<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Failed Authentication - Confusing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953190#M225559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Output attached with MAC table for that port (no paste option?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5 sessions on the interface, only 4 MACs show on the address table.&amp;nbsp; Does the failed MAB session not get shown on the table?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do use dynamic vlan assignment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Aug 2012 15:08:16 GMT</pubDate>
    <dc:creator>robert.riggle</dc:creator>
    <dc:date>2012-08-09T15:08:16Z</dc:date>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953186#M225527</link>
      <description>&lt;P&gt;I am having some confustion currently while looking into devices that fail authentication through the ACS.&amp;nbsp; When looking at the reporting tool for the ACS I see a device (Dell laptop) show up on the same switch port with around 900 failed authentication attempts per day.&amp;nbsp; I follow that up with a check on the MAC address table for that switch.&amp;nbsp; I see devices connected (through a hub), but not the one that is failing.&amp;nbsp; On the switch port there is the hub, 2 Dell laptops (but not the one getting logged in the ACS) and a VTC unit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add to the confusion, only the VTC unit shows a IP on the ARP table of the firewall.&amp;nbsp; Not sure where to go from here.&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953186#M225527</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2019-03-11T02:24:13Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953187#M225533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the port configuration? If you are running newer code you may be running authentication host mode single. Try running the command "authentication host mode multi-auth"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some reference material when it comes to the different host modes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/dot1x.html#wp1240475"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/50sg/configuration/guide/dot1x.html#wp1240475&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 14:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953187#M225533</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-09T14:37:17Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953188#M225537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Port configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; interface GigabitEthernet1/0/12&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; switchport access vlan 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; switchport mode access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication control-direction in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication port-control auto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will look at the refrence material also, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 14:41:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953188#M225537</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2012-08-09T14:41:27Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953189#M225545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the failure reason? also are you using dynamic vlan assignment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you post the "show authentication sessions interface gig 1/0/12"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 14:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953189#M225545</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-09T14:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953190#M225559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Output attached with MAC table for that port (no paste option?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5 sessions on the interface, only 4 MACs show on the address table.&amp;nbsp; Does the failed MAB session not get shown on the table?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do use dynamic vlan assignment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 15:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953190#M225559</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2012-08-09T15:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953191#M225570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you on vlan 2 or vlan 200? Are you using dynamic vlan assignment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 15:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953191#M225570</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-09T15:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953192#M225581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The ports are set up in vlan 2, on passing authenticaiton they get moved over to vlan 200.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 15:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953192#M225581</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2012-08-09T15:39:29Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953193#M225604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of code and model of switch are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2012 21:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953193#M225604</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-09T21:03:31Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953194#M225644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It's a 2960S switch running 12.2(55)SE5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 11:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953194#M225644</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2012-08-10T11:04:34Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953195#M225677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I missed your question before, the answer is yes when authentication fails the client is not entered on the mac address table since that will allow traffic to be forwarded. Dot1x (mab) is a l2 authentication framework which doesnt allow the mac address to be learned till we see the access-accept from the radius server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if the client authentication is expected to fail then everything is ok as far as your deployment goes and the behavior of the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Aug 2012 06:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953195#M225677</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-11T06:05:23Z</dc:date>
    </item>
    <item>
      <title>ACS Failed Authentication - Confusing</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953196#M225783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thats what I needed to know, thanks.&amp;nbsp; Its disapointing though...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2012 14:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failed-authentication-confusing/m-p/1953196#M225783</guid>
      <dc:creator>robert.riggle</dc:creator>
      <dc:date>2012-08-13T14:53:56Z</dc:date>
    </item>
  </channel>
</rss>

