<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic integration extreme switch to cisco ise in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/integration-extreme-switch-to-cisco-ise/m-p/51097#M13856</link>
    <description>Hi all, i hope you are doing well&lt;BR /&gt;
please can you help to see if the error it's in the switch extreme or in the ise?&lt;BR /&gt;
&lt;BR /&gt;
im getting the following error from ise &lt;BR /&gt;
 &lt;BR /&gt;
Event 5400 Authentication failed&lt;BR /&gt;
Failure Reason 11014 RADIUS packet contains invalid attribute(s)&lt;BR /&gt;
 &lt;BR /&gt;
 &lt;BR /&gt;
in the extreme device the lines that you put in are::&lt;BR /&gt;
 &lt;BR /&gt;
configure radius netlogin primary server 10.8.54.120 1812 client-ip 10.8.54.121 vr VR-Default&lt;BR /&gt;
configure radius netlogin primary shared-secret encrypted "Didata2019"&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
configure netlogin vlan cisco&lt;BR /&gt;
configure netlogin dynamic-vlan enable&lt;BR /&gt;
configure netlogin dynamic-vlan uplink-ports 48&lt;BR /&gt;
enable ports 11-24 dot1x&lt;BR /&gt;
configure netlogin ports 2 mode port-based-vlans&lt;BR /&gt;
configure netlogin ports 2 no-restart&lt;BR /&gt;
and snmp is configure&lt;BR /&gt;
 &lt;BR /&gt;
so, i have a few questions, it's imperative to have the snmpv3 or can be the snmpv2 to work with?&lt;BR /&gt;
but the devices and users are not going to the check, when a take a tcp dump&lt;BR /&gt;
do you know which more attribute do we have to put in the ISE device?&lt;BR /&gt;
do i need to put an extra config in the extreme switch? or is fine?&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
this is the tcp and the radius challenge&lt;BR /&gt;
 &lt;BR /&gt;
18:27:16.482677 IP (tos 0x0, ttl 64, id 0, offset 0, flags [df], proto UDP (17), length 134)&lt;BR /&gt;
X.X.X.X.41884 &amp;gt; srv-ise-: RADIUS, length: 106&lt;BR /&gt;
Access-Request (1), id: 0x5c, Authenticator: 4222cceb304c20525556ce28010d3cf6&lt;BR /&gt;
User-Name Attribute (1), length: 8, Value: srojas&lt;BR /&gt;
EAP-Message Attribute (79), length: 13, Value: ..&lt;BR /&gt;
NAS-IP-Address Attribute (4), length: 6, Value: 10.8.54.121&lt;BR /&gt;
Service-Type Attribute (6), length: 6, Value: Login&lt;BR /&gt;
Calling-Station-Id Attribute (31), length: 19, Value: E8-6A-64-2E-6D-3A&lt;BR /&gt;
NAS-Port-Id Attribute (87), length: 4, Value: 21&lt;BR /&gt;
NAS-Port Attribute (5), length: 6, Value: 1021&lt;BR /&gt;
NAS-Port-Type Attribute (61), length: 6, Value: Ethernet&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: {....w..]...._.c&lt;BR /&gt;
18:27:16.486793 IP (tos 0x0, ttl 64, id 11075, offset 0, flags [df], proto UDP (17), length 180)&lt;BR /&gt;
srv-ise &amp;gt; X,X,X,X 1884: RADIUS, length: 152&lt;BR /&gt;
Access-Challenge (11), id: 0x5c, Authenticator: 4a5051e21408fcb0f25eb794f08b3998&lt;BR /&gt;
State Attribute (24), length: 106, Value: 64CPMSessionID=0a083678VsRdGYwkon5XnlXinUbVtE4xg2G5Jp9VYxWEH0/ql2U;34SessionID=srv-ise-poc/334695666/92;&lt;BR /&gt;
EAP-Message Attribute (79), length: 8, Value: .d&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: .M&amp;gt;F.&lt;BR /&gt;
18:27:16.491115 IP (tos 0x0, ttl 64, id 0, offset 0, flags [df], proto UDP (17), length 355)&lt;BR /&gt;
X.X.X.X.41884 &amp;gt; srv-ise: RADIUS, length: 327&lt;BR /&gt;
Access-Request (1), id: 0x5d, Authenticator: 34a2b32737e5e7c059c32f31161a99b3&lt;BR /&gt;
User-Name Attribute (1), length: 8, Value: srojas&lt;BR /&gt;
EAP-Message Attribute (79), length: 168, Value: .d&lt;BR /&gt;
NAS-IP-Address Attribute (4), length: 6, Value: 10.8.54.121&lt;BR /&gt;
Service-Type Attribute (6), length: 6, Value: Login&lt;BR /&gt;
Calling-Station-Id Attribute (31), length: 19, Value: E8-6A-64-2E-6D-3A&lt;BR /&gt;
NAS-Port-Id Attribute (87), length: 4, Value: 21&lt;BR /&gt;
NAS-Port Attribute (5), length: 6, Value: 1021&lt;BR /&gt;
NAS-Port-Type Attribute (61), length: 6, Value: Ethernet&lt;BR /&gt;
State Attribute (24), length: 66, Value: 64CPMSessionID=0a083678VsRdGYwkon5XnlXinUbVtE4xg2G5Jp9VYxWEH0/ql&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: &amp;lt;.1.B.^.w....n..&lt;BR /&gt;
18:27:16.494422 IP (tos 0x0, ttl 64, id 11077, offset 0, flags [df], proto UDP (17), length 66)&lt;BR /&gt;
srv-ise &amp;gt; X.X.X.X.41884: RADIUS, length: 38&lt;BR /&gt;
Access-Reject (3), id: 0x5d, Authenticator: a7b41552a449bf5985ff3ec0b104379e&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: p.......3.@E^.$.</description>
    <pubDate>Fri, 21 Dec 2018 07:27:00 GMT</pubDate>
    <dc:creator>sebd44</dc:creator>
    <dc:date>2018-12-21T07:27:00Z</dc:date>
    <item>
      <title>integration extreme switch to cisco ise</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/integration-extreme-switch-to-cisco-ise/m-p/51097#M13856</link>
      <description>Hi all, i hope you are doing well&lt;BR /&gt;
please can you help to see if the error it's in the switch extreme or in the ise?&lt;BR /&gt;
&lt;BR /&gt;
im getting the following error from ise &lt;BR /&gt;
 &lt;BR /&gt;
Event 5400 Authentication failed&lt;BR /&gt;
Failure Reason 11014 RADIUS packet contains invalid attribute(s)&lt;BR /&gt;
 &lt;BR /&gt;
 &lt;BR /&gt;
in the extreme device the lines that you put in are::&lt;BR /&gt;
 &lt;BR /&gt;
configure radius netlogin primary server 10.8.54.120 1812 client-ip 10.8.54.121 vr VR-Default&lt;BR /&gt;
configure radius netlogin primary shared-secret encrypted "Didata2019"&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
configure netlogin vlan cisco&lt;BR /&gt;
configure netlogin dynamic-vlan enable&lt;BR /&gt;
configure netlogin dynamic-vlan uplink-ports 48&lt;BR /&gt;
enable ports 11-24 dot1x&lt;BR /&gt;
configure netlogin ports 2 mode port-based-vlans&lt;BR /&gt;
configure netlogin ports 2 no-restart&lt;BR /&gt;
and snmp is configure&lt;BR /&gt;
 &lt;BR /&gt;
so, i have a few questions, it's imperative to have the snmpv3 or can be the snmpv2 to work with?&lt;BR /&gt;
but the devices and users are not going to the check, when a take a tcp dump&lt;BR /&gt;
do you know which more attribute do we have to put in the ISE device?&lt;BR /&gt;
do i need to put an extra config in the extreme switch? or is fine?&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
this is the tcp and the radius challenge&lt;BR /&gt;
 &lt;BR /&gt;
18:27:16.482677 IP (tos 0x0, ttl 64, id 0, offset 0, flags [df], proto UDP (17), length 134)&lt;BR /&gt;
X.X.X.X.41884 &amp;gt; srv-ise-: RADIUS, length: 106&lt;BR /&gt;
Access-Request (1), id: 0x5c, Authenticator: 4222cceb304c20525556ce28010d3cf6&lt;BR /&gt;
User-Name Attribute (1), length: 8, Value: srojas&lt;BR /&gt;
EAP-Message Attribute (79), length: 13, Value: ..&lt;BR /&gt;
NAS-IP-Address Attribute (4), length: 6, Value: 10.8.54.121&lt;BR /&gt;
Service-Type Attribute (6), length: 6, Value: Login&lt;BR /&gt;
Calling-Station-Id Attribute (31), length: 19, Value: E8-6A-64-2E-6D-3A&lt;BR /&gt;
NAS-Port-Id Attribute (87), length: 4, Value: 21&lt;BR /&gt;
NAS-Port Attribute (5), length: 6, Value: 1021&lt;BR /&gt;
NAS-Port-Type Attribute (61), length: 6, Value: Ethernet&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: {....w..]...._.c&lt;BR /&gt;
18:27:16.486793 IP (tos 0x0, ttl 64, id 11075, offset 0, flags [df], proto UDP (17), length 180)&lt;BR /&gt;
srv-ise &amp;gt; X,X,X,X 1884: RADIUS, length: 152&lt;BR /&gt;
Access-Challenge (11), id: 0x5c, Authenticator: 4a5051e21408fcb0f25eb794f08b3998&lt;BR /&gt;
State Attribute (24), length: 106, Value: 64CPMSessionID=0a083678VsRdGYwkon5XnlXinUbVtE4xg2G5Jp9VYxWEH0/ql2U;34SessionID=srv-ise-poc/334695666/92;&lt;BR /&gt;
EAP-Message Attribute (79), length: 8, Value: .d&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: .M&amp;gt;F.&lt;BR /&gt;
18:27:16.491115 IP (tos 0x0, ttl 64, id 0, offset 0, flags [df], proto UDP (17), length 355)&lt;BR /&gt;
X.X.X.X.41884 &amp;gt; srv-ise: RADIUS, length: 327&lt;BR /&gt;
Access-Request (1), id: 0x5d, Authenticator: 34a2b32737e5e7c059c32f31161a99b3&lt;BR /&gt;
User-Name Attribute (1), length: 8, Value: srojas&lt;BR /&gt;
EAP-Message Attribute (79), length: 168, Value: .d&lt;BR /&gt;
NAS-IP-Address Attribute (4), length: 6, Value: 10.8.54.121&lt;BR /&gt;
Service-Type Attribute (6), length: 6, Value: Login&lt;BR /&gt;
Calling-Station-Id Attribute (31), length: 19, Value: E8-6A-64-2E-6D-3A&lt;BR /&gt;
NAS-Port-Id Attribute (87), length: 4, Value: 21&lt;BR /&gt;
NAS-Port Attribute (5), length: 6, Value: 1021&lt;BR /&gt;
NAS-Port-Type Attribute (61), length: 6, Value: Ethernet&lt;BR /&gt;
State Attribute (24), length: 66, Value: 64CPMSessionID=0a083678VsRdGYwkon5XnlXinUbVtE4xg2G5Jp9VYxWEH0/ql&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: &amp;lt;.1.B.^.w....n..&lt;BR /&gt;
18:27:16.494422 IP (tos 0x0, ttl 64, id 11077, offset 0, flags [df], proto UDP (17), length 66)&lt;BR /&gt;
srv-ise &amp;gt; X.X.X.X.41884: RADIUS, length: 38&lt;BR /&gt;
Access-Reject (3), id: 0x5d, Authenticator: a7b41552a449bf5985ff3ec0b104379e&lt;BR /&gt;
Message-Authenticator Attribute (80), length: 18, Value: p.......3.@E^.$.</description>
      <pubDate>Fri, 21 Dec 2018 07:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/integration-extreme-switch-to-cisco-ise/m-p/51097#M13856</guid>
      <dc:creator>sebd44</dc:creator>
      <dc:date>2018-12-21T07:27:00Z</dc:date>
    </item>
  </channel>
</rss>

