<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi again! in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957144#M37459</link>
    <description>&lt;P&gt;Hi again!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Anyone can look into this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2016 12:05:39 GMT</pubDate>
    <dc:creator>Capricorn</dc:creator>
    <dc:date>2016-12-14T12:05:39Z</dc:date>
    <item>
      <title>ISE 1.3 issue with Catalyst 4500E (12.54)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957141#M37456</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I am new to ISE world.&lt;/P&gt;
&lt;P&gt;I have different Authorization policy based on computer and user. Once the computer start it will assign to vlan based on its security group membership. If a user login to same computer then second Authorization clicks in IP is assigned from Vlan based on user security group.&lt;/P&gt;
&lt;P&gt;It works on 2900 series switch but the same thing doesn't work on&amp;nbsp;Catalyst 4500E (12.54). I have matched the config for Dot1x on both switches and the look fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue is that on Catalyst 4500 the second authorization doesnt work. Only the first policy that is for computer authentication works.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any suggestion on this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Capricorn&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957141#M37456</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2019-03-11T07:15:17Z</dc:date>
    </item>
    <item>
      <title>Hello Capricorn-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957142#M37457</link>
      <description>&lt;P&gt;Hello Capricorn-&lt;/P&gt;
&lt;P&gt;My guess is that you are hitting a bug with the version of code that you are running on the 4500. Can you provide the following info:&lt;/P&gt;
&lt;P&gt;- Exact chassis model (Obtain from show ver)&lt;/P&gt;
&lt;P&gt;- Exact version code (Obtain from show ver)&lt;/P&gt;
&lt;P&gt;- Output from from the following command: show authentication session interface&amp;nbsp;&lt;EM&gt;interface_name_number&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;- Configuration of the affected port&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 17:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957142#M37457</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-11-29T17:56:54Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno for looking into</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957143#M37458</link>
      <description>&lt;P&gt;Thanks Neno for looking into this. Please see below.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;WS-C4506-E&lt;/P&gt;
&lt;P&gt;cat4500e-ipbasek9-mz.122-54.SG1.bin&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;description ISE&lt;BR /&gt; switchport access vlan 550&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 300&lt;BR /&gt; ip access-group ACL-DEFAULT in&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication violation restrict&lt;BR /&gt; mab&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 5&lt;BR /&gt; dot1x max-reauth-req 1&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt; spanning-tree guard root&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;--------&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show authentication sessions interface gigabitEthernet 3/31&lt;BR /&gt; Interface: GigabitEthernet3/31&lt;BR /&gt; MAC Address: a0b3.cc23.xxxx&lt;BR /&gt; IP Address: 10.2.7.227&lt;BR /&gt; User-Name: host/testcomputer.mydomain.com&lt;BR /&gt; Status: Authz Success&lt;BR /&gt; Domain: DATA&lt;BR /&gt; Oper host mode: multi-domain&lt;BR /&gt; Oper control dir: both&lt;BR /&gt; Authorized By: Authentication Server&lt;BR /&gt; Vlan Policy: 109&lt;BR /&gt; Session timeout: N/A&lt;BR /&gt; Idle timeout: N/A&lt;BR /&gt; Common Session ID: 0AF4DC0C0000003D8153AA91&lt;BR /&gt; Acct Session ID: 0x00005255&lt;BR /&gt; Handle: 0xA300003E&lt;/P&gt;
&lt;P&gt;Runnable methods list:&lt;BR /&gt; Method State&lt;BR /&gt; dot1x Authc Success&lt;BR /&gt; mab Not run&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 09:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957143#M37458</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2016-12-06T09:28:05Z</dc:date>
    </item>
    <item>
      <title>Hi again!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957144#M37459</link>
      <description>&lt;P&gt;Hi again!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Anyone can look into this?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 12:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957144#M37459</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2016-12-14T12:05:39Z</dc:date>
    </item>
    <item>
      <title>Sorry about that. I thought I</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957145#M37460</link>
      <description>&lt;P&gt;Sorry about that. I thought I replied to the thread but I guess I missed it &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, based on what you have provided I see two things that look strange:&lt;/P&gt;
&lt;P&gt;1. The username provided in the session is a name of a computer not actual user. Thus, it appears that the user auth is not even seen by the switch/ise&lt;/P&gt;
&lt;P&gt;2. In the port config you have a pre-auth ACL (&lt;SPAN&gt;ACL-DEFAULT) but I don't see a dACL in the authorization policy. So my question here is: Are you returning a dACL with your authorization policy? If not, I would suggest doing that as you need a dACL to replace the pre-auth ACL. Otherwise, the pre-auth ACL remains on the port even after successful authentication/authorization. You can quickly test this by pushing a "permit ip any any" with both authorization profiles.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 23:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957145#M37460</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-15T23:25:09Z</dc:date>
    </item>
    <item>
      <title>Hi!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957146#M37461</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for looking into it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Everything works fine if I have a computer connected to Catalyst 2960G (&amp;nbsp;Version 12.2(44)SE6) and&amp;nbsp;it doesnt work if I connected the same computer to&amp;nbsp;&lt;SPAN&gt;WS-C4506-E.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To me it looks ok from ISE as it works for 2960G. What you say?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2016 10:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957146#M37461</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2016-12-16T10:46:30Z</dc:date>
    </item>
    <item>
      <title>So the reason I suggest you</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957147#M37462</link>
      <description>&lt;P&gt;So the reason I suggest you try the dACL is because the behavior of the default Pre-Auth ACL changed between versions and switch family. I had a link that described this but cannot find it now.&lt;/P&gt;
&lt;P&gt;I would definitely configure and push a dACL and see if that fixes the problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2016 21:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957147#M37462</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-17T21:39:41Z</dc:date>
    </item>
    <item>
      <title>Hi!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957148#M37463</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We are already pushing DACL to it.&lt;/P&gt;
&lt;P&gt;I can see the DACL is coming down to switch.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 13:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957148#M37463</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2016-12-22T13:13:33Z</dc:date>
    </item>
    <item>
      <title>If you are pushing a dACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957149#M37464</link>
      <description>&lt;P&gt;If you are pushing a dACL then I would expect to see "&amp;nbsp;ACS ACL:&lt;EM&gt;your_dACL_name&lt;/EM&gt;" in the output from "show authentication session..." I did not see that in the output that you provided. To test this further, you can issue "show ip access-list interface&amp;nbsp;&lt;EM&gt;interface_name"&amp;nbsp;&lt;/EM&gt;after the session has completed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2016 19:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957149#M37464</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-23T19:49:30Z</dc:date>
    </item>
    <item>
      <title>I get this. show ip access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957150#M37465</link>
      <description>&lt;P&gt;I get this. show ip access-lists interface gigabitEthernet 3/31&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;permit ip any any (30 estimate matches)&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2017 13:34:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-3-issue-with-catalyst-4500e-12-54/m-p/2957150#M37465</guid>
      <dc:creator>Capricorn</dc:creator>
      <dc:date>2017-01-12T13:34:06Z</dc:date>
    </item>
  </channel>
</rss>

