<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Refer. the Auth fail config.  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096928#M215339</link>
    <description>&lt;P&gt;Refer. the Auth fail config. ,, while Radius is down ,&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/9994111/8021x-critical-authentication-feature-12225see&lt;/P&gt;</description>
    <pubDate>Wed, 28 May 2014 09:50:00 GMT</pubDate>
    <dc:creator>Saurav Lodh</dc:creator>
    <dc:date>2014-05-28T09:50:00Z</dc:date>
    <item>
      <title>Cisco ISE - Reauthentication of client if server becomes alive again</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096926#M215308</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Dears,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this case where Cisco ISE server is used to authenticate &amp;amp; authorize clients on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the switch port to authorize the client in case the ISE server is dead (or not reachable).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that I want to &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;reauthenticate&lt;/STRONG&gt;&lt;/SPAN&gt; the client once the ISE server becomes alive again but I am not able to.. ("Additional Information is needed to connect to this network" bullet is not appearing and the client PC remains authenticated and assigned to the VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the switch port configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface FastEthernet0/5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport access vlan 240&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport mode access&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport voice vlan 156&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; authentication event server dead action authorize vlan 240&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;authentication event server alive action reinitialize &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; authentication host-mode multi-domain&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; authentication order dot1x mab&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; authentication priority mab&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; authentication port-control auto&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; mab&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; dot1x pae authenticator&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; spanning-tree portfast&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone can help? &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096926#M215308</guid>
      <dc:creator>Wissam Bteich</dc:creator>
      <dc:date>2019-03-11T02:45:50Z</dc:date>
    </item>
    <item>
      <title>Did you get a fix for this? </title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096927#M215320</link>
      <description>&lt;P&gt;Did you get a fix for this?&amp;nbsp; I am running into the same issue running 12.2(55)SE9.&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 05:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096927#M215320</guid>
      <dc:creator>mlovellette</dc:creator>
      <dc:date>2014-05-28T05:00:30Z</dc:date>
    </item>
    <item>
      <title>Refer. the Auth fail config.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096928#M215339</link>
      <description>&lt;P&gt;Refer. the Auth fail config. ,, while Radius is down ,&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/9994111/8021x-critical-authentication-feature-12225see&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2014 09:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096928#M215339</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-05-28T09:50:00Z</dc:date>
    </item>
    <item>
      <title>Please check whether the</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096929#M215379</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;Please check whether the switch is dropping the connection or the server.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1044576table1044574" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;Symptoms or Issue &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;802.1X and MAB authentication and authorization are successful, but the switch is dropping active sessions and the &lt;B class="cCN_CmdName"&gt;epm session summary&lt;/B&gt; command does not display any active sessions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1044576table1044574" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;Conditions &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;This applies to user sessions that have logged in successfully and are then being terminated by the switch. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1044576table1044574" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;Possible Causes &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;The preauthentication ACL (and the subsequent DACL enforcement from Cisco ISE) on the NAD may not be configured correctly for that session. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&amp;nbsp;
&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;The preauthentication ACL is configured and the DACL is downloaded from Cisco ISE, but the switch brings the session down. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&amp;nbsp;
&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Cisco ISE may be enforcing a preposture VLAN assignment rather than the (correct) postposture VLAN, which can also bring down the session. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1044576table1044574" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;Resolution &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Ensure the Cisco IOS release on the switch is equal to or more recent than Cisco IOS Release 12.2.(53)SE. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&amp;nbsp;
&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Check to see whether or not the DACL name in Cisco ISE contains a blank space (possibly around or near a hyphen "-"). There should be no space in the DACL name. Then ensure that the DACL syntax is correct and that it contains no extra spaces. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&amp;nbsp;
&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Ensure that the following configuration exists on the switch to interpret the DACL properly (if not enabled, the switch may terminate the session): &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&amp;nbsp;
&lt;DIV class="pEx2_Example2"&gt;
&lt;PRE&gt;
&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;radius-server attribute 6 on-for-login-auth
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&amp;nbsp;
&lt;DIV class="pEx2_Example2"&gt;
&lt;PRE&gt;
&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;radius-server attribute 8 include-in-access-req
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&amp;nbsp;
&lt;DIV class="pEx2_Example2"&gt;
&lt;PRE&gt;
&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;radius-server attribute 25 access-request include
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&amp;nbsp;
&lt;DIV class="pEx2_Example2"&gt;
&lt;PRE&gt;
&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;radius-server vsa send accounting
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&amp;nbsp;
&lt;DIV class="pEx2_Example2"&gt;
&lt;PRE&gt;
&lt;SPAN style="font-size: small;"&gt;&lt;SPAN style="font-family: Times New Roman;"&gt;radius-server vsa send authentication
&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 11:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096929#M215379</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-06-02T11:01:26Z</dc:date>
    </item>
    <item>
      <title>Just noticed your config has</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096930#M215406</link>
      <description>&lt;P&gt;Just noticed your config has "&lt;EM&gt;authentication priority mab"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Try&lt;EM&gt; "authentication priority dot1x mab"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not 100% but I would suggest this could be your problem&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2014 22:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096930#M215406</guid>
      <dc:creator>Stephen McBride</dc:creator>
      <dc:date>2014-06-02T22:15:44Z</dc:date>
    </item>
    <item>
      <title>what is switch model and</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096931#M215455</link>
      <description>&lt;P&gt;what is switch model and software version&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 17:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-reauthentication-of-client-if-server-becomes-alive/m-p/2096931#M215455</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2014-06-04T17:17:07Z</dc:date>
    </item>
  </channel>
</rss>

