no issue and they successfully authenticated and login easily.
    Is there any way of login successfully for the users first time using 802.1x authentication with Windows AD like a Single Sign On?

    We ran into the same situation from time to time. We implemented 802.1x authentication using the Cisco Secure Services Client (SSC) on the windows hosts.
    At the beginning we were completly unable to logon on the maschines where no locally stored windows profile exists. After change to timeout to authenticate at the network in the SSC options we are able to logon to the network and also be authenticated by the domain controller.
    Sadly this works out often as a timing issue. Most times the user needs to try a couple of times. At the moment, I'm also very interessted in a good way to avoid this (as it seems to be) racecondition.
    Hope that someone else has any clue?

  • 802.1x with AD support via ACS 4

    Hello ,
    I have been trying to configure 802.1x Authentication on a test switch . Authentication will be provided by the ACS server . This worked when I had the client setup for EAP-MD5 and had local user accounts on the ACS server . However this is impractical if we were to deploy this on a large scale. How can i configure 802.1X authentication to occur via the ACS with the ACS looking at the AD database . The trouble is AD does not support EAP-MD5. It supports PEAP but the problem I am having is "EAP-TLS or PEAP authentication failed during SSL handshake "
    Has anyone here setup 802.1x with AD integration via ACS 4.0 . Please help.
    Thanks.
    Karthik

    Hi Karthik,
    The SSL handshake will fail in our experience for any of the following reasons:
    - The supplicant cannot access the private key corresponding to it's certificate - check that the system a/c has pemissions over the private key found in c:\documents and settings\all users\application data\microsoft\crypto\rsa\machine keys
    - The ACS sever does not trust the Root Certificate for the PKI that issued the supplicants certificate - Is the Supplicants Root CA present in the ACS Certificate Trust List?
    - CRL checking is enabled and the CRL has expired or is inaccessible
    If you up the logging levels to full and examine the csauth log closely you should get more detail as to the reason
    Hope that helps
    Andy

  • Assign VLAN from freeradius to Cisco 3550 Switch

    Hi All,
    I am trying to assign VLAN from freeradius to the a cisco 3550 switch but it's not working.
    I keep getting those lines in the cisco switch debug:
    3w6d: RADIUS:  Tunnel-Medium-Type  [65]  6   01:Unsupported            [6]
    3w6d: RADIUS:  Tunnel-Type         [64]  6   01:Unsupported            [13]
    What does it mean? Any idea how to solve this?
    Below freeradius conf and switch debug.
    Thanks.
    Configuration on freeradius users file:
    wassim    Cleartext-Password := "wassim"
            Tunnel-Medium-Type:1 = IEEE-802,
            Tunnel-Type:1 = VLAN,
            Tunnel-Private-Group-Id:1 = 100
    Cisco Switch debug log:
    3w6d: RADIUS:  authenticator 99 15 53 A6 AB B7 0B 75 - 9F A7 5F 27 8F F1 2E 67
    3w6d: RADIUS:  NAS-IP-Address      [4]   6   192.168.1.8              
    3w6d: RADIUS:  NAS-Port            [5]   6   50023                    
    3w6d: RADIUS:  NAS-Port-Type       [61]  6   Eth                       [15]
    3w6d: RADIUS:  User-Name           [1]   8   "wassim"
    3w6d: RADIUS:  Called-Station-Id   [30]  19  "00-15-F9-F8-4E-97"
    3w6d: RADIUS:  Calling-Station-Id  [31]  19  "00-1A-80-3F-F6-A1"
    3w6d: RADIUS:  Service-Type        [6]   6   Framed                    [2]
    3w6d: RADIUS:  Framed-MTU          [12]  6   1500                     
    3w6d: RADIUS:  State               [24]  18 
    3w6d: RADIUS:   DB C1 1C E7 DE C7 09 5E 75 5E 5B 0F 23 3A 54 E7  [???????^u^[?#:T?]
    3w6d: RADIUS:  EAP-Message         [79]  69 
    3w6d: RADIUS:   02 06 00 43 15 00 17 03 01 00 38 BF 71 FC FA 04  [???C??????8?q???]
    3w6d: RADIUS:   BE DC FD CC 03 D2 7F 8B 09 63 2C B2 AE D8 AC 61  [?????????c,????a]
    3w6d: RADIUS:   64 21 2B 00 ED 0E 6E E8 B0 49 50 6B 99 B8 88 A4  [d!+???n??IPk????]
    3w6d: RADIUS:   36 C6 FD B9 F0 77 2D 82 28 0A 37 D1 D4 73 B4 59  [6????w-?(?7??s?Y]
    3w6d: RADIUS:   F9 37 E6                                         [?7?]
    3w6d: RADIUS:  Message-Authenticato[80]  18 
    3w6d: RADIUS:   A2 59 A3 DE A6 98 5F 78 25 12 59 BB 4D B8 74 F0  [?Y????_x??Y?M?t?]
    3w6d: RADIUS: Received from id 1645/123 192.168.1.57:1812, Access-Accept, len 186
    3w6d: RADIUS:  authenticator C0 31 7F D7 A6 D4 1F C8 - 27 AA F0 99 EA 1F 92 C3
    3w6d: RADIUS:  Tunnel-Medium-Type  [65]  6   01:Unsupported            [6]
    3w6d: RADIUS:  Tunnel-Type         [64]  6   01:Unsupported            [13]
    3w6d: RADIUS:  Tunnel-Private-Group[81]  6   01:"100"
    3w6d: RADIUS:  Vendor, Microsoft   [26]  58 
    3w6d: RADIUS:   MS-MPPE-Recv-Key   [17]  52 
    3w6d: RADIUS:   86 8B 3E 74 76 E7 CB 9A 8F EF F5 9C 16 2E 88 1A  [??>tv????????.??]
    3w6d: RADIUS:   12 3B 80 A6 E9 9B B6 6F E6 63 C8 AA B0 DB 0E 76  [?;?????o?c?????v]
    3w6d: RADIUS:   61 C1 6A 5D 62 BD 72 BE 78 C8 9D 4D A7 3F 54 35  [a?j]b?r?x??M??T5]
    3w6d: RADIUS:   40 DC                                            [@?]
    3w6d: RADIUS:  Vendor, Microsoft   [26]  58 
    3w6d: RADIUS:   MS-MPPE-Send-Key   [16]  52 
    3w6d: RADIUS:   8A 61 97 87 78 FD CA 16 8D F0 ED 75 C0 70 93 AE  [?a??x??????u?p??]
    3w6d: RADIUS:   71 EF 5A 21 53 35 A4 88 F9 84 16 83 10 43 6E 9E  [q?Z!S5???????Cn?]
    3w6d: RADIUS:   AB A7 8B 56 6C 42 0D AB 09 1D 82 D3 CB 7E 6C B8  [???VlB???????~l?]
    3w6d: RADIUS:   56 58                                            [VX]
    3w6d: RADIUS:  EAP-Message         [79]  6  
    3w6d: RADIUS:   03 06 00 04                                      [????]
    3w6d: RADIUS:  Message-Authenticato[80]  18 
    3w6d: RADIUS:   82 4B 64 0F 07 64 59 18 0F 27 07 95 A5 15 09 33  [?Kd??dY??'?????3]
    3w6d: RADIUS:  User-Name           [1]   8   "wassim"
    3w6d: RADIUS: EAP-login: length of eap packet = 4
    3w6d: RADIUS: Tunnel-MType, [01] 00 00 06
    3w6d: RADIUS: TAS(1) created and enqueued.
    3w6d: RADIUS: Tunnel-Type, [01] 00 00 0D
    3w6d: RADIUS: Tunnel-GID, [01] 100
    3w6d: RADIUS: unrecognized Microsoft VSA type 17
    3w6d: RADIUS: unrecognized Microsoft VSA type 16
    3w6d: RADIUS: TAS(1) takes precedence over tagged attributes, tunnel_type=vlan
    3w6d: RADIUS: free TAS(1)
    3w6d: RADIUS: no appropriate authorization type for user.
    3w6d: RADIUS: Tunnel-MType, [01] 00 00 06
    3w6d: RADIUS: TAS(1) created and enqueued.
    3w6d: RADIUS: Tunnel-Type, [01] 00 00 0D
    3w6d: RADIUS: unrecognized Microsoft VSA type 17
    3w6d: RADIUS: unrecognized Microsoft VSA type 16
    3w6d: RADIUS: TAS(1) takes precedence over tagged attributes, tunnel_type=vlan
    3w6d: RADIUS: free TAS(1)
    3w6d: RADIUS: no appropriate authorization type for user.
    3w6d: RADIUS: Tunnel-MType, [01] 00 00 06
    3w6d: RADIUS: TAS(1) created and enqueued.
    3w6d: RADIUS: Tunnel-Type, [01] 00 00 0D
    3w6d: RADIUS: unrecognized Microsoft VSA type 17
    3w6d: RADIUS: unrecognized Microsoft VSA type 16
    3w6d: RADIUS: TAS(1) takes precedence over tagged attributes, tunnel_type=vlan
    3w6d: RADIUS: free TAS(1)
    3w6d: RADIUS: no appropriate authorization type for user.
    3w6d: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/23, changed state to up

    I believe you should be using the numerical values in your fields, look at this one :
    http://www.scribd.com/doc/75788651/52/X-with-VLAN-Assignment
    Tunnel-Medium-Type:1 = 6
    Tunnel-Type:1 = 13
    Tunnel-Private-Group-Id:1 =

Maybe you are looking for

  • Growing chart line, Flash CS4

    Hello, I want to make a growing line. Therefore I have an object without outlines that is angled like a stock exchange chart line. The object is imported (copy paste) from Illustrator. I tried with shape tween with the same object form (not the same

  • Imac has restarted with default settings?

    i  was  downloading flash player update  and did ,  then was asked to  restart firefox  which i did  then  the desktop  lost  all  icons  and  screen  looked like it did  when i  took it  out of the box  2 years ago,   all  music  is lost and recent

  • Server crash with -server option on Win2k

    We have observerd that the WL server crashes eventually when run with the Hopspot option. The performance gets really bad with -classic JVM. Do we have any work around for this , please ? Thx

  • IP - Rows defined individually, Columns dynamic for

    Hi, If I want to create a ready to input Query for my First Version of the year, I don´t have Actual Data, so I don´t have combination of characteristics. I need a blank template, I want to open 12 months of the year and  I know the GL Accounts that

  • 3 problems: please assist

    problem 1: I used to be able to command-select multiple images, drag a keyword to one of them, and have that keyword apply automatically to all images selected. Now, that doesn't work. The keyword (dragged from the HUD) only applies to the image to w