Hi,
I am currently playing around with with an AP 205H and a Cisco 2960x
AOS Version: 6.4.3.7
IOS Version: 15.0(2a)EX5
Cisco Switch Model: Cisco 2960x
I have the AP 205H working the way I wanted on the Cisco with a simple configuration on the switch port. It basically only had switchport access configured with the VLAN for our APs.
I am not trying to implement wired 802.1x on the Cisco and have the AP perform 802.1x and then configure the 3 switch ports on the AP 205H to also perform 802.1x on any clients plugged in.
The first hurdle I am facing is that I do not see the 802.1x requests coming into the CPPM from the AP itself when it gets plugged in. However, I do it see it's MACAUTH attempt after 802.1x fails. I am currently using Eth0 on the back of the AP with the default port configuration. I have provisioned the AP with it's own user name and password and created a local account in the CPPM to authenticate against.
From the Aruba controller this is the status:
00:0b:86:xx:xx:xx CourtTest 192.168.xxx.xxx 0 AP:HT:11-/22.5/22.5 0 AP:VHT:132E/21/21 W-AP205 1FE2a 8h:57m:27s N/A
I beleive this is indicating that it failed 802.1x authentication.
Cisco switch port is configured as follows:
interface GigabitEthernet1/0/4
switchport mode access
switchport voice vlan 25
srr-queue bandwidth share 1 30 35 5
priority-queue out
authentication host-mode multi-auth
authentication order dot1x mab
authentication port-control auto
mab
mls qos trust dscp
dot1x pae authenticator
dot1x timeout tx-period 10
auto qos trust dscp
spanning-tree portfast
I am able to authenticate other devices with 802.1x such as laptops and desktops through this switch so I know that the 802.1x configuration on the switch is at least communicating with the CPPM. But I suspect I am configuring something wrong on the port when it comes to this AP.
I was looking at this article. There are some options that are used that do not appear to be available on our switch so I am not sure how relevant this configuration is.
Any help would greatly be appreciated.
Cheers