<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB Failing Even Though Authc is Successful in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-failing-even-though-authc-is-successful/m-p/3563975#M440372</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I'd first suggest that you try taking the comments ( ! ) out of your dACL contents.&amp;nbsp; Older platforms in particular can have problems with dACL lines that are not true access control entries.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The logs may stop short but my assumption is that you are getting AuthC success and AuthZ failure on the switch - meaning the switch is not able to apply the authorization instructions sent by ACS.&amp;nbsp; AuthZ failure should be shown in normal logging levels, but you could also try debugging EPM to determine if the dACL is being applied.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These commands may also help with troubleshooting:&lt;/P&gt;&lt;P&gt;show ip access-list #ACSACL#-IP-LM-PERMIT-ALL-57217a63&lt;/P&gt;&lt;P&gt;show ip access-list g1/0/2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;-Fruits&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Sep 2017 12:35:47 GMT</pubDate>
    <dc:creator>bfruits</dc:creator>
    <dc:date>2017-09-26T12:35:47Z</dc:date>
    <item>
      <title>MAB Failing Even Though Authc is Successful</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-failing-even-though-authc-is-successful/m-p/3563974#M440371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;ACS/IBNS Teams,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is saying they cannot get mab working on a 3750 but the same host works on a 3560 if moved. Basically, it shows Authc successful but the port state still shows as unauthorized. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the logs. Any ideas? My next step is to also post to the ISE support community. However, this is ACS as the server today. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Sep 2017 23:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-failing-even-though-authc-is-successful/m-p/3563974#M440371</guid>
      <dc:creator>jupoole</dc:creator>
      <dc:date>2017-09-25T23:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: MAB Failing Even Though Authc is Successful</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-failing-even-though-authc-is-successful/m-p/3563975#M440372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I'd first suggest that you try taking the comments ( ! ) out of your dACL contents.&amp;nbsp; Older platforms in particular can have problems with dACL lines that are not true access control entries.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The logs may stop short but my assumption is that you are getting AuthC success and AuthZ failure on the switch - meaning the switch is not able to apply the authorization instructions sent by ACS.&amp;nbsp; AuthZ failure should be shown in normal logging levels, but you could also try debugging EPM to determine if the dACL is being applied.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These commands may also help with troubleshooting:&lt;/P&gt;&lt;P&gt;show ip access-list #ACSACL#-IP-LM-PERMIT-ALL-57217a63&lt;/P&gt;&lt;P&gt;show ip access-list g1/0/2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;-Fruits&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2017 12:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-failing-even-though-authc-is-successful/m-p/3563975#M440372</guid>
      <dc:creator>bfruits</dc:creator>
      <dc:date>2017-09-26T12:35:47Z</dc:date>
    </item>
  </channel>
</rss>

