802.1x multiple sessions with same LOGIN+MAC on single-host port
We have 802.1x with radius server.
c2960 configured to allow only one device per port with no Mac-Bypass and no critical auth.
From time to time user seems to get multiple authentications on single port with single mac-address.
So we get several sessions on port with the same login, mac (but different session-id).
Command "dot1x re-auth int" doesn't clear those sessions. Neither do "force-unauthorized" or "shut/noshut". Only thing that helps is reboot switch.
Happens with different users.
Anybody seen this issue?
IOS 12.2(46)SE
Sure. Tried to make it short.
Config for 802.1x-aaa:
aaa new-model
aaa group server radius default
server X.X.X.X auth-port 12345 acct-port 12346
aaa authentication login default group radius enable
aaa authentication dot1x default group radius
aaa authorization exec default group radius if-authenticated
aaa authorization network default local group radius
aaa authorization reverse-access default group radius
aaa accounting suppress null-username
aaa accounting update periodic 1
aaa accounting dot1x default start-stop group radius
aaa accounting exec default start-stop group radius
aaa accounting network default start-stop group radius
aaa accounting system default start-stop group radius
aaa session-id common
dot1x system-auth-control
interface FastEthernet0/48
switchport access vlan 1398
switchport mode access
dot1x pae authenticator
dot1x port-control auto
dot1x violation-mode shutdown
spanning-tree portfast
spanning-tree link-type point-to-point
radius-server attribute 44 include-in-access-req
radius-server attribute 44 extend-with-addr
radius-server attribute 188 format non-standard
radius-server attribute 218 mandatory
radius-server attribute 32 include-in-accounting-req format %i %h %d
radius-server attribute 55 include-in-acct-req
radius-server attribute list att
attribute 30-31,44
radius-server host X.X.X.X auth-port 12345 acct-port 12346 key keykeykey
radius-server vsa send accounting
sh dot1x int fa 0/48 det
Dot1x Info for FastEthernet0/48
PAE = AUTHENTICATOR
PortControl = AUTO
ControlDirection = Both
HostMode = SINGLE_HOST
Violation Mode = SHUTDOWN
ReAuthentication = Disabled
QuietPeriod = 60
ServerTimeout = 0
SuppTimeout = 30
ReAuthPeriod = 3600 (Locally configured)
ReAuthMax = 2
MaxReq = 2
TxPeriod = 30
RateLimitPeriod = 0
Dot1x Authenticator Client List Empty
Port Status = UNAUTHORIZED
And right now, while port is UNAUTHORIZED we have 2 sessions as follows:
sh aaa user all
Unique id 34974 is currently in use.
Accounting:
log=0x208241
Events recorded :
CALL START
ATTR REPLACE
NET UP
INTERIM START
VPDN NET UP
update method(s) :
PERIODIC
update interval = 60
Outstanding Stop Records : 0
Dynamic attribute list:
0244DC34 0 00000001 connect-progress(44) 4 Auth Open
0244DC48 0 00000001 pre-session-time(272) 4 0(0)
0244DC5C 0 00000001 elapsed_time(339) 4 4828941(49AF0D)
0244DC70 0 00000001 input-giga-words(111) 4 2(2)
0244DC84 0 00000001 output-giga-words(250) 4 8(8)
024A8C10 0 00000001 bytes_in(112) 4 119041621(7186E55)
024A8C24 0 00000001 bytes_out(252) 4 3588031221(D5DD02F5)
024A8C38 0 00000001 pre-bytes-in(268) 4 7373(1CCD)
024A8C4C 0 00000001 pre-bytes-out(269) 4 8204(200C)
024A8C60 0 00000001 paks_in(113) 4 45940138(2BCFDAA)
024A8CB0 0 00000001 paks_out(253) 4 46979788(2CCDACC)
024A8CC4 0 00000001 pre-paks-in(270) 4 68(44)
024A8CD8 0 00000001 pre-paks-out(271) 4 61(3D)
No data for type EXEC
No data for type CONN
NET: Username=(n/a)
Session Id=000088AD Unique Id=0000889E
Start Sent=0 Stop Only=N
stop_has_been_sent=N
Method List=0
Attribute list:
024CAA00 0 00000001 session-id(336) 4 34989(88AD)
024CAA14 0 00000001 start_time(342) 4 Jan 23 2012 16:22:08
No data for type CMD
No data for type SYSTEM
No data for type RM CALL
No data for type RM VPDN
No data for type AUTH PROXY
8: Username=157102
Session Id=000088AD Unique Id=0000889E
Start Sent=1 Stop Only=N
stop_has_been_sent=N
Method List=226B3E4 : Name = default
Attribute list:
0244DB94 0 00000001 session-id(336) 4 34989(88AD)
0244DBA8 0 00000001 start_time(342) 4 Jan 23 2012 16:22:08
0244DBBC 0 00000009 audit-session-id(599) 24 0AC5010200001C45A5C67429
No data for type IPSEC-TUNNEL
No data for type RESOURCE
No data for type 11
No data for type 12
No data for type CALL
No data for type VPDN-TUNNEL
No data for type VPDN-TUNNEL-LINK
Debg: No data available
Radi: 2032FD8
Interface:
TTY Num = -1
Stop Received = 0
Byte/Packet Counts till Call Start:
Start Bytes In = 993512241 Start Bytes Out = 3867828098
Start Paks In = 23586320 Start Paks Out = 28511581
Byte/Packet Counts till Service Up:
Pre Bytes In = 993519614 Pre Bytes Out = 3867836302
Pre Paks In = 23586388 Pre Paks Out = 28511642
Cumulative Byte/Packet Counts :
Bytes In = 1112561235 Bytes Out = 3160900227
Paks In = 69526526 Paks Out = 75491430
StartTime = 16:22:08 GMT+5 Jan 23 2012
AuthenTime = 16:22:08 GMT+5 Jan 23 2012
Component = DOT1X
Authen: service=8021X type=EAP method=RADIUS
Kerb: No data available
Meth: No data available
PreA: No data available
General:
Unique Id = 0000889E
Session Id = 000088AD
Attribute List:
024A8C10 0 00000001 port-type(174) 4 Ethernet
024A8C24 0 00000009 interface(170) 16 FastEthernet0/48
024A8C38 0 00000009 dnis(50) 17 00-18-B9-F5-5B-30
024A8C4C 0 00000009 clid(37) 17 48-5B-39-EA-26-7C
PerU: No data available
Unique id 34976 is currently in use.
Accounting:
log=0x10000208241
Events recorded :
CALL START
ATTR REPLACE
NET UP
INTERIM START
VPDN NET UP
SESSION INFO
update method(s) :
PERIODIC
update interval = 60
Outstanding Stop Records : 0
Dynamic attribute list:
024CAA00 0 00000001 connect-progress(44) 4 Auth Open
024CAA14 0 00000001 pre-session-time(272) 4 2(2)
024CAA28 0 00000001 elapsed_time(339) 4 4828961(49AF21)
024CAA3C 0 00000001 input-giga-words(111) 4 2(2)
024CAA50 0 00000001 output-giga-words(250) 4 8(8)
024CAAA0 0 00000001 bytes_in(112) 4 119021816(71820F8)
024CAAB4 0 00000001 bytes_out(252) 4 3588011179(D5DCB4AB)
024CAAC8 0 00000001 pre-bytes-in(268) 4 6219(184B)
024CAADC 0 00000001 pre-bytes-out(269) 4 7005(1B5D)
024CAAF0 0 00000001 paks_in(113) 4 45939933(2BCFCDD)
0244DB94 0 00000001 paks_out(253) 4 46979618(2CCDA22)
0244DBA8 0 00000001 pre-paks-in(270) 4 59(3B)
0244DBBC 0 00000001 pre-paks-out(271) 4 51(33)
No data for type EXEC
No data for type CONN
NET: Username=(n/a)
Session Id=000088AF Unique Id=000088A0
Start Sent=0 Stop Only=N
stop_has_been_sent=N
Method List=0
Attribute list:
024A8C10 0 00000001 session-id(336) 4 34991(88AF)
024A8C24 0 00000001 start_time(342) 4 Jan 23 2012 16:22:18
No data for type CMD
No data for type SYSTEM
No data for type RM CALL
No data for type RM VPDN
No data for type AUTH PROXY
8: Username=157102
Session Id=000088AF Unique Id=000088A0
Start Sent=1 Stop Only=N
stop_has_been_sent=N
Method List=226B3E4 : Name = default
Attribute list:
024CAA00 0 00000001 session-id(336) 4 34991(88AF)
024CAA14 0 00000001 start_time(342) 4 Jan 23 2012 16:22:18
024CAA28 0 00000009 audit-session-id(599) 24 0AC5010200001C49A5C6990F
No data for type IPSEC-TUNNEL
No data for type RESOURCE
No data for type 11
No data for type 12
No data for type CALL
No data for type VPDN-TUNNEL
No data for type VPDN-TUNNEL-LINK
Debg: No data available
Radi: 2032F58
Interface:
TTY Num = -1
Stop Received = 0
Byte/Packet Counts till Call Start:
Start Bytes In = 993533200 Start Bytes Out = 3867849339
Start Paks In = 23586534 Start Paks Out = 28511761
Byte/Packet Counts till Service Up:
Pre Bytes In = 993539419 Pre Bytes Out = 3867856344
Pre Paks In = 23586593 Pre Paks Out = 28511812
Cumulative Byte/Packet Counts :
Bytes In = 1112561235 Bytes Out = 3160900227
Paks In = 69526526 Paks Out = 75491430
StartTime = 16:22:18 GMT+5 Jan 23 2012
AuthenTime = 16:22:19 GMT+5 Jan 23 2012
Component = DOT1X
Authen: service=8021X type=EAP method=RADIUS
Kerb: No data available
Meth: No data available
PreA: No data available
General:
Unique Id = 000088A0
Session Id = 000088AF
Attribute List:
0244DB94 0 00000001 port-type(174) 4 Ethernet
0244DBA8 0 00000009 interface(170) 16 FastEthernet0/48
0244DBBC 0 00000009 dnis(50) 17 00-18-B9-F5-5B-30
0244DBD0 0 00000009 clid(37) 17 48-5B-39-EA-26-7C
PerU: No data available
PS. Have no command "show authentication"
Similar Messages
-
Multiple clients with same account on a single IMAP server
Hi,
I am connecting to a IMAP server using same account but from 2 different machines. From one machine a mark a message as SEEN=FALSE. But on the second machine, the flag will still be TRUE.
Is there any way to co-ordinate between multiple clients so that all the clients are in sync.
Regards,
Nitin.I was able to resolve the problem using addMessageCountListener and messagesAdded method, as suggested by you.
I am now facing another problem. Whenever a new message is received, code inside messagesAdded method gets executed. Here I am trying to spawn another thread and do some stuff. But this new thread is not starting at all. It goes into some JavaMail:EventQueue and does nothing. What is the concept of EventQueue here? How can I get this new thread executed?
Also will there be synchronization problems in messagesAdded method. Say I received a message and I am processing it in the messagesAdded method. In the mean time another message comes up. How will this behave. -
Are Multiple Classes with Same name in a single Class valid ?
package inheritance;
interface Foo
int bar();
public class Inh6 {
class A implements Foo // THis is the first class
public int bar()
return 1;
public int fubar(Foo foo)
return foo.bar();
public void testFoo()
class A implements Foo // THis is the second class
public int bar()
return 2;
System.out.println(fubar(new A()));
public void testFooModified()
class A implements Foo // THis is the first class
public int bar()
return 4;
System.out.println(fubar(new A()));
public static void main(String[] args) {
new Inh6().testFoo();
new Inh6().testFooModified();
O/P :
2
4My question is this class "A" which is present in the different methods like testFoo() and testFooModified() different declarations of the same class or altogether different classes local to each method,something like err...Local Class ?
Thanks in Advance.kajbj wrote:
My question is this class "A" which is present in the different methods like testFoo() and testFooModified() different declarations of the same class Why would it be the same class? They have different scopes.
KajSo you mean to say they are actually different classes with the same name,which will be invisible out of the respective methods in which they are defined ?
Thanks. -
While send/receive email, I have received an error message "Sending of password d"?
However with same login details, I am able to login with other application.
I have changed password still the issue remains as it is.https://support.mozilla.org/en-US/kb/cannot-send-messages
-
Read multiples files with same extension
how to read multiples files with same extension in java.
for ex : i would like to read all .DAT files from C drive using java.
How is it done- You create the filter
- You get the list of files
- You open and read each file.
For the first two above you look at java.io.File and listFiles(FileFilter filter).
For the third you find whatever input stream is appropriate from java.io.* -
Multiple accounts with same email
I have multiple accounts with same email
The one that has all my contacts is the one attached to FB but for some odd reason I can no longer access this specific account
When I try to reset my password, it only keeps asking me to change my FB password
Once I try logging in on Skype, it keeps asking my FB to connect to the other 2 Skype accounts, completely diffente usernames
I am only interested in the one that originally connected to my FB as it has all my contacts
As my other 2 accounts are my old Skype accounts and have my old contacts from years agoActually this morning I was able to log on the account from an iPad with no fuss but the pc refuses to sign in^^^!???! "Skype couldn't connect" - What is going on???
I also found out that I could sign in via a browser but not via skype program... So I uninstalled it and installed it again and it's working now...
I have now changed the email so I don't have 3 accounts with the same primary email as Skype seems to not being able to handle multiple accounts with same email!!! -
Multiple members with same alias
I have multiple members with same alias name. Are there anyway to build dimension members with same alias name?
Typically I will concatinate the member name (as either a prefix or suffix ) to the Alias to make it unique
-
We have a requirement where in we have multiple solaris servers and each solaris server has a directory with the same name.
The files in these directories will be different.
These same name directories on multiple severs has to be mounted to a single directory on another sever.
We are planning to use NFS, but it seems we can not mount multiple directories with same name on different severs to a single mount point using NFS, and we need to create multiple mount points.
Is there any way we can achieve this so that all the directories can be mounted to a single mount point?You can try to mount all these mount points via NFS in one additional server and then export this new tree again via NFS to all your servers.
No sure if this works. If this works, then you will have in this case just an additional level in the tree. -
Multiple accounts with same email can't acces original account
ok, so i created a new skype. I was messing with skype account on my desktop and wound up unlinking and re linking the account basically i made 2 extra accounts and they have my live: random.namehere_1 and live: random.namehere_2 and i cant log into my original one anymore also when i try to do a recovery it says i have 2-3 skype accounts on my email and i cant log into my accounts by typing in the live:random.namehere and the password it just says ooops something went wrong basicallly saying the pw and account name are wrong when they arent i made sure of it. so how do i eliminate the cloned accounts and log into the main one.
Actually this morning I was able to log on the account from an iPad with no fuss but the pc refuses to sign in^^^!???! "Skype couldn't connect" - What is going on???
I also found out that I could sign in via a browser but not via skype program... So I uninstalled it and installed it again and it's working now...
I have now changed the email so I don't have 3 accounts with the same primary email as Skype seems to not being able to handle multiple accounts with same email!!! -
Unable to monitor two databases with same name on two different hosts
I have got two databases with same name on two different hosts. I added one database to the list of monitored databases. Now If I try to add the other one , I get the message that the database is already being managed.
Can't we monitor two databases with same name on two different hosts?you can... while saving the target,give a different name.. for eg target-2
-
Multiple sessions with Viewer 3.3.61
Hi,
I have Discoverer Server set up on a single machine, using OAS as the HTTP server, and Viewer 3.3.61.
If a user tries to run 2 queries at the same time (opens up two browser windows), one of the queries will be cancelled (usually te first query started).
Why is this? Is this normal functionality, or do I need to set something up for multiple sessions? If I need to set something up, where can I find documentation?
Thanks,
Suzanne
nullSuzanne,
I think this is normal for Discoverer. It seems to be that there is a session for each user login. Thus a single query for each login. This is just my observation.
Christopher -
Multiple files with same name--- automatic renaming option??
I am trying to sort my files by adding multiple files to a single folder. However, many have the same filename, and I get the error " there already exists a file with the name "x", please choose another name" etc. I am dealing with thousands of files here that are very tedious to rename individually. Is there an option or program that either disables this block on multiple files with the same name in a common folder, or automatically renames the files as they are placed in the folder?
i would like all the files to have different names, but not have to do it myself. they are generated my my audio recorder, which automatically names files take1, take2, take3 etc. multiple sessions entail multiple folders, i am trying to consolidate.
-
ARD won't save multiple computers with same IP and different port!
I'm trying to access multiple computers over the internet behind a firewall with port forwarding.
I can access each computer, but ARD won't save the IP address and port (in IP Address column of ARD 3.1) of multiple computers with the same IP address. It will only save ONE. I've tried 'add by address', adding a list for each computer or adding a list for all those computers. Nothing has worked. ARD will actually change the first computer's IP address to 0.0.0.0
Example: Static IP address
Computer 1 xx.xxx.xxx.xxx:51 (public port 51 is forwarded to port 5900 on computer 1)
Computer 2 xx.xxx.xxx.xxx:52 (public port 52 is forwarded to port 5900 on computer 2)
Computer 3 xx.xxx.xxx.xxx:53 (public port 53 is forwarded to port 5900 on computer 3)
Has Apple really overlooked this or am I missing something? Isn't this how most people would remotely manage multiple Macs offsite?
ThanksARD cannot do this as you're asking. If your
workstations get their addresses from an NAT device
rather than being "real", the ports also need to be
forwarded in the router to the workstation's internal
IP address. ARD uses port 3283 for the reporting and
updating function, so if your Macs are getting their
IP addresses through NAT, since you can only forward
a port to a single workstation, you can only get
reports, push package/files to etc. for a single
workstation.
ARD uses the VNC protocol for observation and
control, though, and there are a range of IP
addresses for that protocol, starting with 5900. ARD
uses 5900 by default, so that port would be forwarded
to the first workstation. You would, I believe, need
to install VNC servers on the systems (since the ARD
client cannot listen on any port other than 5900
while VNC servers can be set for other ports such as
5901, 5902, etc. You would then forward 5901 to the
second workstation (and on to 5902, 5903, etc.). You
can then use the following information:
Remote Desktop 2: How to specify a port number
for a VNC client
to connect.
The only other options are: 1) to run the ARD
administrator on a workstation on the network, and
then take control of that system from outside, either
via VNC or another copy of ARD, or 2) set up a
virtual private network (VPN) so that when you
connect from outside, your admin system is officially
part of the local network.
Hope this helps.
That definitely helps. I have ARD installed on my MBP and on a workstation on the LAN. I have used ARD from the MBP to control ARD on a workstation on the local network, but it can get a little tricky. I already have VNC setup on all the workstations. I used to use COTVNC prior to purchasing ARD 3.1.
I guess what I'm really asking is...
How do I add a list of workstations and save the settings (same IP address for each workstation with different ports?) to control/VNC via ARD?
I simply want a list that shows each workstation, so I can control/VNC them using ARD offsite.
Name: Computer 1 IP Address: 123.123.123.123:5901
Name: Computer 2 IP Address: 123.123.123.123:5902
Name: Computer 3 IP Address: 123.123.123.123:5903
I don't want to have to manually type in the IP address into ARD every time.
Will ARD simply not add another computer to the list if it has the same IP address but different port number as a computer already on the list? I haven't been able to find a way to make ARD do this. -
Hi,
Running 10.7.5, Mail version 5.3, I find that I cannot save multiple messages with the same subject line when I want to store them for sending to different people later. It automatically deletes the older message and only saves the new one.
Any idea/help? Can't find it online or using Macs's Help program. They are NOT being stored on my mail server, just checked.
Thanks!I am experiencing exactly the same problem. Mail will not keep multiple email drafts with the same subject line, although they are addressed to different people. At one point, I had drafted and saved a dozen or so such messages intending to send them later only to discover that Mail had deleted all of them but one. Have you received any help or guidance on this? I'm baffled. This did not happen with previous Mail versions.
-
Bridge CS4 won't output to pdf multiple images with same filename
Hiya...my googling efforts have thus far failed!
I've got CS4, and in Bridge, I created a New Smart Collection to find all filenames in a folder containing "." or ".jpg" - which in turn searched through all the subfolders like what you used to be able to do in Photoshop CS3. Very simple stuff, but all the images are jpg's, but in multiple folders (I don't want to move them out of the folders, as the files came from an external source, and there are heaps of folders, and I don't want to pdf each subfolder seperately as it will take forever).
The problem is that some of the files have the same filenames (again I'd prefer not to rename, as it happens a lot on this project, and they are all over the place). So whilst Bridge will show the thumbnail images correctly in the content tabbed screen in my New Smart Collection, but once I've done the Output to PDF thing, for example, instead of showing both different images it has pdf only the first image but repeated it twice. And this happens multiple times throughout the pdf, the more times the same filename is used, the more times the first image gets repeated.
I know that it is messy to have multiple similar filenames, but why can't bridge just place the image anyway? It allocated a space for it on the pdf and does show it in bridge, it just doesn't seem to survive the transfer to pdf well.
The only other thing that I have done is use the below link (which was posted on another adobe forum thread) to create a custom pdf output template (nothing too fancy, just number of rows / columns, size, font etc). But I've tried using the standard bridge templates and it does the same thing.
http://www.proficiografik.com/2009/08/03/save-custom-pdf-output-template-in-adobe-bridge-c s4.html
Any help would be appreciated...even if to tell me that I am being unreasonable!
UPDATE 16/11/09
Just to let you know that I seem to have resolved the bug inadvertently with one of the Adobe updates. The below is the link for the AdobeOutputModule-2.1-mul-AdobeUpdate.zip which was released on 2/19/2009 - which allows for headers & footers to be placed in the Ouput pdf. I finally installed it today, and everything seems to be working fine now (i.e. I can pdf multiple images with the same filenames and the pdf will actually show each different image rather than repeating only 1 of the images).
Must have been a fix installed in the contact sheet templates that get installed with the update - not sure why the original version was corrupted, but I've left that with the Adobe guys (I submitted a bug report - and they were able to replicate the problem but hadn't fixed it as yet).
http://www.adobe.com/support/downloads/detail.jsp?ftpID=4228
Message was edited by: djtun71 (16/11/09)When I click import from disc I am asked to choose a disc and then I get this message:
The following photos will not be imported because they are already present in the catalog. To see these photos in the catalog select 'Show in Library' (the import will be canceled).
This is followed by a long list of images. If I click 'Show in Library' I can see all the images with the same filename. And then they start to automatically write over those images with images from the disc. However they keep the same metadata and keywords from the previous images. If I click on Import and deselect the "don't reimport suspected duplicates" box, it imports only the images that don't share filenames and none of the images that do.
Is there a way of setting the "Don't reimport suspected duplicates" box in preferences?
Maybe you are looking for
-
J'ai un hp envy 17 notebook E4S12Uacarré ABL j'avais intallé windows 8.1 J'ai reçu de microsoft une mise a jour facultative concernant VDDM 1.1 1.2 1.3 au redémarage l'écran est devenu noir impossible d'ouvrir windows j'ai fait une réinstallation ave
-
Specify database field's name dynamically in a select statement
Hi to all!! I have the following problem: I got a paraneters statement where the user is to choose the month of the year,once i have the month, i need to make a query on a database(select field_name) of a field whose name deppend on the month that th
-
Hi there, I have created a simple excel report using an OData feed which shows the total cost per project and also the total baseline cost per project. The projects themselves are made up of summary tasks with sub tasks within them. The problem I hav
-
Hi all, My client requirement is to check the pending Miro at the time of Migo. The flow is when end user doing migo, if there is any miro pending for any migo at plant level then the system should propose an error. is it possible in standard or i ha
-
Where i could customize Transaction/event type for movement type?
I need to get table behind of "transaction/event" (mkpf-vgart) type for material movement... Ex. i have movement type 101, where i could check/get transaction/event type (mkpf-vgart) for it? I know that it is 'WE' but where i could get link table be