[c-nsp] 3560-C NEAT to MS Server2008 NPS

Lists Lists lists at jimiw.net
Tue May 1 23:57:19 EDT 2012


Hi All,

We're trying to get some new 3560-CG's to auth with our MS 2k8 NPS server
but are hitting some roadblocks. Has anyone successfully had them talk to
each other?

We get stuck on EAP types - the server complains that the EAP type is
invalid. On the supplicant switch side I've tried all available EAP methods
(FAST, GTC, MD5, MS-CHAPv2) and same on the Windows side.

Our authenticator and supplicant switches both have cisp enable, and these
configs:

supplicant (tried with and without dot1x supplicant eat):

interface GigabitEthernet0/10
 switchport trunk encapsulation dot1q
 switchport mode trunk
 dot1x pae supplicant
 dot1x credentials supp
 dot1x supplicant eap profile eap
end

authenticator (tried with switchport mode access and mode trunk, and with
authentication open):
interface FastEthernet0/1
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 40,72,88,144,222,300
 switchport mode access
 authentication port-control auto
 dot1x pae authenticator
end


Is there anything we're missing? Anyone got any tips?

Cheers,
James


More information about the cisco-nsp mailing list