<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB authentification feils after reboot in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574336#M321140</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;It has to do with Spanning tree protocol on the switch where right after
switch reboot, STP is still in process and the switch sends out the
Radius-Request but it doesn't reach the Radius Server until STP is run
and the correct interfaces start forwarding.&lt;BR /&gt;&lt;BR /&gt;You need to adjust the Radius Timers on the switch. &lt;BR /&gt;Please enter the following commands on the switch:

radius-server retransmit 6&lt;BR /&gt;radius-server timeout 10&lt;BR /&gt;&lt;BR /&gt;This means that the switch will retransmit the radius request every 10
seconds for 6 times before marking the Server as Dead and failing the
MAB authentication. These 60 seconds are enough for STP to converge.
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Oct 2010 21:35:23 GMT</pubDate>
    <dc:creator>aneelaka</dc:creator>
    <dc:date>2010-10-01T21:35:23Z</dc:date>
    <item>
      <title>MAB authentification feils after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574335#M321139</link>
      <description>&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; "&gt;&lt;SPAN style="mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;Somebody help!!! &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-char-type: symbol; mso-ansi-language: EN-US; mso-ascii-font-family: 'Times New Roman'; font-family: Wingdings; mso-hansi-font-family: 'Times New Roman'; "&gt;J&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language: EN-US;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;Everything working just fine but after switch restarts authentication fails.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;(cat4500e-ENTSERVICESK9-M), Version 12.2(53)SG2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;ACS 4.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt; in ACS&amp;nbsp; can see&amp;nbsp;&amp;nbsp; Authen session timed out: Challenge not provided by client&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;Switch says : Sep 30 19:06:30 MET-DST: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0001.3e01.858a) on Interface Gi9/26&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;interface GigabitEthernet1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;switchport mode access&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;switchport port-security maximum 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication event fail action authorize vlan 500&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication event server dead action authorize vlan 500&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication event no-response action authorize vlan 500&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication order mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication priority mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;authentication port-control auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;mab eap&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;dot1x timeout tx-period 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;dot1x max-req 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;storm-control broadcast level 3.00&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;spanning-tree bpduguard enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;spanning-tree guard loop&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; mso-ansi-language: EN-US; font-family: Times New Roman; "&gt;end&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574335#M321139</guid>
      <dc:creator>Andrius Ajauskas</dc:creator>
      <dc:date>2019-03-11T00:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentification feils after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574336#M321140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE&gt;It has to do with Spanning tree protocol on the switch where right after
switch reboot, STP is still in process and the switch sends out the
Radius-Request but it doesn't reach the Radius Server until STP is run
and the correct interfaces start forwarding.&lt;BR /&gt;&lt;BR /&gt;You need to adjust the Radius Timers on the switch. &lt;BR /&gt;Please enter the following commands on the switch:

radius-server retransmit 6&lt;BR /&gt;radius-server timeout 10&lt;BR /&gt;&lt;BR /&gt;This means that the switch will retransmit the radius request every 10
seconds for 6 times before marking the Server as Dead and failing the
MAB authentication. These 60 seconds are enough for STP to converge.
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 21:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574336#M321140</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-10-01T21:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentification feils after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574337#M321141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have TAC case in this issue, and they sad the same. i tested this without help (it's helped a lit, but not all interfases got right Vlan.)&lt;/P&gt;&lt;P&gt;and we are using rapid spanning tree so it should be enought 60s but.....&lt;SPAN __jive_emoticon_name="shocked" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/shocked.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Oct 2010 10:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574337#M321141</guid>
      <dc:creator>Andrius Ajauskas</dc:creator>
      <dc:date>2010-10-02T10:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentification feils after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574338#M321142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, this problem with MAB is due to the fact that the Radius Server is unreachable for a bit of time right after the switch reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the switch finishes the reboot, there is STP in process so the Radius Server will be unreachable until STPis finished.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look at CSCtj46641 which has been closed as non-software-defect on switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since MAB is immediate after switchport going up and at the same time radius server is still not available, there is a need to workaround the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some options to workaround:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- radius timers increase to accomodate needed time for stp to finish&lt;/P&gt;&lt;P&gt;2- dot1x reauthentication timer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been the outcome of the TAC case between me and Andrius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps others facing this issue in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Serge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 09:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentification-feils-after-reboot/m-p/1574338#M321142</guid>
      <dc:creator>Serge Yasmine</dc:creator>
      <dc:date>2010-10-19T09:47:30Z</dc:date>
    </item>
  </channel>
</rss>

