<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jack, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915857#M39448</link>
    <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;system is hitting the deny policy as there is no 802.1x request from the PC and there is MAB authz allowed for that devices- that is reason you are getting that error,&lt;/P&gt;
&lt;P&gt;Do you configured MAB(Mac address bypass) authz policy for the windows devices? if yes please verify the policy. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem looks like with PC just verify the wiredautoconfig service is running in PC? there are no certificate related errors? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you said some of the PC's are working then it clearly indicate problem with system not ISE,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ref Link:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/blog/12256681/getting-past-intermittentunexplained-8021x-problems-windows-7&lt;/P&gt;
&lt;P&gt;Microsoft&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://support.microsoft.com/en-us/kb/2736878&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2016 09:20:20 GMT</pubDate>
    <dc:creator>Pradeep S.R.</dc:creator>
    <dc:date>2016-06-17T09:20:20Z</dc:date>
    <item>
      <title>Dot1.x error 5434</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915850#M39424</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;attached is the error for dot1x.&lt;/P&gt;
&lt;P&gt;I have configured dot1x and it is working fine with dell laptop as I tried with 2 or 3 users,, &amp;nbsp;but it doesn't work with&amp;nbsp; hp pc as it gives me the attached error.&lt;/P&gt;
&lt;P&gt;when I left the office I have Google out and found the link &lt;A href="https://supportforums.cisco.com/discussion/12451301/cisco-ise-changing-domain-user-doesnt-trigger-automatic-reauthentication&amp;nbsp;" target="_blank"&gt;https://supportforums.cisco.com/discussion/12451301/cisco-ise-changing-domain-user-doesnt-trigger-automatic-reauthentication&amp;nbsp;&lt;/A&gt;; now I want to know is it Suppress Anomalous Clients option is enabled by default ??? by unchecking that will the dot1x will work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915850#M39424</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2019-03-11T06:51:35Z</dc:date>
    </item>
    <item>
      <title>Hi Jack,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915851#M39426</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;Please let me know which version of ISE you are using and do u created the ISE Authz policies based on device profile or only 802.1x attribute?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. by looking at the screenshot I can see device is getting profiled as cisco device ?&lt;/P&gt;
&lt;P&gt;2. u need to compare the policy for working device and non- working HP PC- as in screenshot shows device sending the authentication- MAB(Mac address bypass) method.&lt;/P&gt;
&lt;P&gt;3. yes - by default radius suppress setting is enabled in ISE- you can verify in settings-&amp;gt;protocol-&amp;gt;Radius protocols-settings -it only applies to devices if &lt;STRONG&gt;Reject Request After Detection&lt;/STRONG&gt; is enabled and policy will be in effect till the r&lt;STRONG&gt;equest rejection interval time specified-&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;share the details- will suggest the fix.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;
&lt;P&gt;*** Rate if it helps&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 13:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915851#M39426</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-13T13:51:40Z</dc:date>
    </item>
    <item>
      <title>Dear Pradeepa,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915852#M39431</link>
      <description>&lt;P&gt;Dear Pradeepa,&lt;/P&gt;
&lt;P&gt;I have configured MAB for HP printers which are detected by ISE as HP device so I gave them full permit now when I started to move the users HP PC's they are also seen as a HP device and they are also falling in MAB so to avoid such situation I disabled the Printer MAB policy for time being and try to restart the HP PC then as per the screenshot nothing was seen in&amp;nbsp; the authorization logs as per the attached this is becz of they have already been suppressed. please correct me,&lt;/P&gt;
&lt;P&gt;how I can avoid HP pc to fall as HP device rather then they are capable of Dot1x.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 14:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915852#M39431</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-13T14:11:42Z</dc:date>
    </item>
    <item>
      <title>Hi jack,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915853#M39436</link>
      <description>&lt;P&gt;Hi jack,&lt;/P&gt;
&lt;P&gt;To get the profiling accuracy - we should enable( DNS,DHCP,SNMP, SNMPTRAP, RADIUS) -profiler option in profiler configuration.-&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;there are 4 options to achieve this.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1. check logs and see on which parameter device is getting profiled as HP device? (like radius,dns or dhcp).&lt;/P&gt;
&lt;P&gt;2. &amp;nbsp;u have to tweak the profiling policy for the HP -device and other workstation devices - please refer the Cisco profiling accuracy -http://www.cisco.com/c/dam/en/us/td/docs/security/ise/how_to/HowTo-30-ISE_Profiling_Design_Guide.pdf&lt;/P&gt;
&lt;P&gt;3. still profiling accuracy fails - &amp;nbsp;create customised profiling policy for HP-workstation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;4. create autz policy based on 802.1x attribute and with the domain group-(users AD group) without any device profile.to overcome profiling issue,.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;
&lt;P&gt;*** Rate if it helps&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 14:51:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915853#M39436</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-13T14:51:11Z</dc:date>
    </item>
    <item>
      <title>Dear Pradeepa,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915854#M39439</link>
      <description>&lt;P&gt;Dear Pradeepa,&lt;/P&gt;
&lt;P&gt;I have done the below still it falls as a HP device, In authorization rule I have a condition as domain computer and domain user but still&lt;/P&gt;
&lt;P&gt;4. create autz policy based on 802.1x attribute and with the domain group-(users AD group) without any device profile.to overcome profiling issue,.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 16:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915854#M39439</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-13T16:32:27Z</dc:date>
    </item>
    <item>
      <title>Hi Jack, </title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915855#M39442</link>
      <description>&lt;P&gt;Hi Jack,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I meant to say if none of the 3 options work then only we should go with authz policy without any profiling attribute in that- it means policy should not depend on any profiling parameter&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 16:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915855#M39442</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-13T16:50:27Z</dc:date>
    </item>
    <item>
      <title>Dears,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915856#M39446</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;you can verify in settings-&amp;gt;protocol-&amp;gt;Radius protocols-settings -it only applies to devices if &lt;STRONG&gt;Reject Request After Detection&lt;/STRONG&gt; is enabled and policy will be in effect till the r&lt;STRONG&gt;equest rejection interval time specified-&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I have disabled the above policy, still some of the PC are failing by error &lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;5434&lt;/TD&gt;
&lt;TD&gt;Endpoint conducted several failed authentications of the same scenario&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;I can see&amp;nbsp;a mac address of the machine&amp;nbsp;in the radius live logs&amp;nbsp;instead of their hostname&amp;nbsp; for example host/HR-PC1 as an identity and it gives me the below error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;5434 endpoint conducted several failed authentications of the same scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;15039 rejected per authorization profile&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Some of the PC were working fine with dot1x&amp;nbsp; but suddenly they started with this issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 08:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915856#M39446</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-17T08:10:02Z</dc:date>
    </item>
    <item>
      <title>Hi Jack,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915857#M39448</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;system is hitting the deny policy as there is no 802.1x request from the PC and there is MAB authz allowed for that devices- that is reason you are getting that error,&lt;/P&gt;
&lt;P&gt;Do you configured MAB(Mac address bypass) authz policy for the windows devices? if yes please verify the policy. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem looks like with PC just verify the wiredautoconfig service is running in PC? there are no certificate related errors? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;as you said some of the PC's are working then it clearly indicate problem with system not ISE,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ref Link:&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/blog/12256681/getting-past-intermittentunexplained-8021x-problems-windows-7&lt;/P&gt;
&lt;P&gt;Microsoft&amp;nbsp;&lt;/P&gt;
&lt;P&gt;https://support.microsoft.com/en-us/kb/2736878&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 09:20:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915857#M39448</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-17T09:20:20Z</dc:date>
    </item>
    <item>
      <title>Dear</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915858#M39452</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;
&lt;P&gt;thanks for the reply, I appreciate,&lt;/P&gt;
&lt;P&gt;Do you configured MAB(Mac address bypass) authz policy for the windows devices? if yes please verify the policy&lt;/P&gt;
&lt;P&gt;yes I have configured mab for hp printers and not for HP pc's becz they are dot1x capable, my MAB policy was on top and dot1x was below that so all Hp pc were hitting MAB then I twick the MAB policy below dot1x and all PC started hitting dot1x policy, when I start to move the pc switch port configuration in dot1x they were successfully authenticating, for pc A I configured the switch port in dot1 and it authenticate successfully , the next day when I came the same pc gave me an error&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;5434 endpoint conducted several failed authentications of the same scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;15039 rejected per authorization profile&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;why that so it is happening , before migrating the switch configuration I want to confirm the error is related to PC or misconfiguration on ISE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;Problem looks like with PC just verify the wiredautoconfig service is running in PC? there are no certificate related errors? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;yes it is running and the PC NIC configuration are as the below link. please confirm that I am on the correct path.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;https://supportforums.cisco.com/discussion/12451301/cisco-ise-changing-domain-user-doesnt-trigger-automatic-reauthentication&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d;"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 10:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915858#M39452</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-17T10:29:55Z</dc:date>
    </item>
    <item>
      <title>Hi Jack,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915859#M39455</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;yes it is running and the PC NIC configuration are as the below link. please confirm that I am on the correct path&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Yes you are on right path.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 10:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915859#M39455</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-17T10:37:53Z</dc:date>
    </item>
    <item>
      <title>Dear Pradeepa,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915860#M39457</link>
      <description>&lt;P&gt;Dear Pradeepa,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;To get the profiling accuracy - we should enable( DNS,DHCP,SNMP, SNMPTRAP, RADIUS) -profiler option in profiler configuration.-&lt;/P&gt;
&lt;P&gt;I have enabled all the probes but enabling probe will not make things for me there must be some extra configuration has to be done, if you can brief&amp;nbsp;me how I can segregate HP printers and&amp;nbsp;HP&amp;nbsp;PC that are&amp;nbsp;profiled as a&amp;nbsp;HP-Device&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;there are 4 options to achieve this.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1. check logs and see on which parameter device is getting profiled as HP device? (like radius,dns or dhcp).&lt;/P&gt;
&lt;P&gt;I have to see this in the endpoint ??&lt;/P&gt;
&lt;P&gt;2. &amp;nbsp;u have to tweak the profiling policy for the HP -device and other workstation devices - please refer the Cisco profiling accuracy -http://www.cisco.com/c/dam/en/us/td/docs/security/ise/how_to/HowTo-30-ISE_Profiling_Design_Guide.pdf&lt;/P&gt;
&lt;P&gt;can you brief on my issue I will read it but for time being what can be done.&lt;/P&gt;
&lt;P&gt;3. still profiling accuracy fails - &amp;nbsp;create customized profiling policy for HP-workstation&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how I am following by the below link in which the device which is not profiled can be statically group to a new group.&lt;/P&gt;
&lt;P&gt;https://www.youtube.com/watch?v=11464Fjm2tA&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 10:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915860#M39457</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-17T10:57:54Z</dc:date>
    </item>
    <item>
      <title>Hi Jack,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915861#M39463</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;q 1? &amp;nbsp;Yes you have to check endpoint details &amp;nbsp;from &lt;STRONG&gt;Administration-&amp;gt;Identity Management-&amp;gt;Identities-&amp;gt;Endpoints&lt;/STRONG&gt;&amp;nbsp;(screenshot attached)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;q 2? if you go the profiling architecture and CF (Certainty Factor) value - section guide it helps to u.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Q 3? yes it helps- you can statically map failing device to particular group -it is feasible solution small scale deployment and &amp;nbsp;for large scale &amp;nbsp;dynamic profiling is better option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 11:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915861#M39463</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-17T11:18:07Z</dc:date>
    </item>
    <item>
      <title>Dear Pradeepa,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915862#M39466</link>
      <description>&lt;P&gt;Dear Pradeepa,&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;want to keep MAB policy on top and dot1x policy below in authorization policy,&lt;/P&gt;
&lt;P&gt;If suppose HP Printers which are&amp;nbsp;profiled as a&amp;nbsp;HP -Device&amp;nbsp; in ISE , can I statically map these device to a particular static group instead of automatic mapping to HP-Device&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 12:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915862#M39466</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-06-17T12:03:05Z</dc:date>
    </item>
    <item>
      <title>Hi Marc,</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915863#M39470</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;want to keep MAB policy on top and dot1x policy below in authorization policy,- &lt;STRONG&gt;Yes&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If suppose HP Printers which are&amp;nbsp;profiled as a&amp;nbsp;HP -Device&amp;nbsp; in ISE , can I statically map these device to a particular static group instead of automatic mapping to HP-Device- &lt;STRONG&gt;Yes you can do that.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pradeep&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 09:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1-x-error-5434/m-p/2915863#M39470</guid>
      <dc:creator>Pradeep S.R.</dc:creator>
      <dc:date>2016-06-21T09:33:51Z</dc:date>
    </item>
  </channel>
</rss>

