Re: 802.1x PROBLEMI

emre aksoy <[email protected]> Thu, 10 Sep 2009 04:53:58 -0700 (PDT)
Newsgroups gmane.comp.hardware.cisco.turkish
Message-ID <[email protected]>
Slm dot.1x  tarafında guest vlan tanımla kullanıcı authenticate  oluncaya kadar quest vlan de kalsın , burdan  sisteme login olsun sonrasında switch tekrar authenticate işlemi yapıp uygun vlan e atacaktır.

--- On Thu, 9/10/09, Sunay Musaoglu <[email protected]> wrote:

From: Sunay Musaoglu <[email protected]>
Subject: [cisco-ttl] 802.1x PROBLEMI
To: [email protected]
Cc: [email protected]
Date: Thursday, September 10, 2009, 11:00 AM












 
 




    
                  Merhaba ;

Switch , ias configurasyonları ve topoloji resmi ektedir.

Ekteki konfigurasyon ile log off oldugumda portumu kapatmıyor.



Fakat client ın ethernet kablosunu cekip tekrar switchporta ( fa 0/5 ) taktıgımda ben log off haldeyken ias ve domain controller (ikisi de aynı makina uzerinde) ile baglantı kuramıyor.



Dolayısı ile domaine log on olamıyorum.

Bu problemi nasıl asabilirim ? 

Yardımlarınız icin Tesekkurler.

iyi calismalar.



----------



TEST_3560#sh run


Building configuration. ..





Current configuration : 3125 bytes


!


version 12.2


no service pad





aaa new-model


!


!


aaa authentication dot1x default group radius


aaa authorization network default group radius 


aaa accounting dot1x default start-stop group radius


aaa accounting system default start-stop group radius


!


!


!


aaa session-id common


system mtu routing 1500


ip subnet-zero


ip routing


!


!


!


!


!


dot1x system-auth- control


!


!


!


!


!


spanning-tree mode pvst


spanning-tree extend system-id


!


vlan internal allocation policy ascending


!         


!


!


!


interface FastEthernet0/ 1


 switchport access vlan 10


 switchport mode access


 spanning-tree portfast


!


interface FastEthernet0/ 2


!


interface FastEthernet0/ 3


 switchport access vlan 5


 switchport mode access         FA 0/5 ten IAS a ulasamadýgýmda FA 0/3 ten baglanmak amaclý


 spanning-tree portfast


!


interface FastEthernet0/ 4


!


interface FastEthernet0/ 5


 switchport mode access


 dot1x pae authenticator


 dot1x port-control auto


 dot1x violation-mode protect


 spanning-tree portfast


!





!


interface Vlan1


 no ip address


!


interface Vlan5


 ip address 2.2.2.1 255.255.255. 0


!


interface Vlan10


 ip address 1.1.1.1 255.255.255. 0


!


interface Vlan20


 no ip address


!


ip classless


ip http server


ip http secure-server


!


!


radius-server host 1.1.1.3 auth-port 1812 acct-port 1813 timeout 4


radius-server retry method reorder


radius-server transaction max-tries 10


radius-server retransmit 10


radius-server timeout 4


radius-server deadtime 2


radius-server key 123456


radius-server vsa send authentication


!














TEST_3560#sh vlan





VLAN Name                             Status    Ports


---- ------------ --------- --------- -- --------- ------------ --------- --------- -


1    default                          active    Fa0/2, Fa0/4, Fa0/5, Fa0/6


                                                Fa0/7, Fa0/8, Fa0/9, Fa0/10


                                                Fa0/11, Fa0/12, Fa0/13, Fa0/14


                                                Fa0/15, Fa0/16, Fa0/17, Fa0/18


                                                Fa0/19, Fa0/20, Fa0/21, Fa0/22


                                                Fa0/23, Fa0/24, Fa0/25, Fa0/26


                                                Fa0/27, Fa0/28, Fa0/29, Fa0/30


                                                Fa0/31, Fa0/32, Fa0/33, Fa0/34


                                                Fa0/35, Fa0/36, Fa0/37, Fa0/38


                                                Fa0/39, Fa0/40, Fa0/41, Fa0/42


                                                Fa0/43, Fa0/44, Fa0/45, Fa0/46


                                                Fa0/47, Fa0/48, Gi0/1, Gi0/2


                                                Gi0/3, Gi0/4


5    CLIENT_VLAN                      active    Fa0/3


10   RADIUS_VLAN                      active    Fa0/1


1002 fddi-default                     act/unsup 


1003 token-ring-default               act/unsup 


1004 fddinet-default                  act/unsup 


1005 trnet-default                    act/unsup 





VLAN Type  SAID       MTU   Parent RingNo BridgeNo Stp  BrdgMode Trans1 Trans2


---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------


1    enet  100001     1500  -      -      -        -    -        0      0   


5    enet  100005     1500  -      -      -        -    -        0      0   


10   enet  100010     1500  -      -      -        -    -        0      0   


1002 fddi  101002     1500  -      -      -        -    -        0      0   


1003 tr    101003     1500  -      -      -        -    -        0      0   


1004 fdnet 101004     1500  -      -      -        ieee -        0      0   


1005 trnet 101005     1500  -      -      -        ibm  -        0      0   





Remote SPAN VLANs


------------ --------- --------- --------- --------- --------- -








Primary Secondary Type              Ports


------- --------- ------------ ----- ------------ --------- --------- --------- ---



[Non-text portions of this message have been removed]




 

      

    
    
	
	 
	
	




	




	
	


	
	
	



[Non-text portions of this message have been removed]



------------------------------------

--
Cisco Teknik Tartisma Listesi (Cisco-ttl)

Disclaimer: Some of the individuals posting to this site, including 
the moderators, work for Cisco Systems, Inc. Opinions expressed here and in any corresponding comments are the personal opinions of the original authors, not those of Cisco.
 Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/cisco-ttl/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/cisco-ttl/join
    (Yahoo! ID required)

<*> To change settings via email:
    mailto:[email protected] 
    mailto:[email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/