Aironet 1100 authentication open mac-address problems

I have a new C1100 series that is running 12.2(4). I am trying to get mac-address authentication to use my RADIUS Server (Funk SBR). I think I am close, but I have been close for about 12 hours now.
I am using an ssid for the dot11Radio 0 inetface...
interface Dot11Radio0
no ip address
no ip route-cache
ssid INTECUSA
authentication open mac-address sbr
ssid tsunami
authentication open
guest-mode
...and I THINK I have the sbr list correctly defined.
aaa group server radius default
server 158.155.25.201 auth-port 1812 acct-port 1813
aaa authorization network sbr group radius
radius-server host 158.155.25.201 auth-port 1812 acct-port 1813
...The RADIUS server is up and responding client requests.
...and it looks as though the 1100 is trying to do the right thing, but I don't think I have the sbr method list correctly defined. I don't see any traffic actually go out over the network. Here are the debug messages...
CiscoCS1100#show debug
General OS:
AAA Authorization debugging is on
AAA Accounting debugging is on
dot11 aaa:
Mac Authentication debugging is on
Accounting debugging is on
(now I plug a card into a laptop.
06:51:07: AAA/ACCT/EVENT/(0000013D): CALL START
06:51:07: AAA/ACCT/NET(0000013D): Rec init, Session Id=126
06:51:07: dot11_aaa_mac_auth: method_list: sbr
06:51:07: dot11_aaa_mac_auth: method_index: 0xFFFFFFFF, req: 0x64EA28
06:51:07: dot11_aaa_mac_auth: client->unique_id: 0x13D
06:51:07: dot11_mac_process_reply: AAA reply for 000c.3002.1f57 FAILED
06:51:07: dot11_aaa_upd_accounting: Updating attributes for user: 000c.3002.1f57
Thanks,
Bryan

Thanks for the reply David, but there are no packets going out on the network to the AAA server. Also I think the debug messages I included were incomplete. I just tried to access the network (no setting were changed). here is the debug output. The message...
*21:01:28: AAA/ACCT/NET(00000155): Method list not foundfailed; Cleaning the record up*
Is why I think I am messing up. Again no traffic on the Ethernet side of the 1100 going to the RADIUS server.
21:01:28: AAA/ACCT/EVENT/(00000155): CALL START
21:01:28: AAA/ACCT/NET(00000155): Rec init, Session Id=150
21:01:28: dot11_aaa_mac_auth: method_list: sbr
21:01:28: dot11_aaa_mac_auth: method_index: 0xFFFFFFFF, req: 0x7AB8DC
21:01:28: dot11_aaa_mac_auth: client->unique_id: 0x155
21:01:28: dot11_mac_process_reply: AAA reply for 000c.3002.1f57 FAILED
21:01:28: dot11_aaa_upd_accounting: Updating attributes for user: 000c.3002.1f57
21:01:28: AAA/ACCT/EVENT/(00000155): CALL STOP
21:01:28: AAA/ACCT/CALL STOP(00000155): Sending stop requests
21:01:28: AAA/ACCT(00000155): Sending stop record for NET
21:01:28: AAA/ACCT/NET(00000155): Method list not foundfailed; Cleaning the record up
21:01:28: AAA/ACCT(00000155):acctdb->rec_count = 0..sending signal
21:01:28: AAA/ACCT(00000155): Interface DB not enqueuedsuccess
21:01:29: dot11_mac_auth_process: remove 000c.3002.1f57 from mac hold list
Thanks again,
Bryan

Similar Messages

  • Domain authentication with mac address restrictions

    I am in a branch office and I have one WLC 5508 and one ACS 4.2 with three WLANs:
    WLAN1 with SSID1: for company computers and laptops
    WLAN2 with SSID2: for ipads and tablets
    WLAN3 with SSID3:  for guests
    I am asked to configure WLAN2 as “WLAN2: Provides the Wi-Fi connectivity to ipads and tablets, with back end security using domain authentication with mac address restrictions.

    You would need to create a seperate policy and be able to have a seperation between the two policies... It's kind of hard to explain, but you would have for example:
    Policy 1:
    Wireless user on this SSID WLAN1
    AD on this AD Group (Machine)
    Policy 2:
    Wireless user on this SSID WLAN 2
    AD on this AD Group (USer)
    Thanks,
    Scott
    *****Help out other by using the rating system and marking answered questions as "Answered"*****

  • SG200-8 Static mac address problem

    Hi!
    My second problem with sg200-08 (firmware: SG200-08x_FW_1.0.6.2.stk) is when I try to add specific MAC address as secure:
    MAC Address Tables - Static Addresses - Add; insert vlan id, port, mac address and select "Secure":
    I get error message: "Error: Failed to Add 'Static Address' entry.
    Again, thanks for reply!
    Best regards,
    Boris Bahes.

    Moritz Lipfert wrote:I have the same problem using the current firmware 1.0.6.2. But even an upgrade by TFTP followed by a factory reset does not help. A downgrade to firmware 1.0.5.1 also does not fix this issue.Are there any other suggestions?
    Strange as it may sound, try playing with compatibility mode in Internet Explorer. I have found that these switches interface respond well only in IE.

  • AP 2700 - 2 MAC addresses - problem with joining to the WLC

    Hi,
    I had a problem with joining my new AP 2700 to the controller. I've found workaround but I would like to ask you if you know if this behavior is a some kind of bug or maybe feature :)
    I have DHCP server which assigns IP address base on the binding MAC address with the IP address. Without binding, IP won't be assigned so I added MAC address from the AP sticker (MAC and SN number is on the sticker at the back of each AP) to the DHCP, connected AP to the switch port which was configured exactly the same way like other ports on this switch where older AP are working fine and.... nothing. IP address was not assigned. There was no DHCP request in the DHCP server logs.
    During the investigation I've found that AP present 2 MAC addresses on the switch interface:
    switch#sh mac address-table interface fa1/1
    Mac Address Table
    Vlan Mac Address Type Ports
    11 58f3.54c1.2cb3 DYNAMIC Fa1/1
    11 58f3.54c1.2cb4 DYNAMIC Fa1/1
    The first one (58f3.54c1.2cb3) is a "sticker" MAC address but the second one (58f3.54c1.2cb4) is something new. Looking in to the DHCP logs I've found log that this second MAC address (58f3.54c1.2cb4) tried to get IP address but it was not possible because this MAC was not binding with any IP address so DHCP server refuse. I added this second MAC (58f3.54c1.2cb4) to the DHCP server, AP get IP address, join to the WLC, download software, reboot and ... this MAC address disappear.
    switch#sh mac address-table interface fa1/1
    Mac Address Table
    Vlan Mac Address Type Ports
    11 58f3.54c1.2cb3 DYNAMIC Fa1/1
    Software I had on the AP before joining to the WLC was:
    Version :
    Cisco IOS Software, C2700 Software (AP3G2-RCVK9W8-M), Version 15.2(4)JB5, RELEASE SOFTWARE (fc1)
    now I have (after downloaded from the WLC)
    Version :
    Cisco IOS Software, C2700 Software (AP3G2-K9W8-M), Version 15.2(4)JB6, RELEASE SOFTWARE (fc1)
    Do anyone know what happen?

    (WLC1) >show sysinfo
    Manufacturer's Name.............................. Cisco Systems Inc.
    Product Name..................................... Cisco Controller
    Product Version.................................. 7.6.130.0
    Bootloader Version............................... 1.0.20
    Field Recovery Image Version..................... 7.6.95.16
    Firmware Version................................. FPGA 1.7, Env 1.8, USB console 2.2
    Build Type....................................... DATA + WPS
    System Name...................................... WLC1
    System Location..................................
    System Contact...................................
    System ObjectID.................................. 1.3.6.1.4.1.9.1.1069
    Redundancy Mode.................................. Disabled
    IP Address....................................... 10.10.10.10
    Last Reset....................................... Software reset
    System Up Time................................... 25 days 2 hrs 53 mins 5 secs
    System Timezone Location.........................
    System Stats Realtime Interval................... 5
    System Stats Normal Interval..................... 180
    Configured Country............................... US - United States
    Operating Environment............................ Commercial (0 to 40 C)
    Internal Temp Alarm Limits....................... 0 to 65 C
    Internal Temperature............................. +44 C
    External Temperature............................. +22 C
    Fan Status....................................... OK
    State of 802.11b Network......................... Enabled
    State of 802.11a Network......................... Disabled
    Number of WLANs.................................. 6
    Number of Active Clients......................... 25
    Burned-in MAC Address............................ XX:XX:XX:XX:XX:XX
    Power Supply 1................................... Present, OK
    Power Supply 2................................... Present, OK
    Maximum number of APs supported.................. 25
    (WLC1) >show time
    Time............................................. Thu Apr 9 13:51:00 2015
    Timezone delta................................... 0:0
    Timezone location................................
    NTP Servers
    NTP Polling Interval......................... 3600
    Index NTP Key Index NTP Server NTP Msg Auth Status
    1 0 10.10.10.11 AUTH DISABLED
    It's look like AP doesn't allow for console login or commands it just only show activity. After rebooting the WLC I get information:
    Cisco IOS Software, C2700 Software (AP3G2-RCVK9W8-M), Version 15.2(4)JB5, RELEASE SOFTWARE (fc1)

  • 802.1x authentication with mac address

    Hi guys,
    there is a strange requirement from one of our customer,
    they want us to do 802.1x with mac address authentication and they dont want the pop-ups which ask
    for username, password and domain.
    is it possible??
    can i avoid popping up the username password with 802.1x and that too with mac address???
    Any help would be greatly appreciated
    Thanks
    Jvalin

    Hi,
    The feature which you are looking for is possible in case of wired 802.1x. This feature is called as the MAC-Auth Bypass and is done mostly if the client machine is not 802.1x capable. However nowerdays it is used even if the machine is 802.1x capable.In this we enter the MAC address of the machine in the user database e.g. Active Directory. When you connect the client machine to the Switch, if we have MAC-Auth Bypass enabled on the port, it would take the MAC address of the machine as the username without any prompt for username and password.
    A windows server admin can easily push a group policy which disables the 802.1x on the client machine and it would only respond to the MAC-Auth Bypass.But first you would have to make sure your switch has the Mac-Auth Bypass in the IOS.
    For more information, you can go to http://www.cisco.com/univercd/cc/td/doc/solution/macauthb.pdf
    Regards,
    Kush

  • UCS mac address problem

    Hi all,
    simple question....
    may you know if, with release 1.4.1 there is some mac address learning bug?
    i've go a blades with a mix of palo and other cards, some vnic are pinned to uplink with trunk and allowed vlan 501 on both side. On the UCS blades i've got ESX and ESXi. Service console is tagged to VLAN 501 (according to trunk configuration on UCS and uplink switch). Some blade had got these interface pinned on UCS6100 A and other one on B (with failover). The fact is that if i ping from outside UCS to inside UCS (ESX) no mac learning is performed on all infrastructure.
    I'm sure problem is on UCS 'cause if i clear mac table on UCS nothing works......and all work if i begin to ping from UCS. I've also tried to put on uplink switch a static mac (ESX service console) but was not useful.
    i hope is not a 1.4.1 bug......
    tnx and tnx for help
    dan

    Are any of you using Uplink Pin Groups or have a disjointed Layer 2 network by chance?
    Issues like these are ususally related to Pin Groups/Disjoint L2 using the wrong link as the DR port for incoming traffic.  When traffic is generated from within UCS outbound, the MAC table gets updated on the upstream switch which allows traffic to flow, until it ages out.
    If either of these are the case I suggest you have a look at Brad's videos, name video #6:
    http://bradhedlund.com/2010/06/22/cisco-ucs-networking-best-practices/
    Regards,
    Robert

  • Access Connection - Prefer MAC address problem

    Hey
    My specifications:
    Windows Vista
    Access Connection v5.31
    After updating access connection I'm not able to prefer MAC addresses for my profiles anymore.
    Edit profile> Wireless settings> Advanced configuration (settings)>
    Preferred access point MAC address.-
    This box is grayed out and you're not able to write in the box anymore.
    Am I doing something wrong or is this feature just disabled for this version?
    Also I remember having seen an old version being able to prefer 5 MAC addresses for one profile
    Thank you!
    / jerian

    Welcome to the Apple discussions.
    Is the mac address you're using the one you see when you click on the blue apple, about this mac, more info, network, and scroll down to the mac address? Is it possible there's a mixup between the letter O and zero when entering the mac address?

  • T61s, T60s & older model unable to PXE boot to SCCM (MAC address problem)

    Hi, 
    We have a series of T60, T61 & older machines that are unable to PXE boot to SCCM. The T400 & X series & other newer models can boot just fine. 
    After checking further, we realised that only a certain range of MAC addresses are unable to pxe boot i.e 
    00-1A-XXXXXXX
    00-1C-XXXXXXX 
    range.. all the other range of MAC addresses are fine to boot via network. 
    The error when doing network boot  is "bad or missing discovery server list" 
    Also, we are running on SCCM 2012 at the moment. Our branch office who is running SCCM 2008 can have all the machines - regardless of models & brand boot just fine. 
    Any ideas?  Much appreciated. 

    did it obtain IP address from DHCP server? is DNS server address is configured in DHCP scope? can you ping using IP address?
    if drivers are proper will suggest to update it in boot media & enable command line support to make it easy for deployment & troubleshooting.
    Prashant Patil

  • TS1559 Wifi MAC address problem: iPhone 4s

    Hi, My iPhone 4S' MAC address got changed and then it went into recovery mode. After I restored it the MAC address showed N/A and I can't turn on wifi. I followed everything in the above article and it was still the same. I can use 3G and Bluetooth.

    The Mac address cannot be changed.  Go to settings>general> about an dhave a look at your mac address  there

  • MAC address problem

    Hi all,
    I am a newbie and would really appreciate it if someone can answer the following questions.
    1. How does it work if a packet is send from one network to another network and the MAC of destination if unknown? My understanding is the sender's network gateway mac address is used as the MAC destination address. But how is it send to the destination?
    2. Why do we need a MAC address? Isn't IP address enough?
    3. How come there are some MAC address which does not exist in the network topology?
    Many thanks again.
    Richard

    Richard
    An IP address is not enough because the IP addresses cannot change (unless you are doing NAT but that is not relevant to this) but the mac addresses have to. An example might help -
    H1 -> (int gi0/0)  L3 switch  (int gi0/1) -> S1
    H1 = 192.168.5.10
    S1 = 192.168.6.10
    H1 wants to send a packet to S1 so it needs to send the packet to it's default gateway It does this by using the mac address of the gi0/0 interface on the L3 switch -
    src mac = H1
    dst mac = L3 gi0/0
    src IP = 192.168.5.10
    dst IP = 192.168.6.10
    the L3 switch receives the packet and sees the destination IP is S1 and it has a direct connection so it sends the packet to S1 -
    src mac = L3 int gi0/1
    dst mac = S1
    src IP = 192.168.5.10
    dst IP = 192.168.6.10
    notice how the IPs never change but the mac addresses do at each L3 hop.
    If you just used the IP it wouldn't work because if the IP was the L3 gi0/0 IP the L3 switch would not know what the destInation IP is meant to be.
    Note that i didn't cover ARP which resolves an IP to a mac address because i just wanted to keep it simple.
    Hopefully that's helped with questions 1) and 2).
    Not sure what you mean by question 3)  ?
    Jon

  • Cisco Aiornet 1042 with MAC address

    Hi,
    I have a Cisco Aiornet, model  AIR-AP1042N-E-K9.
    I need to configure the AP to only certain MAC access. 
    I'm doing the configuration through the console. 
    The wireless network is not showing up in devices, anyone know why?
    version 15.2
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    service password-encryption
    hostname ap_disi
    logging rate-limit console 9
    enable secret 5 xxxxx.
    aaa new-model
    aaa group server radius rad_eap
    aaa group server radius rad_mac
    aaa group server radius rad_acct
    aaa group server radius rad_admin
    aaa group server tacacs+ tac_admin
    aaa group server radius rad_pmip
    aaa group server radius dummy
    aaa authentication login default local
    aaa authentication login eap_methods group rad_eap
    aaa authentication login mac_methods local
    aaa authorization exec default local 
    aaa accounting network acct_methods start-stop group rad_acct
    aaa session-id common
    no ip routing
    no ip cef
    dot11 syslog
    dot11 ssid DISI-WLAN24
       authentication open 
    dot11 ssid DISIWIFI
       authentication open mac-address mac_methods 
       authentication key-management wpa version 2
       infrastructure-ssid
    dot11 guest
    username Cisco password 7 xxxx
    username Admin privilege 15 password 7 xxxx
    bridge irb
    interface Dot11Radio0
     no ip address
     no ip route-cache
     encryption mode ciphers aes-ccm 
     ssid DISI-WLAN24
     ssid DISIWIFI
     antenna gain 0
     speed  basic-1.0 2.0 5.5 11.0 6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
     station-role root
     l2-filter bridge-group-acl
     bridge-group 1
     bridge-group 1 subscriber-loop-control
     bridge-group 1 spanning-disabled
     bridge-group 1 block-unknown-source
     no bridge-group 1 source-learning
     no bridge-group 1 unicast-flooding
    interface Dot11Radio1
     description AP SITAS
     no ip address
     no ip route-cache
     encryption mode ciphers aes-ccm 
     ssid DISIWIFI
     antenna gain 0
     peakdetect
     no dfs band block
     speed  basic-6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 m0. m1. m2. m3. m4. m5. m6. m7. m8. m9. m10. m11. m12. m13. m14. m15.
     channel dfs
     station-role root
     bridge-group 1
     bridge-group 1 subscriber-loop-control
     bridge-group 1 spanning-disabled
     bridge-group 1 block-unknown-source
     no bridge-group 1 source-learning
     no bridge-group 1 unicast-flooding
    interface GigabitEthernet0
     no ip address
     no ip route-cache
     duplex auto
     speed auto
     l2-filter bridge-group-acl
     no keepalive
     bridge-group 1
     bridge-group 1 spanning-disabled
     no bridge-group 1 source-learning
    interface BVI1
     ip address 192.168.0.252 255.255.254.0
     no ip route-cache
     ipv6 address dhcp
     ipv6 address autoconfig
     ipv6 enable
    ip default-gateway 192.168.1.254
    ip forward-protocol nd
    ip http server
    ip http authentication aaa
    no ip http secure-server
    ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    ip radius source-interface BVI1 
    access-list 700 permit 8830.8a24.7eb5   0000.0000.0000
    access-list 700 deny   0000.0000.0000   ffff.ffff.ffff
    snmp-server view dot11view ieee802dot11 included
    snmp-server community public view dot11view RO
    snmp-server location DISI
    snmp-server contact SITAS
    snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
    snmp-server enable traps tty
    snmp-server enable traps entity
    snmp-server enable traps disassociate
    snmp-server enable traps deauthenticate
    snmp-server enable traps authenticate-fail
    snmp-server enable traps dot11-qos
    snmp-server enable traps switch-over
    snmp-server enable traps rogue-ap
    snmp-server enable traps wlan-wep
    snmp-server enable traps config-copy
    snmp-server enable traps config
    snmp-server enable traps syslog
    snmp-server enable traps cpu threshold
    snmp-server enable traps aaa_server
    snmp-server host 192.168.1.6 public 
    radius-server attribute 32 include-in-access-req format %h
    radius-server vsa send accounting
    bridge 1 route ip
    line con 0
    line vty 0 4
     transport input all
    sntp server 192.168.1.215
    sntp broadcast client
    end

    Please refer: http://www.cisco.com/c/en/us/td/docs/wireless/access_point/12-4-25d-JA/Configuration/guide/cg_12_4_25d_JA/scg12-4-25d-JA-chap16-filters.html#wp1034897

  • WLC+LAP+ACS4.0 achieving 802.1x PEAP and MAC address authentication ?

    How to configure WLC + LAP + ACS4.0, achieving username and password authentication and MAC address at the same time

    This might help with the PEAP:
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00807917aa.shtml
    MAC Authentication
    Add a MAC Address to ACS
    Complete these steps:
    1. From the ACS main menu, click on the User Setup button.
    2. In the User text box, enter the MAC address to add to the user database.
    Note: The MAC address must be exactly as it is sent by the AP for both the username and the password. If authentication fails, check the failed attempts log to see how the MAC is being reported by the AP. Do not cut and paste the MAC address, as this can introduce phantom characters.
    3. On the User Setup screen, enter the MAC address in the Secure-PAP password text box.
    Note: The MAC address must be exactly as it is sent by the AP for both the username and the password. If authentication fails, check the failed attempts log to see how the MAC is being reported by the AP. Do not cut and paste the MAC address, as this can introduce phantom characters.
    4. Check the Separate (CHAP/MS-CHAP) box.
    5. Enter a password for CHAP/MS-CHAP (this password should be different from the MAC address).
    6. Click Submit.

  • Cisco wlc2504 mac address filtering

    I am using a wlc2504 software version 7.4.100.0. I use MAC filtering for wireless device to connect to our wi-fi. Currently I have about 249 saved MAC address that can access the wi-fi. About once a week, the controller looses or forgets 3-5 MAC addresses, thereby devices looses connectivity to wi-fi. Is there a limit to number of MAC address configured to be saved? What is causing this? What can I do to prevent this from happening? Thanks.

    MAC Address Filter (MAC Authentication) on WLCs
    When you create a MAC address filter on WLCs, users are granted or denied access to the WLAN network based on the MAC address of the client they use.
    There are two types of MAC authentication that are supported on WLCs:
    Local MAC authentication
    MAC authentication using a RADIUS server
    With local MAC authentication, user MAC addresses are stored in a database on the WLC. When a user tries to access the WLAN that is configured for MAC filtering, the client MAC address is validated against the local database on the WLC, and the client is granted access to the WLAN if the authentication is successful.
    By default, the WLC local database supports up to 512 user entries.
    The local user database is limited to a maximum of 2048 entries. The local database stores entries for these items:
    Local management users, which includes lobby ambassadors
    Local network users, which includes guest users
    MAC filter entries
    Exclusion list entries
    Access point authorization list entries
    Together, all of these types of users cannot exceed the configured database size.
    In order to increase the local database, use this command from the CLI:
    <Cisco Controller>config database size ?
    <count> Enter the maximum number of entries (512-2048)
    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/91901-mac-filters-wlcs-config.html

  • Aironet 1100 with Static Address

    Hi All
    I have taken over some access points from a company which were providing our wireless service and have not yet received the IP scheme information.
    I need to get onto one of the Aironet 1100 access points to see what the config etc is.
    I will only be able to take it down for a few hours, how to I actually connect to it.
    I am pretty sure it is configured with a static IP address which I do not know so is there anyway of connecting to it without using the Reset to Default method obviously!
    I have tried IPSU and a hub but no good.
    All replied gratefully received!!
    Darran

    Thanks for the replies guys but it hasnt solved my problem.
    Looks like it's not a static address after all
    I have done the following
    1. Plugged the AP into a switch on our network and connected to it wirelessly. I receive an IP the very same as if I was plugged into the switch directly and when I do an IPconfig I get the very same info as if I was plugged directly in. Still cannot find the AP IP Address though.
    2. Plugged the AP into a switch on our network and connected to the switch and did a show cdp neighbour, the access point does not show up, only other switches.
    3. Read the user guide and connected my laptop directly to the AP with a CAT 5 cable and gave the laptop an address of 10.0.0.2 . The AP does not seem to revert to 10.0.0.1 as suggested in the manual.
    4. I have tried to run the IPSU under all the above conditions, searching by the mac address of the AP but it has not received anything.
    ANy other ideas, Im at my wits end!!

  • Problem to authenticate MAC address on ISE

    Hi guys,
    I have a Lab with a ISE ver 1.1.1 installed on VMWARE, a Switch 3750, a WLC 4200 and one AP registered on WLC, the WLC and AP are connected to Switch, we are testing the user authentication using a samsung tablet and it work ok. The authentication procces is using the actual AD. the issue is when I try to authenticate de device using their MAC address. I'm reading many pappers, but no one explain me the steps to do the both autentication: by user and by MAC address using the ISE.
    can any one help me about the authenticacion MAC address process on ISE. the  final deployment our client want to use user and device authentication.
    Thank you for your attention on this matter.

    Hi Tarik,
    Thanks for your reply,
    the port configuration of SW is it:
    DEMOSW# sh run int Gi2/0/11
    description Access Wireless LAN Controller
    switchport trunk encapsulation dot1q
    switchport mode trunk
    authentication host-mode multi-auth
    authentication open
    authentication order dot1x mab
    authentication priority dot1x mab
    authentication port-control auto
    authentication periodic
    authentication timer reauthenticate server
    mab
    dot1x pae authenticator
    spanning-tree portfast
    DEMOSW# sh run int Gi2/0/12
    description Access Point
    switchport access vlan 103
    spanning-­tree portfast
    Our goal is that the MAC address Tablets can be authenticated using the ISE Internal Enpoints Database.
    I hope you may help me about it.
    Thank you for your attention on this matter.
    Regards.

Maybe you are looking for

  • PDF Forms Saved as CFM Files

    OK, this is kind of a bizarre question and I suspect it has something to do with my having Master Collection installed on my machine and a file typing issue.  But I can't confirm for sure . . . so if anyone has any ideas to point me in the right dire

  • With visual age 302

    Hi, I am using weblogic5.1 Integration Kit for VisualAge 302. After I followed the instruction and try to start weblogic in VisualAge, everything looks fine. But if I try to invoke http://localhost:7001/ from browser, I got the following error: Fri A

  • Fetching LongRAW  over DB link results in ORA-1406 error

    How to FETCH LONG RAW values from remote DB into PLSQL cursor variable. Following is my sample code, where in column MESSAGE_xxx_FILE in XXXX table is defined as LONG RAW. ++++++++++++++++++++++++ declare CURSOR cur IS SELECT MESSAGE_xxx_FILE FROM xx

  • Third Party Orders

    Hi All when creating third party sales order for a make to order scenario my inventory account is getting hit and is throwing an error - therefore, i need to be able to do a statistical goods receipt on this scenario I have mapped all accts in OBYC a

  • Terminal commands

    I am looking for a good manual or resource of terminal commands to download. Does anyone know of one. I am pretty new to terminal but not new to Mac OSX I want to do a few tweaks and if anyone knows the commands then please let me know. 1st i want to