Is there anyone using wired 802.1x in production?

I have 802.1x configured with PEAP and vlan assignment using the MS supplicant. I have hardcoded Machine Auth because Remote Desktop does not work with User Auth. (see my other posts) I have figured out how to change the Microsoft supplicant to PEAP with a vb script. I have a catalyst 6509 enabled with 802.1x enabled on module 8 and 9 with about 60 actual PCs authenticated between to 2 modules. At this point I am testing ACS redundancy (2 ACS SE) and any potential ACS load issues before campus deployment.
My problem:
1. If I reset module 8 or 9 the switch reloads. I guess it is overwhelmed by all the 802.1x requests. I am not too concerned about this right now because this type of product quality is very common in this new era. I have not reset another module in this switch that does not have 802.1x enabled. Though, I have reset modules in the past.
2. My main concern is the amount of time it takes for all the ports on a given module to finally 802.1x authenticate. To avoid problem (1.), I disabled/enabled all ports on module 8. It takes about 8-12 minutes before all 30+ ports are authenticated. This behavior is the same after the reload.
It takes about 10 seconds for one supplicant to authenticate. It appears the switch is serializing the logins in a loop until all are authenticated. I calculate 384 ports * 10 seconds = 1.06 hour to authenticate after reload (best case).
Please share your experiences or ideas.

We have dot1x enabled in production. Over thousand of supplicants. Terrible!! I found last week that while we reset one of the modules; the switch crashed. Because we have 2 Sup in one box, the switch did not reload but failed over to the standby SUP.
We have CatOS 8.4.1 and 8.4.5 in our environment; 2 ACSes for redundant purpose.
I did not perceive the dealy you mention.We found that a lot of supplicants could not be authenticated.
Below is the trace that I found when switches crashed. Do you see the same output?
pantree port fast start set to default for ports 6/29,6/34.
QRDCN05ACC01> (enable) set vlan 461 System reset on software watchdog is disabled
TLB Exception (load/instruction fetch) occurred on Sep 26 2005 16:15:00
Software version = 8.4(1)
Process ID #4c, Name = Backend_SM
process stack top = 3ff1b170, stack pointer = 3ff1b0e8
cause = 00000008
TLB Exception (load/instruction fetch) exception happened
EPC: 210274A0
Traceback:
210274A0
210274A0
Stack content:
sp+00: 00000006 00000006 21026C38 202ECAB0
sp+10: 267AD970 22F9B290 22FA0000 00000006
sp+20: 0000001D 00000030 00000005 21027230
sp+30: 0000012C 00000000 20B47BDC 20B47BDC
sp+40: 00000000 00000000 00000000 00000000
sp+50: 00000000 00000000 00000000 00000000
sp+60: 3FF1B150 20B4A2A0 20B47BDC 20B47BDC
sp+70: 20B47BDC 20B47BDC 00000007 20B47BDC
sp+80: 00000000 20B4A250 20B47BDC 20B47BDC
sp+90: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+A0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+B0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+C0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+D0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+E0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
sp+F0: 20B47BDC 20B47BDC 20B47BDC 20B47BDC
Register content:
Status: 3400FC23 Cause: 00800008
AT: 22830000
V0: 00000001 V1: 267AD970
A0: 00000006 A1: 0000001D
A2: 0000001C A3: 22FA0000
T0: 23C00BC0 T1: 3FFFF070
T2: 00000001 T3: 00000007
T4: 00007080 T5: 00000000
T6: 00800000 T7: F03FFFFF
S0: 22F9B290 S1: 00000000
S2: 00000006 S3: 0000001D
S4: 00000005 S5: 0000001C
S6: 22FA0000 S7: 0000000D
T8: FFFFFFFF T9: 4B34A6A4
K0: 30409001 K1: 215016E8
GP: 2283AC70 SP: 3FF1B0E8
S8: 00000007 RA: 2102742C
HIGH: 0000001A LOW: 0355485E
BADVADDR: 00000002 ERR EPC: A3A3A3A3
Total download memory used = 3989996
crash info filename is bootflash:crashinfo_050926-161503
Opening crash info file bootflash:crashinfo_050926-161503
Time took to write crashinfo = 00:05.09
crashinfo finished

Similar Messages

  • Is there anyone using an iphone 4s, os 5.0.1, in kolkata india on service provided vodafone 3g and the phone working fine?

    Is there anyone using an iphone 4s, os 5.0.1, in kolkata india on service provided vodafone 3g and the phone working fine?

    hi i bought a iphone 4s recently and is having vodafone as service provider. my iphone is not recongising or detecting any 3G signal. Did your problem got solved by any chance?

  • Is there anyone using oracle's forms builder to develop without EBS?

    Is there anyone develop Information System use forms builder to develop your own product without EBS.
    which version are you used ? forms 6i?or forms 10g,11g?

    Hello,
    (Almost) Everybody, here, uses Forms without EBS, because EBS users post in the dedicated E-Buisness Suite forum ;-)
    Francois

  • Is there anyone using Java Methods interface of IREP in his application

    Hello everyone,
    Are you using Java Methods interface of IREP in your application?
    Nowadays I am trying to using Java Methods in my application. But I'm puzzled how to get the interface jar files that the Java Methods would import. It seems that Oracle doesn't provide such interface jar files for all Java Methods shipped in IREP. How do you do with this?
    If you have some experience about using Java Methods in application, hope to hear your voice. Thanks in advance.

    Hi friend,
    Thanks for you update.
    I'm referring to Java Methods that can be called directly by applications not Java Service Interface. These are two different kinds of IREP interfaces. In Oracle Integration Repository User's Guide, there aren't much guidance about how to use Java Methods.
    I appreciate you can help me further.

  • Is there anyone use Hibernate?help me

    Hi everyone:
    I study hibernate recently.There is a problem puzzled me all the time.:(
    What time should I use proxy in hibernate(For example: <class name="eg.Order" proxy="eg.Order">) It can help the hibernate "lazy=true"? They is any association between the proxy and Lazy? Please help me
    Thks !
    :rolleyes:

    Hi
    You know JDO? It's very like it but Hibernate more strong than that.
    Hibernate is an O/R Mapping technology.It is used to map database table to entity object.(like EntityBean). jsp+DAO+Hibernate. Hibernate is a light wrapper of jdbc. See so www.hibernate.com

  • Is there anyone use M Audio Axiom Pro 61 with Logic Pro 9?

    Does Axiom Pro's Hyper-Control work fine with Logic Pro's Plug-in and Instrument?
    Please Share your Opinion

    {quote:title=majo> Can Axion Pro Control Soft Instrument such as Sculpture as well as Plug-in?
    Yes.
    Is there any Logic Plug-in that Axiom Pro can't Control?
    No.

  • Anyone using AP2 on a 2Ghz G5 with Radeon 9600 graphics?

    I had high hopes for v1.5 but it just ran too slow on my G5 to be usable. I hoped to upgrade the card to an x800 xt but after being on order through B&H for six months or so with the estimate of availability "within the next 2 weeks" for that whole time, I finally gave up and got my money back from B&H and gave up on Aperture.
    I have now ordered V2, and I'm hopeful it will be - if not fast - at least usable now on my 2Ghz G5 with the 9600 card. (3GB ram)
    Is there anyone using it with this configuration who could provide me with some feedback?
    Much appreciated!
    Forrest Smyth

    I got a 2x2.5Ghz PowerMac G5, 2 GB RAM, with a 23" Apple Display, and a ATI Radeon 9600 XT..
    I also found Ap1.5 to be a bit to slow, but I just stuck with it.. I have now installed the trail version of Ap2.0 and its quite noticeably faster, fast enough for me to keep this Mac for a while longer (unless it breaks)..
    Im not entirely sure, but it seems that it takes a bit longer to fully load an image (Nikon D80 RAW files) then in Ap1.5.. but thats not to bad, just use quick view mode to browse around.. and then work on the images you want to work on.
    As I said it all works faster, straightening can now actually be done in near real-time
    and all the other sliders (even highlight & shadows) are far more responsive..
    now I must say this is in an aperture library with only about 200-300 images.. I hope it will stay as fast when I get the full version and get all my 30,000 images in it.

  • Is there anyone who has used Freescale's SimpleSUB.dll and DEMOJM board?

    Hello,
    I am trying to connect Frescale DEMOJM board over USB connection. I am adding SimpleUSB.dll to my visual instrument thorough .NET constructor node and giving an mscorlib class GUID to the GUID property, than calling OpenConnection method from an invoke node referencing the SimpleUSB reference. But there is no valid connection to the device as DeviceConnected parameter return "False". 
    I am using LabVIEW 8.6 trial, .NET Framework 3.5. So they are up to date I guess. Is there a limitation of these for using .NET dll? And also I can use the dll in Visual C# successfully.
    At first there was another problem using the .NET constructor node in LabVIEW because of Vista OS.  The vi was blocking when i added the node to the vi. I changed the "language & regional settings" to English(USA). The problem seemed to be solved. Can Vista's bug be still a problem?
    Is there anyone who  has used Freescale's SimpleUSB.dll and DEMOJM board with LabVIEW?
    I will be thankfull for your helps.
    Emre

    Hello Anna,
    Here is one of my poor vi trials.   I have also tried putting some conditionals in some other files but it didn't helped.
    http://rapidshare.com/files/176194859/EXTDLL1.rar.html
    Here is a link for the Freescale's DEMOJM board. It shows how to make a GUI for the board using SimpleUSB.dll & C#.  You can also download the dll from that web page and there is helpfull documentation for the dll.
    http://www.freescale.com/webapp/sps/site/prod_summary.jsp?code=USBJM_TRAINING&nodeId=016246fNrgVJ4Cx...
    I am trying to make the same thing with Labview instead of C#. But I am not familiar with the SW issues so am in trouble.
    Thanks,
    Emre

  • Ive just upgraded to Mountain lion, I was using Safari and tried to use iCloud tabs. When I open it up there are no tabs there, anyone have any ideas on how to get it working?

    Ive just upgraded to Mountain lion, I was using Safari and tried to use iCloud tabs. When I open it up there are no tabs there, anyone have any ideas on how to get it working?

    Can you check system update? I think I did a system Update 1st, a day before installing OSX Lion and there is a Safari update. If not try logging in iCloud.

  • Is there anyone who does computational physics using numerical recipes  and multi source programming in c

    is there anyone who does computational physics using numerical recipes  and multi source programming in c++

    On an iPad?  I'd have to say no, since you can't compile C++ code on an iPad.

  • Is it secure to have the pulic open a resource guide in Adobe Reader?  Or is there a way to make sure anyone using the link to the guide is secure?

    Is it secure to have the public open a resource guide in an Adobe Reader PDF?  Or is there a way to make sure anyone using the link to the guide is protected?
    Not sure how to find an answer to this.
    Thanks, GM

    I am trying to post a 123 page resource guide online for the public to access through the website of a non profit.  The guide has a lot of web links for to use for more information.  But there have been clickability issues when using some browsers to download the PDF and so I would prefer to suggest that they try to download the resource into Adobe Reader before using.  I want to make sure that this would securely safe for readers and users.
    Sorry I was not clear in my original question and thank you for your kind attention.
    Thank you again,
    GM

  • Cisco 7921 - Does anyone Use EAP-TLS in their VoWLAN Deployments?

    Hi Guys,
    I am looking at making a technology decision, in regards to VoWLAN and authentication.
    For our Data Deployment, we use EAP-TLS with a PKI infrastructure and ACS. The ACS passes fields from the certs to AD for verification.
    Can I do exactly the same for the Voice Deployment?
    Has anyone used EAP-TLS with Voice? Are there any problems? Or should I just go ahead and get some certs minted for the phones, setup some AD accounts and whey hey, its time to party?
    Many thx indeed,
    Ken

    Hi Michael,
    So looking at the deployment guide, this is worded (imho) in a confusing manor? Sorry.
    CCKM is listed under authentication, where i though CCKM is an authentication "key managment" protocol?
    It also says 802.1x authentication with AES encrytion, under the authentication heading?
    It says eap-tls, should this not say 802.1x eap-tls or collapse this with the 802.1x authentication?
    ahh, when it says 802.1x, does that mean 802.1x dynamic wep?
    Would it be correct to say, that I want to use 802.1x eap-tls with tkip and CCKM?
    Sorry, this hurts :)
    Thx,
    Ken
    Wireless Security
    When deploying a wireless LAN, you must provide security. The Cisco Unified Wireless IP Phone 7921G supports the following wireless security features.
    Authentication
    - Cisco Centralized Key Management (CCKM)
    - 802.11i (802.1x authentication + TKIP encryption)
    - 802.11i (802.1x authentication + AES encryption)
    - 802.11i (Pre-Shared key + TKIP encryption)
    - 802.11i (Pre-Shared key + AES encryption)
    - Extensible Authentication Protocol - Flexible Authentication via Secure Tunneling (EAP-FAST)
    - Extensible Authentication Protocol - Transport Layer Security (EAP-TLS)
    - Protected Extensible Authentication Protocol (PEAP)
    - Lightweight Extensible Authentication Protocol (LEAP)
    - Open and Shared Key
    Encryption
    - Advanced Encryption Scheme (AES)
    - Temporal Key Integrity Protocol (TKIP) / Message Integrity Check (MIC)
    - 40-bit and 128-bit Wired Equivalent Protocol (WEP)
    Cisco Centralized Key Management (CCKM)
    When using 802.1x type authentication, you should implement CCKM for authentication. 802.1x can introduce delay during roaming due to its requirement for full re-authentication. CCKM centralizes the key management and reduces the number of key exchanges. Also, WPA introduces additional transient keys and can lengthen roaming time. TKIP encryption is recommended when using CCKM for fast roaming as CCKM does not support AES currently.

  • Hi there! yesterday I installed Mavericks on my Macbook. Since then, it doesn't mount my external hard disk drive anymore, which he did a week ago (without the update). Is there anyone out there who knows a solution?

    Hi there! Yesterday, I installed Mavericks on my Macbook. Since then, it doesn't recognize my external hard disk drive anymore (at least not on the desktop. In Germany they call it "it doens't mount it". I don't know if it's the same expression in english?)
    I just used it a week ago, before I did the update and it worked perfectly fine.
    Is there anyone out there who knows a solution for this problem? I've been googleing for hours now and can't find any answer.
    Thank you!!!

    Please read this whole message before doing anything.
    This procedure is a diagnostic test. It’s unlikely to solve your problem. Don’t be disappointed when you find that nothing has changed after you complete it.
    The purpose of the test is to determine whether the problem is caused by third-party software that loads automatically at startup or login, by a peripheral device, by a font conflict, or by corruption of the file system or of certain system caches.
    Disconnect all wired peripherals except those needed for the test, and remove all aftermarket expansion cards, if applicable. Start up in safe mode and log in to the account with the problem. You must hold down the shift key twice: once when you turn on the computer, and again when you log in.
    Note: If FileVault is enabled, or if a firmware password is set, or if the startup volume is a Fusion Drive or a software RAID, you can’t do this. Ask for further instructions.
    Safe mode is much slower to start up and run than normal, with limited graphics performance, and some things won’t work at all, including sound output and Wi-Fi on certain models. The next normal startup may also be somewhat slow.
    The login screen appears even if you usually login automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
    Test while in safe mode. Same problem?
    After testing, restart as usual (not in safe mode) and verify that you still have the problem. Post the results of the test.

  • Wired 802.1x with PEAP

    I have manage to get wired 802.1x working using Windows Active Directory as the database. With machine authentication, single-signon can be achieved.
    Setup:
    C3750 switch - Cisco ACS 3.2 - Windows AD
    Sequence of events:
    1. 802.1x machine authentication
    2. User logs in to domain
    3. 802.1x with user credentials
    But, I have the following issues:
    i. If user logs in using local account, it takes 3 minutes (default dot1x switch timers) for the port to turn unauthorized. Is it possible to place the port in unauthorized state immediately?
    ii. If the user 802.1x login has dynamic VLAN assignment, the AD scripts do not run. It seems that the AD scripts can't run if there is a change of IP address upon login (difference in VLAN for 'machine authentication' and 'user login').
    Any solution for this?
    Tks

    2 issues here:
    *Cached credentials for Microsoft supplicannts. Microsoft's authentication strategy in general reflects, and WLAN roaming would be difficult without the use of cached credentials. If cached credentials are not desired, would recommend another supplicant.
    * Falied Authentication for a local account. It should try to dot1x authenticate this user. For PEAP as an example, you would see the username as \. Now, a port will only be placed into a HELD state if a RADIUS-Reject is sent to the switch. A RADIUS-Reject will only be sent to the switch if the attempt is actually "failed" as opposed to silently discarded, packet lost in transit, etc. Taking 3 minutes to actually fail an attempt is indeed way too long, but the switch is probably doing what RADIUS is telling it to do. (this can be verified by a sniffer trace or debugs). Correspinding logs on RADIUS would help as well.

  • Wired 802.1x re-authentication passes but no connectivity after 1 hour

    I am testing wired 802.1x with the desired behavior of machine auth with user auth. I have a 6509 CAT OS 8.3(5) using the dot1x global defaults, 2 laptops one is XP SP1 and XP SP2 both with AuthMode=1 and SupplicantMode=3 with windows update as of 02mar2005. Active Directory. ACS SE 3.2 using vlan assignment. Have tested PC and user in different vlans and it works fine.
    1st observation:
    The initial EAP authentication is good. Every hour there is an EAP request with a final result of success in the packet trace. The switch shows connected dot1x-123. The ACS log shows the passed re-authentication. Everything looks good but both laptops lose connectivity 1 hour after the first authorization. If I issue "set port dot1x initialize" or enable/disable the port the process starts over.
    2nd observation:
    I can connect with Remote Desktop. There are 2 EAP start frames then the port becomes unauthorized about a minute later.
    Any ideas?

    No. I am still waiting on Cisco to address the 1st observation. Does it occur on your 6506 8.4(2). I see it also in my 6509 with 8.4(2). I find it interesting that it works in my end of life 2948g switch 8.2(1)GLX.
    The MS supplicant defaults for WIRED are authmode=1 and supplicantmode=2. Remote Desktop works in their default WIRED mode.
    At this point I am content controlling machine access until dot1x matures. Cisco ACS has a machine access restriction feature that authorizes the port after a successful User Auth. I have found if enabled, a successful Machine Auth will be unauthorized when logged in with a local account. If disable the local account is authorized b/c MA has only occurred.

Maybe you are looking for

  • INCLUDE of a Function Module

    Hi All, On the Function Module (SE37) Attributes screen, there is a field name "INCLUDE name" which is related to the FM. Is there any table that we can use to search by FM to get this Include? I am developing program to read the source code in the F

  • Error in Oracle IPM 10gR3

    Hi I am trying to install IPM 10gR3 as per the install.doc provided by the Oracle. I completed the setup of the first server. At one point, it ask me to Run IBPMServer /diag from the command prompt to start the Oracle I/PM services configured on this

  • Sending and recieving

    I recently set up a mail account, but every time I try to send something, it says this- The connection to the server "smtp.mac.com" on port 25 timed out. What is wrong???

  • BT Infinity and Pages Not Loading

    Have been using BT Infinity successfully for two months, but two weeks ago suddenly started to experience my browser stalling, websites not loading at all (eg www.latimes.com - simply will not load any of the home page), some sites loading but repeat

  • RFC to WS Error

    I am doing RFC to WS  scenario i am getting following error in RFC sender adapter Error in processing caused by: com.sap.aii.af.lib.mp.module.ModuleException: call to messaging system failed: com.sap.engine.interfaces.messaging.api.exception.Messagin