Security

 View Only
Expand all | Collapse all

Wired 802.1x user fails reauthentication

This thread has been viewed 13 times
  • 1.  Wired 802.1x user fails reauthentication

    Posted Dec 11, 2023 03:06 PM
    Hey guys, how are you?
     
     
     
    I am experiencing an issue with my 802.1x WIRED service. Where all my end users are able to connect and get the correct vlan on the first authentication, but when they shut down or restart the computer, authentication does not happen automatically and often the username and password do not appear to add their AD credentials, in other cases appears after 2 to 3 minutes.
     
    In Access Tracker, sometimes the "host/" attempt to authenticate appears and other times it appears that the user was authenticated and sometimes the request dies in a timeout, but the computer remains without gaining an IP.
     
    Has anyone ever caught something similar?
     
    Note: This occurs on different switch models.
     
     
    Thanks in advance.


  • 2.  RE: Wired 802.1x user fails reauthentication

    Posted Dec 12, 2023 08:51 AM

    What type of client? The (re)authentication is triggered by the switch. This issue looks to be related with MAC&802.1X on the same switch port, and timers/retries/order/precedence between those. Good starting config for a few switch models is in the Wired Policy Enforcement Solution Guide (available here).

    What is strange is that you have the same on different switch models, if different models are different brand/operating models.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------