NAP 802.1x Enforcement – Switches we’ve tested w/NAPI've heard from countless people that they would like to see a list of 802.1x switches that we have seen working with NAP. My teammate Calvin Choe just blogged our up-to-date list of vendors / switches we have verified. Check it out! <p> </p><a title="http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx" href="http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx">http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx</a> <br><br><br>NAP the WORLD in 2007,<br><br>Jeff Sigman<br>NAP Release Manager<br><a title="mailto:Jeff.Sigman@online.microsoft.com" href="mailto:Jeff.Sigman@online.microsoft.com">Jeff.Sigman@online.microsoft.com</a> *<br><a title="http://blogs.technet.com/nap" href="http://blogs.technet.com/nap">http://blogs.technet.com/nap</a><br>*Remove the &quot;online&quot; to actually email me.<br>** This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.<br>© 2009 Microsoft Corporation. All rights reserved.Tue, 28 Jul 2009 20:59:30 Ze2d06107-c225-410b-874b-c0ecaf9fdf80http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#e2d06107-c225-410b-874b-c0ecaf9fdf80http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#e2d06107-c225-410b-874b-c0ecaf9fdf80Jeff Sigman {Mr. NAP}http://social.technet.microsoft.com/Profile/en-US/?user=Jeff%20Sigman%20%7bMr.%20NAP%7dNAP 802.1x Enforcement – Switches we’ve tested w/NAPI've heard from countless people that they would like to see a list of 802.1x switches that we have seen working with NAP. My teammate Calvin Choe just blogged our up-to-date list of vendors / switches we have verified. Check it out! <p> </p><a title="http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx" href="http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx">http://blogs.technet.com/nap/archive/2007/07/10/nap-802-1x-enforcement-switches-we-ve-tested-w-nap.aspx</a> <br><br><br>NAP the WORLD in 2007,<br><br>Jeff Sigman<br>NAP Release Manager<br><a title="mailto:Jeff.Sigman@online.microsoft.com" href="mailto:Jeff.Sigman@online.microsoft.com">Jeff.Sigman@online.microsoft.com</a> *<br><a title="http://blogs.technet.com/nap" href="http://blogs.technet.com/nap">http://blogs.technet.com/nap</a><br>*Remove the &quot;online&quot; to actually email me.<br>** This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.<br>Tue, 10 Jul 2007 20:56:16 Z2007-07-10T20:56:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#86b576c1-7d15-4406-bc9f-10ce7e158a01http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#86b576c1-7d15-4406-bc9f-10ce7e158a01Brijesh Kumar Shuklahttp://social.technet.microsoft.com/Profile/en-US/?user=Brijesh%20Kumar%20ShuklaNAP 802.1x Enforcement – Switches we’ve tested w/NAP<p align=left><font face=Arial size=2>Hi Jeff,</font></p> <p align=left>Thanks to publish the list of the swtches which can support NAP.</p> <p align=left>I can understand that all the switches can supposrt NAP for wired connection.</p> <p align=left>Suppose, If i would like to use wireless connection (Putting a wireless Acsess Point between switch and Vista client).</p> <p align=left>Do Cisco switch 3560 support for NAP for when packet arrived from wireless Accecc point.</p> <p align=left>My idea is....</p> <p align=left> </p> <p align=left>____________________________________</p> <p align=left>|                                                              |</p> <p align=left>|       __________________                        |</p> <p align=left>|      | Cicso Switch 3560    |                       |</p> <p align=left>|      |__________________|                       |</p> <p>|                   |                                          |</p> <p align=left>|                  |                                           |</p> <p align=left>|      --------------------------------------                  |</p> <p align=left>|      | wireless Access Point    |                 |</p> <p align=left>|      |_____________________|                 |</p> <p>|___________________________________|</p> <p align=left>                :</p> <p align=left>           Wireless link</p> <blockquote dir=ltr style="margin-right:0px"> <p align=left>      :</p></blockquote> <p align=left>_________:______________</p> <p align=left>|                                       |</p> <p align=left>|     NAP VISTA Client        |</p> <p align=left>|                                       |</p> <p align=left>|______________________|</p> <p align=left> </p> <p align=left>Kindly teach me on this scenario.</p> <p align=left>Regards</p> <p align=left>Brijesh Shukla</p>Thu, 11 Oct 2007 05:04:37 Z2007-10-11T05:04:37Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#4ebd0309-4636-42c3-b441-553c474bac3ahttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#4ebd0309-4636-42c3-b441-553c474bac3aMichael Kleef [MSFT]http://social.technet.microsoft.com/Profile/en-US/?user=Michael%20Kleef%20%5bMSFT%5dNAP 802.1x Enforcement – Switches we’ve tested w/NAP<p>Yes that will work with VLAN tagging. See my blog for an indication of how this is done with a Cisco switch.</p> <p align=left> </p> <p align=left>Go to blogs.technet.com/mkleef and click the category &quot;Blogcasts by me&quot;. I havent included the wireless bits but the base switch config is what youll need first.</p> <p align=left><font face=Arial size=2></font> </p>Thu, 20 Dec 2007 03:35:02 Z2007-12-20T03:35:02Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#02514543-be9b-42a6-821a-0468680f488ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#02514543-be9b-42a6-821a-0468680f488eMURATIRhttp://social.technet.microsoft.com/Profile/en-US/?user=MURATIRNAP 802.1x Enforcement – Switches we’ve tested w/NAP<p>Hello , </p> <p align=left> </p> <p align=left>If you want to use NAP over Wireless network. You may need a wireless LAN Controller. Because Wireless Access Points cannot support Dynamic VLAN ing.</p> <p align=left> </p> <p align=left>Regards.</p> <p align=left><font face=Arial size=2></font> </p>Tue, 18 Mar 2008 14:03:26 Z2008-03-18T14:03:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#662e83dc-4ed0-4dff-b651-a6529330d437http://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#662e83dc-4ed0-4dff-b651-a6529330d437Roel_85http://social.technet.microsoft.com/Profile/en-US/?user=Roel_85NAP 802.1x Enforcement – Switches we’ve tested w/NAP Hi,<br><br>I've search all throuch the internet, but can't find any valuable information about which 802.1x modes NAP exactly supports.<br>There are several different 802.1x possibility, like:<br><br> <table class="apps_tablecolor" cellspacing=1 cellpadding=3 width="100%" border=0> <tbody> <tr bgcolor="#ffffff"> <td align=left><span class=modulecontent><input type=checkbox value=7426><font size=2>  </font><a class=modulecontentlink><font size=2>IEEE 802.1X Multi-Domain Authentication</font></a></span><br><span><font size=2><input type=checkbox value=6785></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x - Auth Fail Open</font></a></span><br><span><font size=2><input type=checkbox value=6535></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x - Auth Fail VLAN</font></a></span><br><span><font size=2><input type=checkbox value=2222></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x - VLAN Assignment</font></a></span><br><span><font size=2><input type=checkbox value=6079></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x - Wake on LAN Support</font></a></span><br><span><font size=2><input type=checkbox value=4487></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Authenticator</font></a></span><br><span><font size=2><input type=checkbox value=6222></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Guest VLAN</font></a></span><br><span><font size=2><input type=checkbox value=7853></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Local Authentication for Cisco LEAP</font></a></span><br><span><font size=2><input type=checkbox value=5787></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Local Authentication for EAP-FAST</font></a></span><br><span><font size=2><input type=checkbox value=6127></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Private Guest VLAN</font></a></span><br><span><font size=2><input type=checkbox value=6126></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Private VLAN Assignment</font></a></span><br><span><font size=2><input type=checkbox value=2526></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x RADIUS Accounting</font></a></span><br><span><font size=2><input type=checkbox value=6129></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Radius-Supplied Session Timeout</font></a></span><br><span><font size=2><input type=checkbox value=3858></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Supplicant</font></a></span><br><span><font size=2><input type=checkbox value=6437></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x with DHCP</font></a></span><br><span><font size=2><input type=checkbox value=2527></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x with Port Security</font></a></span><br><span><font size=2><input type=checkbox value=6085></font>  <a class=modulecontentlink><font size=2>NAC - L2 IEEE 802.1x</font></a></span><br><span><font size=2><input type=checkbox value=2526></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x RADIUS Accounting</font></a></span><br> <tr bgcolor="#99cccc"> <td><span class=modulesection><font size=2>Technology - Security and VPN<br>Sub Technology - Authentication Protocols</font></span></td></tr> <tr bgcolor="#ffffff"> <td align=left><span class=modulecontent><font size=2><input type=checkbox value=3858>  </font><a class=modulecontentlink><font size=2>IEEE 802.1x Supplicant</font></a></span><br><span><font size=2><input type=checkbox value=2112></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x - VPN Access Control</font></a></span><br> <tr bgcolor="#99cccc"> <td><span class=modulesection><font size=2>Technology - Wireless / Mobility<br>Sub Technology - Wireless, LAN (WLAN)</font></span></td></tr> <tr bgcolor="#ffffff"> <td align=left><span class=modulecontent><font size=2><input type=checkbox value=7477>  </font><a class=modulecontentlink><font size=2>IEEE 802.1x Supplicant Support for Cisco LEAP</font></a></span><br><span><font size=2><input type=checkbox value=4931></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Supplicant Support for EAP-FAST</font></a></span><br><span><font size=2><input type=checkbox value=7475></font>  <a class=modulecontentlink><font size=2>IEEE 802.1x Supplicant Support for EAP-TLS</font></a></span></td></tr></tbody></table><br>Also i found somewere that the switch has to support something such as RADIUS tunneling attribute or something? Can't find it anymore :(<br><br>But the reason that i ask which 802.1x components NAP require, is that i can search for some low end model, or end of life models, like a Cisco 3600 series, or 2950 series.<br><br>Sow what 802.1x components has the switch or AP to support, in order to get NAP working?<br><br>thanks in advance.Tue, 04 Nov 2008 13:44:29 Z2008-11-04T13:44:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#2ee67fb4-e703-420c-b4ee-7e9b7ff054cdhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#2ee67fb4-e703-420c-b4ee-7e9b7ff054cddrientieshttp://social.technet.microsoft.com/Profile/en-US/?user=drientiesNAP 802.1x Enforcement – Switches we’ve tested w/NAP If i'm correct it should support <a class=modulecontentlink><font color="#0072bc" size=2>IEEE 802.1x - VLAN Assignment</font></a> for dynamic VLAN switching under NAP, but basicly the device should accept RADIUS attributes  and apply them.<br>The RADIUS Attributes I used in my research are: <br><br>64 (Tunnel Type)<br>65 (Tunnel Medium Type)<br>81 (Tunnel Private Group ID)<br><br>perhaps some vendors use specific attributes for VLAN assigment, but these standard ones do the trick on my tested equipment<br><br>In my research of NAP i found that the following cisco devices &quot;should&quot; support this feature, provided they have a recent IOS to support the feature:<br><br>2940       IOS 12.1(22)EA4<br>2960       IOS 12.2(25)SED<br>2980       CatOS 8.4GLX<br>3550       IOS 12.1(14)EA1<br>3560       IOS 12.2(25)SED<br>3750       IOS 12.2(25)SED<br>4000*     CatOS 8.4GLX or IOS 12.1(19)EW<br>4500*     CatOS 8.4GLX or IOS 12.1(19)EW<br>6500       CatOS 7.2 or IOS 12.1(13)E4<br><br><font style="font-size:10px">* Supervisor II+ or higher<br><br><font style="font-size:12px">This list is far from complete, these are just devices that are in use in my organisation which i checked for NAP capabilities</font></font>Wed, 05 Nov 2008 12:43:07 Z2008-11-05T12:43:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#43d25933-3835-4921-8731-574d21876fcchttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#43d25933-3835-4921-8731-574d21876fccGerd Schelberthttp://social.technet.microsoft.com/Profile/en-US/?user=Gerd%20SchelbertNAP 802.1x Enforcement – Switches we’ve tested w/NAP<p> Hi Muratir.<br><br>Imho your list shows, why so many companies stuck to implement dot1x (aka 802.1x)-based solutions.</p> <p>Basically you only need the support for 802.1x-authentication using PEAP with MS-ChapV2 or certificate as EAP-Method. Then you can have an &quot;on/off-decision&quot; at the switchport.<br><br>Most of the other mentioned functions in your list, which is in fact part of a featurelist for Cisco-IOS-devices, are needed because life is not fair;-)<br><br>In a heterogeneous network-setup with multivendor-equipment as network- and systemdevice, you will need more functions, for instance for realising guest-networks fpr non-authenticated devices, additional authentication-methods like MAC-based Auth, failsafe-network-segments for a basic network-functionality in case of troubles with the dot1x-implementation, authentication-based VLAN-switching (if all your clients are able to understand a dynamic ip-address-change) etc etc.<br><br>So at the end your total solution design defines which functions your network access devices must have to implement your special solution.<br><br>Too complicated? Perhaps think about different enforcement methods like dhcp or inline-filtering-devices like consentry instead of using dot1x or wait for more featurecomplete versions of 802.1x in some years ;-) The last and incomplete revision of the standard is from 2004, which is far away from todays technologies.<br><br>Best regards<br><br>Gerd Schelbert</p> <p> </p>Thu, 08 Jan 2009 13:54:54 Z2009-01-08T13:54:54Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#a79dfc21-dbbd-4f7f-84c1-f02f44c95b9chttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#a79dfc21-dbbd-4f7f-84c1-f02f44c95b9cgroquehttp://social.technet.microsoft.com/Profile/en-US/?user=groqueNAP 802.1x Enforcement – Switches we’ve tested w/NAPHi I got Radius assigned vlan(s) to work on a Cisco Aironet 1231G with firmware 12.3(8)EB. Works great! if anybody needs any help let me know.Tue, 19 May 2009 22:41:05 Z2009-05-19T22:41:05Zhttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#67a5ae9a-8e54-4a1f-a9ba-11d73588fd9ehttp://social.technet.microsoft.com/Forums/en-US/winserverNAP/thread/e2d06107-c225-410b-874b-c0ecaf9fdf80#67a5ae9a-8e54-4a1f-a9ba-11d73588fd9eDagmar Heideckerhttp://social.technet.microsoft.com/Profile/en-US/?user=Dagmar%20HeideckerNAP 802.1x Enforcement – Switches we’ve tested w/NAPHi,<br/><br/>I have got a D-Link DES-3828 which is on your list but I cannot find any option to configure dynamic vlans. The manual does not mention it at all. Do you have a configuration hint for me?<br/><br/>Thanks a lot!Tue, 28 Jul 2009 20:59:30 Z2009-07-28T20:59:30Z