<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 - 5411 EAP Session Timeout in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-5411-eap-session-timeout/m-p/1909634#M188272</link>
    <description>&lt;P&gt;Friends, I got a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We run ACS 5-2-0-26-10. Some clients gets the error message "5411 EAP Session Timeout", and the clients are assigned guest LAN. If I reboot and log in again, still the same. However, if I reboot and log in with another user, it's back on the corporate network. Then I can log off and log in the user again, everything works fine. I haven't been able to find out why this happens. It's the machine authentication that fails, we have set our ACS to accept either user or machine ID. I also found out that if the user waits for about 20 minutes they're back on the corporate network. However I haven't found any timers that is set to this interval. I can't debug using Wireshark, because this is users that needs their computer right away, and I haven't been able to re-create the problem in lab neither.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our port config;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport access vlan 320&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; ip arp inspection limit rate 15 burst interval 5&lt;/P&gt;&lt;P&gt; authentication control-direction in&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 666&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 320&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 666&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout quiet-period 20&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; storm-control broadcast level 5.00&lt;/P&gt;&lt;P&gt; storm-control multicast level 30.00&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt; spanning-tree guard root&lt;/P&gt;&lt;P&gt; ip dhcp snooping limit rate 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;dot1x guest-vlan supplicant&lt;/P&gt;&lt;P&gt;dot1x critical eapol&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help I can get is highly appreciated!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:06:24 GMT</pubDate>
    <dc:creator>bvj197222</dc:creator>
    <dc:date>2019-03-11T02:06:24Z</dc:date>
    <item>
      <title>ACS 5.2 - 5411 EAP Session Timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-5411-eap-session-timeout/m-p/1909634#M188272</link>
      <description>&lt;P&gt;Friends, I got a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We run ACS 5-2-0-26-10. Some clients gets the error message "5411 EAP Session Timeout", and the clients are assigned guest LAN. If I reboot and log in again, still the same. However, if I reboot and log in with another user, it's back on the corporate network. Then I can log off and log in the user again, everything works fine. I haven't been able to find out why this happens. It's the machine authentication that fails, we have set our ACS to accept either user or machine ID. I also found out that if the user waits for about 20 minutes they're back on the corporate network. However I haven't found any timers that is set to this interval. I can't debug using Wireshark, because this is users that needs their computer right away, and I haven't been able to re-create the problem in lab neither.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our port config;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport access vlan 320&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; ip arp inspection limit rate 15 burst interval 5&lt;/P&gt;&lt;P&gt; authentication control-direction in&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 666&lt;/P&gt;&lt;P&gt; authentication event server dead action authorize vlan 320&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 666&lt;/P&gt;&lt;P&gt; authentication event server alive action reinitialize &lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout quiet-period 20&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; storm-control broadcast level 5.00&lt;/P&gt;&lt;P&gt; storm-control multicast level 30.00&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt; spanning-tree guard root&lt;/P&gt;&lt;P&gt; ip dhcp snooping limit rate 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;dot1x guest-vlan supplicant&lt;/P&gt;&lt;P&gt;dot1x critical eapol&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help I can get is highly appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-5411-eap-session-timeout/m-p/1909634#M188272</guid>
      <dc:creator>bvj197222</dc:creator>
      <dc:date>2019-03-11T02:06:24Z</dc:date>
    </item>
  </channel>
</rss>

