<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication method ISE 2.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3921366#M457335</link>
    <description>&lt;P&gt;Thank you both Mike and Colby. Nice suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Krishnan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 20:29:49 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2019-09-09T20:29:49Z</dc:date>
    <item>
      <title>Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919755#M457289</link>
      <description>&lt;P&gt;Can someone please explain why the authentication details report shows the authentication method is mab, but the switch shows as dot1x ? The phone's Mac is part of the mab list but the PC is part of AD.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dot1x showing as Mab.JPG" style="width: 677px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/44422iC0EA288E6C02024E/image-size/large?v=v2&amp;amp;px=999" role="button" title="dot1x showing as Mab.JPG" alt="dot1x showing as Mab.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 16:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919755#M457289</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-09-05T16:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919786#M457291</link>
      <description>Can you share your interface configs? Can you also share the output of:&lt;BR /&gt;#show auth sess int g4/0/34 detail&lt;BR /&gt;My assumption is that you have configured something along these lines:&lt;BR /&gt;#authentication host-mode multi-auth&lt;BR /&gt;This lets you authenticate a client for voice vlan and several authenticated clients on data vlan.&lt;BR /&gt;OR&lt;BR /&gt;#authentication host-mode multi-domain&lt;BR /&gt;This lets you authenticate a host and voice device on an 8021x authenticated port.&lt;BR /&gt;Have you attempted to clear auth, then check the ISE live logs again to see if that has changed? Very strange.&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Sep 2019 18:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919786#M457291</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-09-05T18:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919842#M457332</link>
      <description>Thanks for the quick reply, Mike.&lt;BR /&gt;&lt;BR /&gt;Here is the output of show auth&lt;BR /&gt;#show auth sess int g4/0/34 detail&lt;BR /&gt;Interface: GigabitEthernet4/0/34&lt;BR /&gt;IIF-ID: 0x469B67B0&lt;BR /&gt;MAC Address: a44c.c86e.5226&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: domain\user&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: 0A166419000007A301B881B3&lt;BR /&gt;Acct Session ID: 0x000007d6&lt;BR /&gt;Handle: 0x72000799&lt;BR /&gt;Current Policy: POLICY_Gi4/0/34&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Server Policies:&lt;BR /&gt;Security Policy: None&lt;BR /&gt;Security Status: Link Unsecured&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Stopped&lt;BR /&gt;dot1x Authc Success&lt;BR /&gt;&lt;BR /&gt;----------------------------------------&lt;BR /&gt;&lt;BR /&gt;Interface: GigabitEthernet4/0/34&lt;BR /&gt;IIF-ID: 0x4B18BE9A&lt;BR /&gt;MAC Address: c4b9.cdb5.4b1c&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: x.x.x.x&lt;BR /&gt;User-Name: C4-B9-CD-B5-4B-1C&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: VOICE&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: 000000000000008943C9F979&lt;BR /&gt;Acct Session ID: 0x00000022&lt;BR /&gt;Handle: 0xc700007f&lt;BR /&gt;Current Policy: POLICY_Gi4/0/34&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Server Policies:&lt;BR /&gt;ACS ACL: xACSACLx-IP-PERMIT_ALL_TRAFFIC-57f6b0d3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success</description>
      <pubDate>Thu, 05 Sep 2019 19:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3919842#M457332</guid>
      <dc:creator>BigK</dc:creator>
      <dc:date>2019-09-05T19:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3920187#M457333</link>
      <description>For the data host what supplicant are you using? What type of EAP protocol are you using for 8021x? What was your result of running clear auth sess int g4/0/34? Do the ISE logs still report same weirdness?</description>
      <pubDate>Fri, 06 Sep 2019 13:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3920187#M457333</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-09-06T13:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3920195#M457334</link>
      <description>&lt;P&gt;The only thing that would make sense is that it is authenticating with MAB first and then 802.1x is kicking in and authenticating that way.&amp;nbsp; ISE Radius Live Logs probably shows both authentications as succeeded.&amp;nbsp; Check the Live Logs and filter on the Endpoint ID (MAC Address).&amp;nbsp; This would happen if your interface configuration is setup to do MAB first with the command "authentication order mab dot1x".&amp;nbsp; And then you probably have "authentication priority dot1x mab" which means that it will do MAB but if an EAPOL frame is seen from the client, the switch will stop MAB immediately and start the dot1x process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are doing IBNS 2.0, then the configuration is probably trying both MAB and 802.1x at the same time.&amp;nbsp; Again, verify your ISE Live Logs to see if there are multiple entries for the same MAC address (Endpoint ID).&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 13:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3920195#M457334</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-09-06T13:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication method ISE 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3921366#M457335</link>
      <description>&lt;P&gt;Thank you both Mike and Colby. Nice suggestions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Krishnan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 20:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-method-ise-2-4/m-p/3921366#M457335</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2019-09-09T20:29:49Z</dc:date>
    </item>
  </channel>
</rss>

