Comware 3 Switches (3Com 4500, 5500, 5500G - H3C S3600, S5600) - EAPOL v2 and v3 being dropped.

2013-04-18 Thread Nick Lowe
Dear All, If anybody still uses any Comware v3 switches anywhere with 802.1X, they had a bug until recently where they would drop and not respond to all EAPOL v2 and v3 in flagrant violation to the 802.1X-2001 specification. These are switches such as: 3Com 4500, 5500 or 5500G series H3C S3600,

Re: Comware 3 Switches (3Com 4500, 5500, 5500G - H3C S3600, S5600) - EAPOL v2 and v3 being dropped.

2013-04-18 Thread Nick Lowe
In response to a private email I had asking for clarification, sorry, I meant the 10/100 4210s which run Comware v3, not 4210Gs which run Comware v5... The actual error you will see on such switched with terminal debugging enabled along with debugging dot1x all you'll see on afflicted devices is:

Re: Comware 3 Switches (3Com 4500, 5500, 5500G - H3C S3600, S5600) - EAPOL v2 and v3 being dropped.

2013-04-18 Thread Nick Lowe
Great, hit send by accident with a sentence half constructed. Hopefully you'll get the gist! - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: Comware 3 Switches (3Com 4500, 5500, 5500G - H3C S3600, S5600) - EAPOL v2 and v3 being dropped.

2013-04-18 Thread Paul Marchbank
Thanks for the heads up on this. We use some of these with dot1x. For reference to others, if you still have any 5500-SIs, that were discontinued years back, they do today run 5500-EI code with all features. Many folks still run these with old software because they do not know that this is the