<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False authentication sessions problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248057#M110022</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I observe undesirable behavior of my Cisco 3560 switches,&amp;nbsp; which keep authentication sessions for devices that are currently not&amp;nbsp; connected to the network.&lt;/P&gt;&lt;P&gt;To be precise, I mean the sessions relating to the devices that&amp;nbsp; haven't been successfully authenticated and as the result the switch is&amp;nbsp; trying to re-authenticate it. The problem shows up when the device is no&amp;nbsp; longer connected to the network, but switch is still keeping that&amp;nbsp; authentication session (ineffectively trying to authenticate the device&amp;nbsp; that is no longer connected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example - int fa0/37 - on that interface is connected 6 devices, while current authentication sessions are 36:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;BR /&gt; 16:54:10.793 CEST Fri Jun 7 2013&lt;BR /&gt; SW1#&lt;STRONG&gt;sh mac add int Fa0/37 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mac Address Table&lt;BR /&gt; -------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt; ---- ----------- -------- -----&lt;/P&gt;&lt;P&gt;82 0012.3fb9.5b3f STATIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.0f31 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.10d9 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.1440 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.39dc DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 6cf0.4929.4aa8 DYNAMIC Fa0/37&lt;BR /&gt; Total Mac Addresses for this criterion: 6&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; SW1#&lt;STRONG&gt;sh auth sess | i 0/37&lt;/STRONG&gt;&lt;BR /&gt; Fa0/37 f0de.f15f.3332 N/A DATA Authz Failed 0ACA022A000004751725F612&lt;BR /&gt; Fa0/37 28d2.4401.8591 N/A DATA Authz Failed 0ACA022A000005AE9C6AB46B&lt;BR /&gt; Fa0/37 0024.1dab.5943 N/A DATA Authz Failed 0ACA022A0000008B630B988D&lt;BR /&gt; Fa0/37 0024.1d0b.bd9d dot1x DATA Running 0ACA022A000005867DC8BA06&lt;BR /&gt; Fa0/37 28d2.4408.0f31 dot1x DATA Running 0ACA022A000005C2AC8D0728&lt;BR /&gt; Fa0/37 f0de.f152.2266 N/A DATA Authz Failed 0ACA022A000000DE8CD63254&lt;BR /&gt; Fa0/37 0021.86ff.b4f2 N/A DATA Authz Failed 0ACA022A000005495F07FBBD&lt;BR /&gt; Fa0/37 f04d.a251.6135 mab DATA Authz Failed 0ACA022A0000043D0D549EA9&lt;BR /&gt; Fa0/37 28d2.4408.1440 dot1x DATA Running 0ACA022A000005C1AC8CD8D3&lt;BR /&gt; Fa0/37 0021.ccd8.095c dot1x DATA Running 0ACA022A000004781740E560&lt;BR /&gt; Fa0/37 5cf9.dd41.6a35 mab DATA Authz Failed 0ACA022A0000044E11EA7A95&lt;BR /&gt; Fa0/37 0012.3fb9.5b3f dot1x DATA Authz Success 0ACA022A0000003924E5D007&lt;BR /&gt; Fa0/37 5cf9.dd41.6c06 mab DATA Authz Failed 0ACA022A0000044F11EF1A3B&lt;BR /&gt; Fa0/37 0021.cc6e.3db3 dot1x DATA Running 0ACA022A000004A921E704A2&lt;BR /&gt; Fa0/37 0021.ccd0.1487 N/A DATA Authz Failed 0ACA022A00000479175405FF&lt;BR /&gt; Fa0/37 0021.ccd7.e67f dot1x DATA Running 0ACA022A0000055E6012F3D3&lt;BR /&gt; Fa0/37 28d2.4407.209d N/A DATA Authz Failed 0ACA022A0000045012089F38&lt;BR /&gt; Fa0/37 0011.4302.d91b N/A DATA Authz Failed 0ACA022A000004A721363771&lt;BR /&gt; Fa0/37 28d2.4408.10d9 dot1x DATA Running 0ACA022A000005C0AC8CAB1D&lt;BR /&gt; Fa0/37 0013.72ca.549e N/A DATA Authz Failed 0ACA022A0000009F6D129B84&lt;BR /&gt; Fa0/37 28d2.4406.28e2 N/A DATA Authz Failed 0ACA022A00000376D9E4E000&lt;BR /&gt; Fa0/37 0024.7e10.ef3a N/A DATA Authz Failed 0ACA022A0000003B254891A7&lt;BR /&gt; Fa0/37 0026.1823.fa2f dot1x DATA Running 0ACA022A000000D3872D60E0&lt;BR /&gt; Fa0/37 3c97.0e83.f722 N/A DATA Authz Failed 0ACA022A000003DFE8AB9EB6&lt;BR /&gt; Fa0/37 70f3.9513.c315 dot1x DATA Running 0ACA022A0000050540434445&lt;BR /&gt; Fa0/37 6cf0.4929.4aa8 N/A DATA Authz Failed 0ACA022A0000003A24E64567&lt;BR /&gt; Fa0/37 001d.7284.4cae dot1x DATA Running 0ACA022A0000008C63D0E95F&lt;BR /&gt; Fa0/37 70f3.9513.c420 N/A DATA Authz Failed 0ACA022A00000103B00B97CC&lt;BR /&gt; Fa0/37 28d2.4408.39dc dot1x DATA Running 0ACA022A000005C3AC8D33D2&lt;BR /&gt; Fa0/37 0013.72b8.ec0b dot1x DATA Running 0ACA022A0000056D695D4C5D&lt;BR /&gt; Fa0/37 5cf9.dd41.6c80 mab DATA Authz Failed 0ACA022A000004360D108AA4&lt;BR /&gt; Fa0/37 000f.1fe4.6f9f N/A DATA Authz Failed 0ACA022A000000E39161ABC9&lt;BR /&gt; Fa0/37 001e.3736.9a6a N/A DATA Authz Failed 0ACA022A000004831C16033E&lt;BR /&gt; Fa0/37 0024.7eda.ab58 N/A DATA Authz Failed 0ACA022A0000030ED4955421&lt;BR /&gt; Fa0/37 28d2.4402.4bbf N/A DATA Authz Failed 0ACA022A0000005139D52E1E&lt;BR /&gt; Fa0/37 0018.8b0c.7882 N/A DATA Authz Failed 0ACA022A000004CC30DD0119&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;BR /&gt; 16:54:21.891 CEST Fri Jun 7 2013&lt;BR /&gt; SW1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the "clear authentication sess session-id …" executed for that "hanging" session causes its removal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000004CC30DD0119&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A0000005139D52E1E&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A0000030ED4955421&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000004831C16033E&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000000E39161ABC9&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh auth sess | i 0/37&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Fa0/37 f0de.f15f.3332 N/A DATA Authz Failed 0ACA022A000004751725F612&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4401.8591 N/A DATA Authz Failed 0ACA022A000005AE9C6AB46B&lt;/P&gt;&lt;P&gt;Fa0/37 0024.1dab.5943 N/A DATA Authz Failed 0ACA022A0000008B630B988D&lt;/P&gt;&lt;P&gt;Fa0/37 0024.1d0b.bd9d N/A DATA Authz Failed 0ACA022A000005867DC8BA06&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.0f31 dot1x DATA Running 0ACA022A000005C2AC8D0728&lt;/P&gt;&lt;P&gt;Fa0/37 f0de.f152.2266 N/A DATA Authz Failed 0ACA022A000000DE8CD63254&lt;/P&gt;&lt;P&gt;Fa0/37 0021.86ff.b4f2 N/A DATA Authz Failed 0ACA022A000005495F07FBBD&lt;/P&gt;&lt;P&gt;Fa0/37 f04d.a251.6135 mab DATA Authz Failed 0ACA022A0000043D0D549EA9&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.1440 dot1x DATA Running 0ACA022A000005C1AC8CD8D3&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd8.095c dot1x DATA Running 0ACA022A000004781740E560&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6a35 mab DATA Authz Failed 0ACA022A0000044E11EA7A95&lt;/P&gt;&lt;P&gt;Fa0/37 0012.3fb9.5b3f dot1x DATA Authz Success 0ACA022A0000003924E5D007&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6c06 mab DATA Authz Failed 0ACA022A0000044F11EF1A3B&lt;/P&gt;&lt;P&gt;Fa0/37 0021.cc6e.3db3 dot1x DATA Running 0ACA022A000004A921E704A2&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd0.1487 dot1x DATA Running 0ACA022A00000479175405FF&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd7.e67f dot1x DATA Running 0ACA022A0000055E6012F3D3&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4407.209d dot1x DATA Running 0ACA022A0000045012089F38&lt;/P&gt;&lt;P&gt;Fa0/37 0011.4302.d91b N/A DATA Authz Failed 0ACA022A000004A721363771&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.10d9 dot1x DATA Running 0ACA022A000005C0AC8CAB1D&lt;/P&gt;&lt;P&gt;Fa0/37 0013.72ca.549e N/A DATA Authz Failed 0ACA022A0000009F6D129B84&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4406.28e2 dot1x DATA Running 0ACA022A00000376D9E4E000&lt;/P&gt;&lt;P&gt;Fa0/37 0024.7e10.ef3a N/A DATA Authz Failed 0ACA022A0000003B254891A7&lt;/P&gt;&lt;P&gt;Fa0/37 0026.1823.fa2f dot1x DATA Running 0ACA022A000000D3872D60E0&lt;/P&gt;&lt;P&gt;Fa0/37 3c97.0e83.f722 N/A DATA Authz Failed 0ACA022A000003DFE8AB9EB6&lt;/P&gt;&lt;P&gt;Fa0/37 70f3.9513.c315 dot1x DATA Running 0ACA022A0000050540434445&lt;/P&gt;&lt;P&gt;Fa0/37 6cf0.4929.4aa8 N/A DATA Authz Failed 0ACA022A0000003A24E64567&lt;/P&gt;&lt;P&gt;Fa0/37 001d.7284.4cae dot1x DATA Running 0ACA022A0000008C63D0E95F&lt;/P&gt;&lt;P&gt;Fa0/37 70f3.9513.c420 N/A DATA Authz Failed 0ACA022A00000103B00B97CC&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.39dc dot1x DATA Running 0ACA022A000005C3AC8D33D2&lt;/P&gt;&lt;P&gt;Fa0/37 0013.72b8.ec0b dot1x DATA Running 0ACA022A0000056D695D4C5D&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6c80 mab DATA Authz Failed 0ACA022A000004360D108AA4&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;17:08:54.372 CEST Fri Jun 7 2013&lt;/P&gt;&lt;P&gt;SW1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh ver&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3560 Software (C3560-IPBASEK9-M), Version 12.2(55)SE7, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" rel="nofollow" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2013 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Mon 28-Jan-13 10:10 by prod_rel_team&lt;/P&gt;&lt;P&gt;Image text-base: 0x01000000, data-base: 0x02D00000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone tell me what is the reason of that switch behavior and what needs to be done to prevent that kind of situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also use Identity Service Engine 1.1.1 and 802.1x authentication. "&lt;STRONG&gt;sh dot1x interface fa0/37 details&lt;/STRONG&gt;" in attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need anything, don’t hesitate to ask me, please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would sincerely appreciate your consideration of this matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:31:45 GMT</pubDate>
    <dc:creator>kluczak16</dc:creator>
    <dc:date>2019-03-11T03:31:45Z</dc:date>
    <item>
      <title>False authentication sessions problem</title>
      <link>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248057#M110022</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I observe undesirable behavior of my Cisco 3560 switches,&amp;nbsp; which keep authentication sessions for devices that are currently not&amp;nbsp; connected to the network.&lt;/P&gt;&lt;P&gt;To be precise, I mean the sessions relating to the devices that&amp;nbsp; haven't been successfully authenticated and as the result the switch is&amp;nbsp; trying to re-authenticate it. The problem shows up when the device is no&amp;nbsp; longer connected to the network, but switch is still keeping that&amp;nbsp; authentication session (ineffectively trying to authenticate the device&amp;nbsp; that is no longer connected).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example - int fa0/37 - on that interface is connected 6 devices, while current authentication sessions are 36:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;BR /&gt; 16:54:10.793 CEST Fri Jun 7 2013&lt;BR /&gt; SW1#&lt;STRONG&gt;sh mac add int Fa0/37 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mac Address Table&lt;BR /&gt; -------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan Mac Address Type Ports&lt;BR /&gt; ---- ----------- -------- -----&lt;/P&gt;&lt;P&gt;82 0012.3fb9.5b3f STATIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.0f31 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.10d9 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.1440 DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 28d2.4408.39dc DYNAMIC Fa0/37 &lt;/P&gt;&lt;P&gt;82 6cf0.4929.4aa8 DYNAMIC Fa0/37&lt;BR /&gt; Total Mac Addresses for this criterion: 6&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; SW1#&lt;STRONG&gt;sh auth sess | i 0/37&lt;/STRONG&gt;&lt;BR /&gt; Fa0/37 f0de.f15f.3332 N/A DATA Authz Failed 0ACA022A000004751725F612&lt;BR /&gt; Fa0/37 28d2.4401.8591 N/A DATA Authz Failed 0ACA022A000005AE9C6AB46B&lt;BR /&gt; Fa0/37 0024.1dab.5943 N/A DATA Authz Failed 0ACA022A0000008B630B988D&lt;BR /&gt; Fa0/37 0024.1d0b.bd9d dot1x DATA Running 0ACA022A000005867DC8BA06&lt;BR /&gt; Fa0/37 28d2.4408.0f31 dot1x DATA Running 0ACA022A000005C2AC8D0728&lt;BR /&gt; Fa0/37 f0de.f152.2266 N/A DATA Authz Failed 0ACA022A000000DE8CD63254&lt;BR /&gt; Fa0/37 0021.86ff.b4f2 N/A DATA Authz Failed 0ACA022A000005495F07FBBD&lt;BR /&gt; Fa0/37 f04d.a251.6135 mab DATA Authz Failed 0ACA022A0000043D0D549EA9&lt;BR /&gt; Fa0/37 28d2.4408.1440 dot1x DATA Running 0ACA022A000005C1AC8CD8D3&lt;BR /&gt; Fa0/37 0021.ccd8.095c dot1x DATA Running 0ACA022A000004781740E560&lt;BR /&gt; Fa0/37 5cf9.dd41.6a35 mab DATA Authz Failed 0ACA022A0000044E11EA7A95&lt;BR /&gt; Fa0/37 0012.3fb9.5b3f dot1x DATA Authz Success 0ACA022A0000003924E5D007&lt;BR /&gt; Fa0/37 5cf9.dd41.6c06 mab DATA Authz Failed 0ACA022A0000044F11EF1A3B&lt;BR /&gt; Fa0/37 0021.cc6e.3db3 dot1x DATA Running 0ACA022A000004A921E704A2&lt;BR /&gt; Fa0/37 0021.ccd0.1487 N/A DATA Authz Failed 0ACA022A00000479175405FF&lt;BR /&gt; Fa0/37 0021.ccd7.e67f dot1x DATA Running 0ACA022A0000055E6012F3D3&lt;BR /&gt; Fa0/37 28d2.4407.209d N/A DATA Authz Failed 0ACA022A0000045012089F38&lt;BR /&gt; Fa0/37 0011.4302.d91b N/A DATA Authz Failed 0ACA022A000004A721363771&lt;BR /&gt; Fa0/37 28d2.4408.10d9 dot1x DATA Running 0ACA022A000005C0AC8CAB1D&lt;BR /&gt; Fa0/37 0013.72ca.549e N/A DATA Authz Failed 0ACA022A0000009F6D129B84&lt;BR /&gt; Fa0/37 28d2.4406.28e2 N/A DATA Authz Failed 0ACA022A00000376D9E4E000&lt;BR /&gt; Fa0/37 0024.7e10.ef3a N/A DATA Authz Failed 0ACA022A0000003B254891A7&lt;BR /&gt; Fa0/37 0026.1823.fa2f dot1x DATA Running 0ACA022A000000D3872D60E0&lt;BR /&gt; Fa0/37 3c97.0e83.f722 N/A DATA Authz Failed 0ACA022A000003DFE8AB9EB6&lt;BR /&gt; Fa0/37 70f3.9513.c315 dot1x DATA Running 0ACA022A0000050540434445&lt;BR /&gt; Fa0/37 6cf0.4929.4aa8 N/A DATA Authz Failed 0ACA022A0000003A24E64567&lt;BR /&gt; Fa0/37 001d.7284.4cae dot1x DATA Running 0ACA022A0000008C63D0E95F&lt;BR /&gt; Fa0/37 70f3.9513.c420 N/A DATA Authz Failed 0ACA022A00000103B00B97CC&lt;BR /&gt; Fa0/37 28d2.4408.39dc dot1x DATA Running 0ACA022A000005C3AC8D33D2&lt;BR /&gt; Fa0/37 0013.72b8.ec0b dot1x DATA Running 0ACA022A0000056D695D4C5D&lt;BR /&gt; Fa0/37 5cf9.dd41.6c80 mab DATA Authz Failed 0ACA022A000004360D108AA4&lt;BR /&gt; Fa0/37 000f.1fe4.6f9f N/A DATA Authz Failed 0ACA022A000000E39161ABC9&lt;BR /&gt; Fa0/37 001e.3736.9a6a N/A DATA Authz Failed 0ACA022A000004831C16033E&lt;BR /&gt; Fa0/37 0024.7eda.ab58 N/A DATA Authz Failed 0ACA022A0000030ED4955421&lt;BR /&gt; Fa0/37 28d2.4402.4bbf N/A DATA Authz Failed 0ACA022A0000005139D52E1E&lt;BR /&gt; Fa0/37 0018.8b0c.7882 N/A DATA Authz Failed 0ACA022A000004CC30DD0119&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;BR /&gt; 16:54:21.891 CEST Fri Jun 7 2013&lt;BR /&gt; SW1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only the "clear authentication sess session-id …" executed for that "hanging" session causes its removal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000004CC30DD0119&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A0000005139D52E1E&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A0000030ED4955421&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000004831C16033E&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;clear auth sess sess 0ACA022A000000E39161ABC9&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh auth sess | i 0/37&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Fa0/37 f0de.f15f.3332 N/A DATA Authz Failed 0ACA022A000004751725F612&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4401.8591 N/A DATA Authz Failed 0ACA022A000005AE9C6AB46B&lt;/P&gt;&lt;P&gt;Fa0/37 0024.1dab.5943 N/A DATA Authz Failed 0ACA022A0000008B630B988D&lt;/P&gt;&lt;P&gt;Fa0/37 0024.1d0b.bd9d N/A DATA Authz Failed 0ACA022A000005867DC8BA06&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.0f31 dot1x DATA Running 0ACA022A000005C2AC8D0728&lt;/P&gt;&lt;P&gt;Fa0/37 f0de.f152.2266 N/A DATA Authz Failed 0ACA022A000000DE8CD63254&lt;/P&gt;&lt;P&gt;Fa0/37 0021.86ff.b4f2 N/A DATA Authz Failed 0ACA022A000005495F07FBBD&lt;/P&gt;&lt;P&gt;Fa0/37 f04d.a251.6135 mab DATA Authz Failed 0ACA022A0000043D0D549EA9&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.1440 dot1x DATA Running 0ACA022A000005C1AC8CD8D3&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd8.095c dot1x DATA Running 0ACA022A000004781740E560&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6a35 mab DATA Authz Failed 0ACA022A0000044E11EA7A95&lt;/P&gt;&lt;P&gt;Fa0/37 0012.3fb9.5b3f dot1x DATA Authz Success 0ACA022A0000003924E5D007&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6c06 mab DATA Authz Failed 0ACA022A0000044F11EF1A3B&lt;/P&gt;&lt;P&gt;Fa0/37 0021.cc6e.3db3 dot1x DATA Running 0ACA022A000004A921E704A2&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd0.1487 dot1x DATA Running 0ACA022A00000479175405FF&lt;/P&gt;&lt;P&gt;Fa0/37 0021.ccd7.e67f dot1x DATA Running 0ACA022A0000055E6012F3D3&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4407.209d dot1x DATA Running 0ACA022A0000045012089F38&lt;/P&gt;&lt;P&gt;Fa0/37 0011.4302.d91b N/A DATA Authz Failed 0ACA022A000004A721363771&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.10d9 dot1x DATA Running 0ACA022A000005C0AC8CAB1D&lt;/P&gt;&lt;P&gt;Fa0/37 0013.72ca.549e N/A DATA Authz Failed 0ACA022A0000009F6D129B84&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4406.28e2 dot1x DATA Running 0ACA022A00000376D9E4E000&lt;/P&gt;&lt;P&gt;Fa0/37 0024.7e10.ef3a N/A DATA Authz Failed 0ACA022A0000003B254891A7&lt;/P&gt;&lt;P&gt;Fa0/37 0026.1823.fa2f dot1x DATA Running 0ACA022A000000D3872D60E0&lt;/P&gt;&lt;P&gt;Fa0/37 3c97.0e83.f722 N/A DATA Authz Failed 0ACA022A000003DFE8AB9EB6&lt;/P&gt;&lt;P&gt;Fa0/37 70f3.9513.c315 dot1x DATA Running 0ACA022A0000050540434445&lt;/P&gt;&lt;P&gt;Fa0/37 6cf0.4929.4aa8 N/A DATA Authz Failed 0ACA022A0000003A24E64567&lt;/P&gt;&lt;P&gt;Fa0/37 001d.7284.4cae dot1x DATA Running 0ACA022A0000008C63D0E95F&lt;/P&gt;&lt;P&gt;Fa0/37 70f3.9513.c420 N/A DATA Authz Failed 0ACA022A00000103B00B97CC&lt;/P&gt;&lt;P&gt;Fa0/37 28d2.4408.39dc dot1x DATA Running 0ACA022A000005C3AC8D33D2&lt;/P&gt;&lt;P&gt;Fa0/37 0013.72b8.ec0b dot1x DATA Running 0ACA022A0000056D695D4C5D&lt;/P&gt;&lt;P&gt;Fa0/37 5cf9.dd41.6c80 mab DATA Authz Failed 0ACA022A000004360D108AA4&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh clock&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;17:08:54.372 CEST Fri Jun 7 2013&lt;/P&gt;&lt;P&gt;SW1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1#&lt;STRONG&gt;sh ver&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3560 Software (C3560-IPBASEK9-M), Version 12.2(55)SE7, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" rel="nofollow" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2013 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Mon 28-Jan-13 10:10 by prod_rel_team&lt;/P&gt;&lt;P&gt;Image text-base: 0x01000000, data-base: 0x02D00000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone tell me what is the reason of that switch behavior and what needs to be done to prevent that kind of situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also use Identity Service Engine 1.1.1 and 802.1x authentication. "&lt;STRONG&gt;sh dot1x interface fa0/37 details&lt;/STRONG&gt;" in attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need anything, don’t hesitate to ask me, please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would sincerely appreciate your consideration of this matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248057#M110022</guid>
      <dc:creator>kluczak16</dc:creator>
      <dc:date>2019-03-11T03:31:45Z</dc:date>
    </item>
    <item>
      <title>False authentication sessions problem</title>
      <link>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248058#M110065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The switch doesn't know to flush the session after the Client goes because the other switch you're plugging everything in to keeps the interface up... The switch never actually knows the Client has gone, just that it's not communicating any more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There will be ("should be"!) an automated timer somewhere that flushes these idle sessions.&amp;nbsp; I expect there'll be a specific bit of Dot1x config for this (the re-auth timer, perhaps?), but it could be as simple as the MAC Address-Table Aging-Time?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jun 2013 14:33:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248058#M110065</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-06-15T14:33:59Z</dc:date>
    </item>
    <item>
      <title>False authentication sessions problem</title>
      <link>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248059#M110089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you so much for replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually all the switches are configured as following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/37&lt;/P&gt;&lt;P&gt; switchport access vlan 18&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport nonegotiate&lt;/P&gt;&lt;P&gt; switchport voice vlan 24&lt;/P&gt;&lt;P&gt; qos trust dscp&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication order mab dot1x&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; auto qos voip trust&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; tx-queue 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; priority high&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; shape percent 33&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; service-policy output autoqos-voip-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something wrong with the port config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking forward to hearing from you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 10:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248059#M110089</guid>
      <dc:creator>kluczak16</dc:creator>
      <dc:date>2013-06-17T10:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: False authentication sessions problem</title>
      <link>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248060#M110122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've said it before, and I'll say it again &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In an actual deployment, the last/default authorization rule should permit to do CWA or/and profiling, so that any unauthenticated MAB user should get a match on this rule, thus not restarting auth process. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the idle sessions, you cand use &lt;STRONG&gt;authetication timer inactivity &lt;/STRONG&gt;comand. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_a3.html#wp1060094" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/ios/security/command/reference/sec_a3.html#wp1060094&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Jun 2013 20:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/false-authentication-sessions-problem/m-p/2248060#M110122</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2013-06-22T20:49:40Z</dc:date>
    </item>
  </channel>
</rss>

