<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic dot1x &amp; MAC auth using RADIUS with Router Code in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12622#M187</link>
    <description>Hi All,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;We're implementing dot1x and MAC auth on 7150 stack (08.0.80) running router code (basic). We've configured dot1x and MAC auth to RADIUS just like we have successfully in our lab environment (7250 switch code) but it doesn't work. The RADIUS server never even gets a request but we have confirmed connectivity between the two. IP interface VE exists in the test VLAN and default route to the WAN. I have a feeling it has something to do with the fact we dont have a management VLAN specified, but as i understand it, when running router code, this is not an option? Quite new to ICX so still figuring things out. Any pointer appreciated.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Auth-mode multiple-untagged&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-default-vlan XXX&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; restricted-vlan YYY&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-fail-action restricted-vlan&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-timeout-action failure&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x enable ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x port-control auto ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication enable ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication password-format xx:xx:xx:xx:xx:xx&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication dot1x default radius&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host &lt;A href="http://WWW.XXX.YYY.ZZZ" rel="nofollow"&gt;WWW.XXX.YYY.ZZZ&lt;/A&gt; auth-port 1812 acct-port 1813 default key 2 $RSddJzVvYish dot1x mac-auth&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Mon, 17 Sep 2018 20:21:37 GMT</pubDate>
    <dc:creator>robert_lowe_722</dc:creator>
    <dc:date>2018-09-17T20:21:37Z</dc:date>
    <item>
      <title>dot1x &amp; MAC auth using RADIUS with Router Code</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12622#M187</link>
      <description>Hi All,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;We're implementing dot1x and MAC auth on 7150 stack (08.0.80) running router code (basic). We've configured dot1x and MAC auth to RADIUS just like we have successfully in our lab environment (7250 switch code) but it doesn't work. The RADIUS server never even gets a request but we have confirmed connectivity between the two. IP interface VE exists in the test VLAN and default route to the WAN. I have a feeling it has something to do with the fact we dont have a management VLAN specified, but as i understand it, when running router code, this is not an option? Quite new to ICX so still figuring things out. Any pointer appreciated.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Auth-mode multiple-untagged&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-default-vlan XXX&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; restricted-vlan YYY&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-fail-action restricted-vlan&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; auth-timeout-action failure&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x enable ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; dot1x port-control auto ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication enable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication enable ethe 3/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; mac-authentication password-format xx:xx:xx:xx:xx:xx&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication dot1x default radius&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host &lt;A href="http://WWW.XXX.YYY.ZZZ" rel="nofollow"&gt;WWW.XXX.YYY.ZZZ&lt;/A&gt; auth-port 1812 acct-port 1813 default key 2 $RSddJzVvYish dot1x mac-auth&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 17 Sep 2018 20:21:37 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12622#M187</guid>
      <dc:creator>robert_lowe_722</dc:creator>
      <dc:date>2018-09-17T20:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x &amp; MAC auth using RADIUS with Router Code</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12623#M188</link>
      <description>You can specify a VE or Interface to use.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip radius source-interface x&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Please refer to the Security guide section Source address configuration Radius&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 24 Sep 2018 18:49:48 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12623#M188</guid>
      <dc:creator>william_hadley_</dc:creator>
      <dc:date>2018-09-24T18:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x &amp; MAC auth using RADIUS with Router Code</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12624#M189</link>
      <description>Thanks William, this is exactly what i was looking for!</description>
      <pubDate>Mon, 24 Sep 2018 22:46:22 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/dot1x-MAC-auth-using-RADIUS-with-Router-Code/m-p/12624#M189</guid>
      <dc:creator>robert_lowe_722</dc:creator>
      <dc:date>2018-09-24T22:46:22Z</dc:date>
    </item>
  </channel>
</rss>

