<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looks like a dhcp snooping in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822822#M41214</link>
    <description>Looks like a dhcp snooping/device tracking issue, the auth sess does not know the ip of your windows pc and the ACL then does not get applied. You can check that with "show ip access-list interface x/x" . Can you do a "show ip device tracking int x/x" and see if the device ip shows up as active ? Also have you configured the recommended settings in the switch using the trustsec universal switch config guide ?</description>
    <pubDate>Tue, 22 Dec 2015 22:09:08 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2015-12-22T22:09:08Z</dc:date>
    <item>
      <title>ISE 2.0 (patch 1) authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822819#M41209</link>
      <description>&lt;P&gt;I am running into a bit of an odd issue with ISE 2.0 (patch 1). &amp;nbsp;I have a Win 7 laptop that passes authC/authZ, gets an IP address, but cannot access any internal or external resources. &amp;nbsp;It's using 802.1x with EAP-TLS with machine and user certs from AD. &amp;nbsp;Along with this issue I am having another one with MAR, but TAC is looking into that issue. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just cannot figure out how the device can get an IP address, but not access anything on the network. &amp;nbsp;The laptop can do a release/renew of the IP address as well, so it's getting somewhere on the network.&lt;/P&gt;
&lt;P&gt;TIA for any ideas. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Dan&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822819#M41209</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2019-03-26T00:34:02Z</dc:date>
    </item>
    <item>
      <title>Is it wireless or wired, if</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822820#M41211</link>
      <description>Is it wireless or wired, if wired you should check on the switch, with "show auth sess int x/x" to see if the switch has actually authorized the user, and downloaded the ACL if you are using open mode</description>
      <pubDate>Tue, 22 Dec 2015 20:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822820#M41211</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-12-22T20:24:29Z</dc:date>
    </item>
    <item>
      <title>It's a wired deployment.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822821#M41213</link>
      <description>&lt;P&gt;It's a wired deployment. &amp;nbsp;Results of show auth sess:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;IT-READING-S04#sh authentication sessions int g1/0/27&lt;BR /&gt; Interface: GigabitEthernet1/0/27&lt;BR /&gt; MAC Address: f01f.af48.3290&lt;BR /&gt; IP Address: Unknown&lt;BR /&gt; User-Name:&amp;nbsp;user@client.com&lt;BR /&gt; Status: Authz Success&lt;BR /&gt; Domain: DATA&lt;BR /&gt; Oper host mode: multi-auth&lt;BR /&gt; Oper control dir: both&lt;BR /&gt; Authorized By: Authentication Server&lt;BR /&gt; Vlan Policy: N/A&lt;BR /&gt; ACS ACL: xACSACLx-IP-Wired_Permit_All-5661b508&lt;BR /&gt; Session timeout: N/A&lt;BR /&gt; Idle timeout: N/A&lt;BR /&gt; Common Session ID: AC100BCC0000120BF61FB559&lt;BR /&gt; Acct Session ID: 0x0001DD8A&lt;BR /&gt; Handle: 0x36000215&lt;/P&gt;
&lt;P&gt;Runnable methods list:&lt;BR /&gt; Method State&lt;BR /&gt; dot1x Authc Success&lt;BR /&gt; mab Not run&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Nothing being blocked and the dACL is permit ip any any.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2015 20:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822821#M41213</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2015-12-22T20:26:40Z</dc:date>
    </item>
    <item>
      <title>Looks like a dhcp snooping</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822822#M41214</link>
      <description>Looks like a dhcp snooping/device tracking issue, the auth sess does not know the ip of your windows pc and the ACL then does not get applied. You can check that with "show ip access-list interface x/x" . Can you do a "show ip device tracking int x/x" and see if the device ip shows up as active ? Also have you configured the recommended settings in the switch using the trustsec universal switch config guide ?</description>
      <pubDate>Tue, 22 Dec 2015 22:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822822#M41214</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-12-22T22:09:08Z</dc:date>
    </item>
    <item>
      <title>Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822823#M41215</link>
      <description>&lt;P&gt;Jan,&lt;/P&gt;
&lt;P&gt;It was the dhcp snopping/tracking config missing from the switch. &amp;nbsp;Thanks for the help!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-Dan&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 14:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-1-authorization-issue/m-p/2822823#M41215</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2015-12-23T14:40:02Z</dc:date>
    </item>
  </channel>
</rss>

