diagnose_dot1x
Diagnose 802.1X authentication failures: paste RADIUS/ISE log, switchport config, or supplicant log. Root causes include EAP mismatch, unknown CA, shared-secret, missing VLAN, CoA NAK, dACL; get fixes for switch and ISE.
Instructions
Diagnose a port that will not authenticate. Paste any of: the RADIUS/ISE authentication log, the switchport interface config, the supplicant (Windows wired AutoConfig) log. Names the root cause — EAP method mismatch, unknown CA, shared-secret/NAD mismatch, missing dynamic VLAN, CoA NAK on the wrong port, invalid dACL — decodes ISE failure codes, and gives the fix on the switch AND in ISE. Read-only, rule-based.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| radius_log | No | ||
| supplicant_log | No | ||
| switchport_config | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |