<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 1.1.3 posture status OK but network connection failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168043#M128251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please clarify the issue you are experiencing from the endpoint (is this performing dot1x)? I see the username in the logs but I am a litte confused as to the debugs and the screenshot you provided. Also please provide a screenshot of your authorization policy and DACLs that are configured on ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are quite a few bugs regarding the 12.2(55)SE7 release and I wanted to know if you are plugging in behind an ip phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide the running configuration of the port "show run interface..." I would like to see the entire acl configuration "show run | sec ip access-list", I would also like to see the following commands during the user connection stage (one for when it first plugs in, another when its in the posture uknown state, and then again after the final access-accept) "show authentication session interface ..." along with the "show ip access-list interface xxx" along with a debug radius authentication for the entire event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Apr 2013 23:52:30 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-04-02T23:52:30Z</dc:date>
    <item>
      <title>ISE 1.1.3 posture status OK but network connection failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168040#M128243</link>
      <description>&lt;P&gt;hello, &lt;/P&gt;&lt;P&gt;I am on my way to make this ISE works.&lt;/P&gt;&lt;P&gt;Now I am able to do posture assessment and reauthenticate with success.&lt;/P&gt;&lt;P&gt;The logs says that's OK, I have two lines.&lt;/P&gt;&lt;P&gt;NACAgent on the host do the job correctly but the NIC says : "Network failure" despite NACagent grants the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Ideas folks ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch says : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03:04:28: %AUTHMGR-5-START: Starting 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8&lt;/P&gt;&lt;P&gt;03:04:59: %DOT1X-5-FAIL: Authentication failed for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID&lt;/P&gt;&lt;P&gt;03:04:59: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8&lt;/P&gt;&lt;P&gt;03:04:59: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8&lt;/P&gt;&lt;P&gt;03:04:59: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8&lt;/P&gt;&lt;P&gt;03:04:59: %AUTHMGR-5-FAIL: Authorization failed for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the SW's config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group radius&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt; client 192.168.6.10 server-key 123456789&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no ip domain-lookup&lt;/P&gt;&lt;P&gt;ip domain-name security.com&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.6.29 192.168.6.100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 192.168.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp snooping vlan 1&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;dot1x critical eapol&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;spanning-tree extend system-id&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan internal allocation policy ascending&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/1&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate server&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; ip address 192.168.6.100 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip sla enable reaction-alerts&lt;/P&gt;&lt;P&gt;snmp-server community snmp RO&lt;/P&gt;&lt;P&gt;snmp-server enable traps mac-notification change move threshold&lt;/P&gt;&lt;P&gt;snmp-server host 192.168.6.10 version 2c snmp&amp;nbsp; mac-notification&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;&lt;P&gt;radius-server host 192.168.6.10 auth-port 1645 acct-port 1646 key 123456789&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ntp clock-period 36029254&lt;/P&gt;&lt;P&gt;ntp server 192.168.6.29&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168040#M128243</guid>
      <dc:creator>vrz rrr</dc:creator>
      <dc:date>2019-03-11T03:15:47Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.3 posture status OK but network connection failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168041#M128246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I have an issue with pre-posture ACL and so forth.&lt;/P&gt;&lt;P&gt;What are the ACLs to set both on ISE and the switch ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing works so far (Cisco documentation troubleshoot manual)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have that ACL_PREPOSTURE on both the SW and ISE for posture remediation profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deny udp any any eq domain&lt;/P&gt;&lt;P&gt;deny ip any host 192.168.6.10&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ACL_ALLOW applied on the port: &lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;ip access-list extended ACL-ALLOW
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt; &lt;A name="wp1059727"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt; permit ip any any&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please HELP !!&lt;/P&gt;&lt;P&gt;My IOS is :&lt;/P&gt;&lt;P&gt;c3750-ipbasek9-mz.122-55.SE7.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 11:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168041#M128246</guid>
      <dc:creator>vrz rrr</dc:creator>
      <dc:date>2013-04-02T11:36:11Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.3 posture status OK but network connection failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168042#M128249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone could help ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the time being, I won't recommend this product to my clients as there is too much issues in between the Switch and ISE !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 19:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168042#M128249</guid>
      <dc:creator>vrz rrr</dc:creator>
      <dc:date>2013-04-02T19:44:52Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.3 posture status OK but network connection failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168043#M128251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please clarify the issue you are experiencing from the endpoint (is this performing dot1x)? I see the username in the logs but I am a litte confused as to the debugs and the screenshot you provided. Also please provide a screenshot of your authorization policy and DACLs that are configured on ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are quite a few bugs regarding the 12.2(55)SE7 release and I wanted to know if you are plugging in behind an ip phone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide the running configuration of the port "show run interface..." I would like to see the entire acl configuration "show run | sec ip access-list", I would also like to see the following commands during the user connection stage (one for when it first plugs in, another when its in the posture uknown state, and then again after the final access-accept) "show authentication session interface ..." along with the "show ip access-list interface xxx" along with a debug radius authentication for the entire event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 23:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168043#M128251</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-04-02T23:52:30Z</dc:date>
    </item>
    <item>
      <title>ISE 1.1.3 posture status OK but network connection failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168044#M128252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tarik, thanks for trying to help !&lt;/P&gt;&lt;P&gt;I guess that we all have configured the Sw and ISE as described in the documentation.&lt;/P&gt;&lt;P&gt;It would be kind to give us a standard Sw config that works. In my opinion, dACL is the point to be clarified urgently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No IP Phone at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;How to configure dACL on ISE ? ( pre-posture, redirect ) ????&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;What are the ports ? ( 8443, 8905n any ?)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Do we need a ACL to be set in the Sw before the dACL is applied ???&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please answer those questions first, and we will provide you some logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'am not able to have a stable behaviour any more.&lt;/P&gt;&lt;P&gt;Lastest tested IOS : &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;c3750-ipbasek9-mz.122-52.SE.bin&lt;/STRONG&gt;&lt;/SPAN&gt; (compatibility matrix on Cisco Website)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We waste of lot of time trying not to debug the software, but trying to find which parts work together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again Tarik.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 07:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-1-3-posture-status-ok-but-network-connection-failed/m-p/2168044#M128252</guid>
      <dc:creator>vrz rrr</dc:creator>
      <dc:date>2013-04-03T07:14:57Z</dc:date>
    </item>
  </channel>
</rss>

