hello, the command set you gave is for tacacs
I am having a similar issue with DOT1X authetication. when radius server is reachable , machine is getting IP and getting DOT1X authetication via the radius (Clearpass). but when radius is not reachable machine not getting IP
configuration done as under
user VLAN is VLAN 100
*************************
Global
domain default enable cppm
radius scheme cppm
primary authentication x.x.x.x key simple x.x.x.x
secondary authentication x.x.x.x key simple x.x.x.x
primary accounting x.x.x.x key simple x.x.x.x
Secondary accounting x.x.x.x key simple x.x.x.x
accounting-on enable
user-name-format without-domain
nas-ip x.x.x.x
domain cppm
authentication lan-access radius-scheme cppm local
authorization lan-access radius-scheme cppm local
accounting lan-access radius-scheme cppm local
radius nas-ip x.x.x.x
radius dynamic-author server
client ip x.x.x.x key simple x.x.x.x
client ip x.x.x.x key simple x.x.x.x
port-security enable
port-security mac-move permit
dot1x authentication-method eap
mac-authentication domain cppm
*********************
Interface level
port link-type hybrid
undo port hybrid vlan 1
port hybrid vlan 100 untagged
port hybrid pvid vlan 100
mac-vlan enable
stp root-protection
stp edged-port
lldp compliance admin-status cdp txrx
qos trust dscp
poe enable
dot1x mandatory-domain cppm
undo dot1x handshake
undo dot1x multicast-trigger
mac-authentication domain cppm
mac-authentication timer auth-delay 10
port-security port-mode userlogin-secure-or-mac-ext
loopback-detection action shutdown
Dot1x critical vlan 100
Dot1x critical eapol