<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Try to change the config on in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/intermittent-802-1x-authentication-issue/m-p/3053778#M23301</link>
    <description>&lt;P&gt;Try to change the config on few ports to&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication order dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;/P&gt;
&lt;P&gt;and see if the problem still occurs frequently&lt;/P&gt;
&lt;P&gt;I found this to be working well in our environment, but each case is different of course&lt;/P&gt;
&lt;P&gt;Also, I have the dot1x block period set to 0 in Windows network profile&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2017 14:11:15 GMT</pubDate>
    <dc:creator>agrissimanis</dc:creator>
    <dc:date>2017-04-03T14:11:15Z</dc:date>
    <item>
      <title>Intermittent 802.1x Authentication Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-802-1x-authentication-issue/m-p/3053777#M23299</link>
      <description>&lt;P&gt;We have been running the below configuration for several years now.&amp;nbsp; More and more when a user logs into a computer, they will be prompted with the Cisco Guest Portal or have no network access.&amp;nbsp; Just logging off and back in again usually resolved the issue but it is frustrating for our users.&amp;nbsp; Originally we had mostly Windows 7 computers and the occurrences were very low.&amp;nbsp; It seems as computers were replaced with Windows Vista, 8.1 and now 10 that it is happening more frequently.&amp;nbsp; 99% of the time when this happens the computer is cold booted from being off overnight and the user tries to log in as soon as the Ctrl-Alt-Del screen appears.&amp;nbsp; We have been instructing users to wait 60 seconds before logging in and this has helped, although not always.&amp;nbsp; It appears that either the 802.1x service has not started on the computer or it is taking too long to respond to ISE and then getting denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any timeouts that should be changed either in ISE or on the Windows machine?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE 1.4 patch 8 authenticating to 2012R2 AD Domain Controllers&lt;/P&gt;
&lt;P&gt;4500 Chassis running IOS cat4500e-universalk9.SPA.03.04.05.SG.151-2.SG5.bin&lt;/P&gt;
&lt;P&gt;There are ACL’s on the switch VLAN and ISE pushes down a dACL at login.&lt;/P&gt;
&lt;P&gt;Computers are authenticated through ISE via AD and then re-authenticated when the user logs in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Port Configuration:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication control-direction in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication event fail action next-method&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication host-mode multi-auth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication order mab dot1x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication priority dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication port-control auto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication violation restrict&lt;/P&gt;
&lt;P&gt;&amp;nbsp;mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;snmp trap mac-notification change added&lt;/P&gt;
&lt;P&gt;&amp;nbsp;snmp trap mac-notification change removed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x pae authenticator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;storm-control broadcast level 0.50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows GPO enabled for “Always wait for the network at computer startup and logon”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;802.1X profile on Windows computer:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Block period: 1 minute&lt;/P&gt;
&lt;P&gt;Computer Authentication: User re-authentication&lt;/P&gt;
&lt;P&gt;EAPOL Start Message: Transmit per IEEE 802.1X&lt;/P&gt;
&lt;P&gt;Maximum Authentication Failures: 100&lt;/P&gt;
&lt;P&gt;Maximum EAPOL-Start Messages Sent: 3&lt;/P&gt;
&lt;P&gt;Held Period: 20 seconds&lt;/P&gt;
&lt;P&gt;Start Period: 5 seconds&lt;/P&gt;
&lt;P&gt;Authentication Period: 30 seconds&lt;/P&gt;
&lt;P&gt;Single Sign On type: PreLogon&lt;/P&gt;
&lt;P&gt;Maximum acceptable delay for network connectivity: 20 seconds&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-802-1x-authentication-issue/m-p/3053777#M23299</guid>
      <dc:creator>ermer</dc:creator>
      <dc:date>2019-03-11T07:35:33Z</dc:date>
    </item>
    <item>
      <title>Try to change the config on</title>
      <link>https://community.cisco.com/t5/network-access-control/intermittent-802-1x-authentication-issue/m-p/3053778#M23301</link>
      <description>&lt;P&gt;Try to change the config on few ports to&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication order dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;/P&gt;
&lt;P&gt;and see if the problem still occurs frequently&lt;/P&gt;
&lt;P&gt;I found this to be working well in our environment, but each case is different of course&lt;/P&gt;
&lt;P&gt;Also, I have the dot1x block period set to 0 in Windows network profile&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 14:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/intermittent-802-1x-authentication-issue/m-p/3053778#M23301</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-04-03T14:11:15Z</dc:date>
    </item>
  </channel>
</rss>

