802.1x not saving authentication details

Hey all,
We're having a small issue with this.
We have an 802.1x implimentation working successfully, devices can connect and have correct network access etc.
The issue we have is that from IOS 4.3 upwards, the authentication details aren't being saved for the wireless connection.
Users are able to connect to the SSID, accept the certificate and login with domain credentials - but when the phone autolocks and the network disconnects it drops the authentication details, so users have to reconnect to the SSID manually and input username / password again.
So I'm wondering if this is by design in 4.3 upwards?
IOS 4.2.1 saves the credentials and automatically reconnects when the device is unlocked (which is how i expected 4.3 to behave)?
Appreciate any information anybody has on this.

Your RADIUS server needs to send the VSA Cisco-AV-Pair "device-traffic-class=voice" so that the switch puts the switch port into the voice domain to activate the Voice VLAN from the phones.  Having your phones fall to the data domain is a classic problem of the missing VSA.  Additionally, you want to have the switch port fail open for voice devices to "save the phones" in a server-dead scenario as well as provide users with an option to get to the critical VLAN:
authentication event server dead action authorize vlan 205
authentication event server dead action authorize voice
If a RADIUS server fails to respond, the switch will authorize the static voice VLAN.
Don't do "authentication periodic" for with IP phones.  This can cause disruptions in an existing phone conversation as during authentication, the phone will lose network access until authentication succeeds (or a server dead event).
You will also want to provide a way to get users out of the auth-fail VLAN, guest VLAN, or critical VLAN (for you and I these are the same usually, your VLAN 205) if your dead server returns, and have the switch rerun dot1x:
authentication even server alive action reinit
Good luck!

Similar Messages

  • WPA2Enterprise not saving authentication password.

    EDIT: Ignore, solved. Just hadn't correctly installed gnome-keyring so it wasn't storing the password
    Last edited by kaijday (2014-02-05 12:41:16)

    Tartan Terror,
    Try updating to 1.1.4, and then remove the email account from settings, and re-add it completely, not just adding the password to the existing settings.
    Hope this helps,
    Nathan C.

  • Rule Author--Rules/Fact Not saving

    Hi', All
    I don’t know what is the problem with Rule repository, It is not saving the details properly, It is only saving details up till dictionary name and version, all the rules which I create are not saving (I am saving the rules and every thing after any change with “Save dictionary”),
    this is happening when I am following Car-rental sample,” http://download.oracle.com/docs/cd/B32110_01/web.1013/b28965/guistart.htm”
    Thanks
    Yatan

    Oddly, I'm having a similar problem.
    I've set up a rule to copy a message to an IMAP account. This works fine - until I close Mail (v3.6). When I next launch it, it has CHANGED the location to a local mailbox. Weird!
    Dow

  • Sg300 - 802.1x NPS - mac authentication not working

    I configured 802.1x on a sg300 switch. It is working very well with some Windows 7 machines and a Windows Server 2008 NPS server.
    Now I tried to get the MAC authentication running, on a 3850X it is working without problems, but every access request sent from the SG300 is declined.
    My current port configuration on the SG300:
    interface fastethernet1
     dot1x guest-vlan enable
     dot1x max-req 1
     dot1x reauthentication
     dot1x timeout quiet-period 10
     dot1x authentication 802.1x mac
     dot1x radius-attributes vlan static
     dot1x port-control auto
     switchport mode access
    On the Windows NPS server there is following error to see:
    Authentication Details:
        Connection Request Policy Name:    Secure Wire
        Network Policy Name:        -
        Authentication Provider:        Windows
        Authentication Server:        myradius.local
        Authentication Type:        -
        EAP Type:            -
        Account Session Identifier:        30353030399999
        Reason Code:            1
        Reason:                An internal error occurred. Check the system event log for additional information.
    There is compared to the message from the 3850 the authentication type missing (PAP) and a not very helpful error message displayed...

    Still not working.
    I tried different settings and (also older) software versions on the SF302-08P.
    Also started to change the settings on the NPS (though it is working with the 3850X!), without success.
    The NPS reports following error:
    Schannel:
    The following fatal alert was received: 40.
    EventID 36887
    If I search for this error, every source is pointing to certificate errors, but there should not be any certificate involved?!
    ... is this a bug on the SF302-08P?

  • Browsers do not remember realm authentication details

    Hello,
    When I try to access pages in a protected realm, I sometimes have to enter the username nad password 5 or more times. Sometimes just twice. Even if I tell my browser to remember the password/username, it still prompts me to authenticate later on. I don't think it's a browser problem because this affects Safari, Firefox (win and mac) and Internet Explorer.
    Why would it try to authenticate so many times? And why doesn't it remember the authentication details? Would the webserver be sending out a different kind of identification ( or whatever?) each time, so the browser thinks it's a different site? (Perhaps related to that 16080 cache?)
    Thanks for your suggestions
    -Woody

    Since it's affecting multiple browsers it has to be something server-side.
    Realms are keyed off both the hostname and the URI in combination with the realm name. You should look at the URLs in question, make sure they all have the same realm name assigned, and check the web server logs to see what the server is saying about the authentication (e.g. look for any 'authentication failed' messages).
    It is also true that the performance cache (:16080) port can affect this if you're using redirects since http://www.yoursite.net/ and http://www.yoursite.net:16080/ are completely different sites as far as the browser is concerned, and therefore would require separate sign-ins. Try turning off the performance cache to see if that helps.

  • Password not saved in PowerPivot 2012

    Hi
    We facing problems using the 2012 version of PowerPivot. The password for the connection to SQL Server is not saved anymore! We previous used the 2008 version without any problem, now we want to upgrade to 2012 but this issue is holding this.
    We use PowerPivot as an offline version and users update there data by refresing the powerpivot. When done in 2012 version, the user is asked to enter the password for the SQL connection. We can't have endusers to enter the PW. It might be reported as a
    bug in 2012 already but no solution yet.
    Anybody?
    Thanks

    Hi Bertil,
    It seems you encountered the similar issue in the thread below:
    SQL Server Authentication connection don't retain password in PowerPivot for Excel 2010:
    http://social.technet.microsoft.com/Forums/sqlserver/en-US/b1164973-36d7-4bb7-827a-f64b63584701/sql-server-authentication-connection-dont-retain-password-in-powerpivot-for-excel-2010
    I have tried to reproduce this issue using Excel 2010 and Excel 2013 again SQL 2008R2 and SQL 2012, but everything were fine. If you can provide the following detail information to us, I will reproduce it again and help you to solve this issue.
    Could you please share the detail steps to reproduce this issue?
    What're the specific versions of SQL Server and PowerPivot for Excel?
    Regards,
    Elvis Long
    TechNet Community Support

  • The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server

    wireless authentication not working 
    I found the following in the radius
    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          1/15/2014 2:07:57 AM
    Event ID:      6273
    Task Category: Network Policy Server
    Level:         Information
    Keywords:      Audit Failure
    User:          N/A
    Computer:     NAP01.test.local
    Description:
    Network Policy Server denied access to a user.
    Contact the Network Policy Server administrator for more information.
    User:
     Security ID:   doamin \user.a
     Account Name:   user.a
    Client Machine:
     Security ID:   NULL SID
     Account Name:   -
     Fully Qualified Account Name: -
     OS-Version:   -
     Called Station Identifier:  00-0F-7D-C4-45-20:staff
     Calling Station Identifier:  0C-74-C2-EF-Dd-0B
    NAS:
     NAS IPv4 Address:  192.168.9.10
     NAS IPv6 Address:  -
     NAS Identifier:   -
     NAS Port-Type:   Wireless - IEEE 802.11
     NAS Port:   497
    RADIUS Client:
     Client Friendly Name:  wcont1
     Client IP Address:   192.168.9.10
    Authentication Details:
     Connection Request Policy Name: Wireless
     Network Policy Name:  wism
     Authentication Provider:  Windows
     Authentication Server:  NAP01.test.local
     Authentication Type:  EAP
     EAP Type:   -
     Account Session Identifier:  -
     Logging Results:   Accounting information was written to the local log file.
     Reason Code:   22
     Reason:    The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.
    Please help

    Hi,
    Anything updates?
    In addition, this issue may also because your client didn't have CA certificate of your domain. Please make sure that your client has CA certificate.
    Besides, the error "The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server" may be due to that the default maximum transmission unit that NPS uses for EAP payloads is 1500
    bytes. You can lower the maximum size that NPS uses for EAP payloads by adjusting the Framed-MTU attribute in a network policy to a value no greater than 1344:
    Configure the EAP Payload Size
    Best regards,
    Susie

  • ReportViewer Parameter area state not saved without to refresh in ie

    Hi from Germany,
    we have created a master detail report with 3 levels and some parameters defined. Connected are these 3 reports by drill throughs with "go to report"-actions. We use the report manager for the navigation to the reports.
    For a faster go back from a detail report to its higher level report again we added links in the header with go to url actions and the expression "javascript:history.go(-1)").
    It works great but in the ie (version 10 and 11, too) there is a not wanted behavior after the user has updated the parameter values and clicked on "Show report". The report is rendered now with the changed parameters fine BUT the parameter area
    is still opened.
        First question: Is there a way to collapse the parameter area also with the click on "Show report"-Button?
    Now users close often the parameter section and drill through to the next level report. When you go from there back (history.go(-1) or also with the browsers back-button) the report before opens but again with an displayed parameter area. It forgots that users
    have collapsed it before.
        2nd question: It seems that the last state with the closed parameter area was not saved (in the session?). Can someone explain me why and if there is a way to solve it?
    In firefox it works like we wanted. There is the parameter area collapsed automaticly after go back in history. It seems it is realy a bug in the ie.
    I have found out a workaround:
    when you close the parameter area in ie and click after it on the refresh-button on the reportviewer-toolbar then the collapsed state is registered and go back to this report opens it right with collapsed parameters. Also a refresh by the browser-button opens
    the report with collapsed parameters.
    It seems for me it is a bug, isn't it?
    Kind regards
    René
    René

    Hi René,
    If I understand correctly, you want to hide the parameter area when the report render in report server. I have create a simple report to test, however, I cannot reproduce the same issue.
    Based on my test, it has two situation when we go to subreport the parameter area cannot hide.
    If we are use “Go to URL” action jump to the subreport, it will not hide the parameter area.
    We have not pass the parameter value to the subreport, it will display the parameter area for us to choose parameter value.
    If you are not above situation, we can use “Go to URL”
    action to work around it. To add parameter (rc:Parameters, rc:Toolbar) in report URL to control the parameter area visibility. Please refer to the following URL:
    Http://ServerName/ReportServer/Pages/ReportViewer.aspx? %2fReportFolder%2fReportName&rs:Command=Render&rc:Parameters=Collapsed
    Reference:
    http://blogs.msdn.com/b/jgalla/archive/2009/03/23/hiding-parameter-area-when-viewing-reports.aspx?Redirected=true
    If there are any misunderstanding, please elaborate the issue for further investigation.
    Regards,
    Alisa Tang
    Alisa Tang
    TechNet Community Support

  • CRM sales order is not saved in CRM but in ECC

    Hi,
    I am new CRM area and will not some hints on where to check.
    When the the Sales orders are successfully created in CRM, they are replicated to R/3 but the sales orders are not saved in CRMD_ORDERADM_H table of the CRM system.
    Also, I dont know see any details of the sales order in the interaction record document flow.
    Can you please help me with any hints on where to check to fix this issue..

    Hi Sangameshwar,
    In CRM you can have two scenarios for ERP Sales Order.
    1. ERP Sales offer and Sales order, using the CRM User Interface to create directly the ERP Sales Documents with LORD interface. The document is only saved in ERP. I believe this the scenario you are using.
    2. CRM Sales offer and Sales order, the document is saved both CRM and ERP. The documents are replicated via Middleware.
    In both scenarios the interaction record should add the document in the doc. flow, it's probably a missing customizing in the interaction record.
    Hope this information help you.
    Regards,
    Jorge G.

  • 802.1X Port Based Authentication - IP Phone- MDA - Port Security Violation

    I have configured 802.1X authentication on selected ports of a Cisco Catalyst 2960S with Micorsoft NPS Radius authentication on a test LAN. I have tested the authentication with a windows XP laptop, a windows 7 laptop with 802.1X, eap-tls authentication and a Mitel 5330 IP Phone using EAP-MD5 aithentication. All the above devices work with with the MS NPS server. However in MDA mode when the  802.1x compliant  windows 7 laptop is connected to the already authenticated Mitel IP Phone, the port experiences a security violation and the goes into error sdisable mode.
    Feb  4 19:16:16.571: %AUTHMGR-5-START: Starting 'dot1x' for client (24b6.fdfa.749b) on Interface Gi1/0/1 AuditSessionID AC10A0FE0000002F000D3CED
    Feb  4 19:16:16.645: %DOT1X-5-SUCCESS: Authentication successful for client (24b6.fdfa.749b) on Interface Gi1/0/1 AuditSessionID AC10A0FE0000002F000D3CED
    Feb  4 19:16:16.645: %PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state
    Feb  4 19:16:17.651: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to down
    Feb  4 19:16:18.658: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down
    If the port config  is changed to "authentication host-mode multi-auth", and the laptop is connected to the phone the port does not experience the security violation but the 802.1x authentication for the laptop fails.
    The ports GI1/0./1 & Gi1/02 are configured thus:
    interface GigabitEthernet1/0/1
    switchport mode access
    switchport voice vlan 20
    authentication event fail action authorize vlan 4
    authentication event no-response action authorize vlan 4
    authentication event server alive action reinitialize
    authentication host-mode multi-domain
    authentication order dot1x mab
    authentication priority dot1x mab
    authentication port-control auto
    mab
    mls qos trust cos
    dot1x pae authenticator
    spanning-tree portfast
    sh ver
    Switch Ports Model              SW Version            SW Image
    *    1 52    WS-C2960S-48FPS-L  15.2(1)E1             C2960S-UNIVERSALK9-M
    Full config attached. Assistance will be grately appreciated.
    Donfrico

    I am currently trying to get 802.1x port authentication working on a Cat3550 against Win2003 IAS but the IAS log shows a invalid message-authenticator error. The 3550 just shows failed. When I authenticate against Cisco ACS (by simply changing the radius-server) it works perfectly.
    However, I am successfully using IAS to authenticate WPA users on AP1210s so RADIUS appears to be OK working OK.
    Are there special attributes that need to be configured on the switch or IAS?

  • 802.1X Port Based Authentication Security Violation

    I have configured 802.1X authentication on selected ports of a Cisco Catalyst 2960S with Micorsoft NPS Radius authentication on a test LAN. I have tested the authentication with a windows XP laptop, a windows 7 laptop with 802.1X, eap-tls authentication and a Mitel 5330 IP Phone using EAP-MD5 aithentication. All the above devices work with with the MS NPS server. However in MDA mode when the  802.1x compliant  windows 7 laptop is connected to the already authenticated Mitel IP Phone, the port experiences a security violation and the goes into error sdisable mode.
    Feb  4 19:16:16.571: %AUTHMGR-5-START: Starting 'dot1x' for client (24b6.fdfa.749b) on Interface Gi1/0/1 AuditSessionID AC10A0FE0000002F000D3CED
    Feb  4 19:16:16.645: %DOT1X-5-SUCCESS: Authentication successful for client (24b6.fdfa.749b) on Interface Gi1/0/1 AuditSessionID AC10A0FE0000002F000D3CED
    Feb  4 19:16:16.645: %PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/1, putting Gi1/0/1 in err-disable state
    Feb  4 19:16:17.651: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to down
    Feb  4 19:16:18.658: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down
    If the port config  is changed to "authentication host-mode multi-auth", and the laptop is connected to the phone the port does not experience the security violation but the 802.1x authentication for the laptop fails.
    The ports GI1/0./1 & Gi1/02 are configured thus:
    interface GigabitEthernet1/0/1
    switchport mode access
    switchport voice vlan 20
    authentication event fail action authorize vlan 4
    authentication event no-response action authorize vlan 4
    authentication event server alive action reinitialize
    authentication host-mode multi-domain
    authentication order dot1x mab
    authentication priority dot1x mab
    authentication port-control auto
    mab
    mls qos trust cos
    dot1x pae authenticator
    spanning-tree portfast
    sh ver
    Switch Ports Model              SW Version            SW Image
    *    1 52    WS-C2960S-48FPS-L  15.2(1)E1             C2960S-UNIVERSALK9-M
    Full config attached. Assistance will be grately appreciated.
    Donfrico

    I believe , you need to configure re-authentication on this switch port:
    ! Enable re-authentication
    authentication periodic
    ! Enable re-authentication via RADIUS Session-Timeout
    authentication timer reauthenticate server

  • Hyperlinks not saving

    Hi,
    I'm currently rebuilding my website with lots of hyperlinks taking you to pages that don't appear on the nav bar. All was fine in the beginning, but after putting 10+ links on the same page, all going to different places I find that they are not saving, and rather than going to the page I want them to, they are all going to a pdf file (this may have been the original button that I copied and pasted, but then I changed the details in the hyperlink box so that it would take you to the various pages.)
    It doesn't matter how many times I click save, or publish between each link or doo them all in one go, whenever I go back to the button has returned to linking to the pdf file.
    HELP! I feel like I am wasting my life away here, and iWeb is supposed to SAVE me time!

    I have found that it works much better, for some reason, to make links on a separate
    page and then copy and paste. The whole link process in iweb can drive you nuts, especially if you are changing fonts and formatting at the same time. It's very sensitive to the order in which you do things I think.

  • When I close CS6 changes in settings are not saved.  Reverts to default settings on reopen.  Why?

    When I close CS6 changes in settings are not saved.  Reverts to default settings on reopen.  Why?

    Sorry Photoshop --  Problems solved -- I read the details -- turns out you need to make changes with no files open for the preferences to apply to all files.
    Thanks,  Al

  • Sent messages are sometimes not saved

    Hello,
    This is a follow up to this thread, which was never answered and is now archived:
    http://discussions.apple.com/thread.jspa?threadID=2213207
    In Mail.app, using IMAP, my sent messages are sometimes not saved. I'd say about 1 in 20 never appear in my Sent folder. The recipients always receive these messages, so it's not a delivery problem. I just don't retain a copy of them. This is very frustrating if I send a cost estimate to a client, or a detailed description of a technical problem that I need to refer back to later.
    I've rebuilt my mailboxes and I've checked my IMAP folders on the server via a webmail interface, and the messages are not there.
    Has anyone else experienced this? It's hard to believe I'm the only one, but it's hard to search for this problem because my search results are always full of people who have lost or can't save -any- of their sent messages. My problem is intermittent and random.
    Thanks,
    -Arlo

    I have a similar occasional problem with an IMAP account using a Comcast Business Class Exchange server. I use Mail and my iPhone to access the account; I'm running OS X 10.6.4 on my laptop but my "sent messages" issue predates the latest release.
    The first time I noticed this issue I thought, "I'll just access my mail via the Comcast web portal. It'll be in the 'sent' folder there." No dice. The "sent" messages simply never stay on the server, yet my recipients get them.
    It's distressing. First, the solution would appear to be a switch to a MS mail client, which I swore off years ago. Second, I rely on having a "sent" message as a record. I switched off IDLE per your suggestion, Ernie, but otherwise I'm in the same boat as the others here. Please keep this thread alive. I'm hopeful that this can be resolved.

  • HT2506 I'm using Preview with a MacBook Pro and MacOS 10.6.8. When adjusting sharpness in the Adjust Colour tool, images are not saved. Any hint? Thanks.

    I'm using Preview with a MacBook Pro and MacOS 10.6.8. When adjusting sharpness in the Adjust Colour tool, images are not saved. Any hint? Thanks.

    I too experienced the same issue.  Here are my details:
    Recently I bought a 15” Macbook Pro and last night I tried to connect and use a Edirol FA/66 Firewire 400 connected outboard audio interface using a Firewire 400 to 800 adapter then connected to a Firewire 800 to Thunderbolt adapter since the MBP doesn’t have a native Firewire port.  What I observed is that the Edirol was not getting power from the bus nor did the MBP (running Yosemite) recognize the Edriol.  At first I thought there was a problem with the Edirol since I haven’t used it in a while but when I connected it to an older MBP that has a native Firewire port, it worked normally.  Is there a known issue with these sorts of external audio interfaces working properly with newer MBP running Yosemite?  I’m hoping that a software update will fix this issue.

Maybe you are looking for

  • Adobe media encoder in PP CS3

    Hi there I'm using Premiere Pro CS3, when I try to launch Adobe media encoder or Matrox media encoder, the program bugs. Any help? I'm very new in this field. Thanx

  • How to make an index in InDesign CC 2014.1 using a topics list?

    Hi all, I have read the long help document on how to make an index in InDesign CC 2014.1 using a topics list, and still can't work out what to do. I have done a 548 page book, using a document for each chapter, and a book file to put them all togethe

  • Trading partner is not populated on G/L accounts

    Dear All, We have activated trading partners. When the SD document is posted only customer account documents are getting populated with "trading partner". However - "trading partner" is not copied to G/L account.(revenue accounts, cost of goods sold)

  • Unknown objects in ABAP/4- Dictionary_workload tables SAPWLM***

    Hello, the following database tables do not exist in the ABAP Dictionary: SAPWLMLOG SAPWLMONI SAPWLMTOC1 SAPWLMTOC2 Are these Workload tables obsolete in 701 and can be deleted? Best regards Lutz

  • Differences between  BDC , LSMW, BAPI,CATT

    Hi ABAP Gurus, Just I have completed my ABAP course. Could you please explain the differences between BDC(Session and Call Transaction),LSMW,CATT and BAPI. Their advantages & limitions. Thanks in advance. Chandra Mohan