<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882257#M471910</link>
    <description>&lt;P&gt;- What is the auth status for these endpoints on the 3850 'show auth sess int gig1/0/3 detail'? IT is Success but it should get a 5 second inactivity timer pushed from ISE like the second example below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch#sho authentication sessions interface gigabitEthernet 1/0/26 details&lt;BR /&gt;Interface: GigabitEthernet1/0/26&lt;BR /&gt;IIF-ID: 0x2A3D51D4&lt;BR /&gt;MAC Address: fc0a.81c2.0024&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: FC-0A-81-C2-00-24&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC103F07000C790EA7603412&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x33000750&lt;BR /&gt;Current Policy: POLICY_Gi1/0/26&lt;BR /&gt;Blocked On: apply user profile - RX_METHOD_NEW_MAC (1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;----------------------------------------&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/26&lt;BR /&gt;IIF-ID: 0x2DD24675&lt;BR /&gt;MAC Address: fc0a.81c3.32c0&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.16.34.212&lt;BR /&gt;User-Name: FC-0A-81-C3-32-C0&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC103F07000CC0DDAB3D0860&lt;BR /&gt;Acct Session ID: 0x00038722&lt;BR /&gt;Handle: 0xb900007d&lt;BR /&gt;Current Policy: POLICY_Gi1/0/26&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Idle timeout: 5 sec&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is the AuthC status of these endpoints on ISE? -- Unauthorized&lt;/P&gt;&lt;P&gt;- What is the AuthZ profile sent for these endpoints?--&amp;nbsp; the below gets pushed&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Idle-Timeout = 5&lt;/P&gt;&lt;P&gt;- Are these endpoints still connected? These are endpoint's that are in a moving vesicle and connect to each AP at the vehicle station&lt;/P&gt;&lt;P&gt;- How are these endpoints authenticated on the Motorola AP? The just associate to the Motorolla AP but this systme i dont have too much visibility of. We just MAB them once they appear on the switch port..&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 02:04:21 GMT</pubDate>
    <dc:creator>x00008037</dc:creator>
    <dc:date>2019-07-01T02:04:21Z</dc:date>
    <item>
      <title>3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3881173#M471905</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have anissue with ISE authentication. I have Motorola wireless access point hangin off a 3850 (16.6.2) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some clients are getting Stuck in this state below and the Auth session is not clearing...and the port have this message on the affected port "Blocked On: apply user profile - RX_METHOD_NEW_MAC (1)"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/3 fc0a.81c0.a350 N/A DATA Unauth U AC101F0B000A04C78DDBD673&lt;BR /&gt;Gi1/0/3 7467.f7af.e1dc mab DATA Auth AC101F0B000ADDAE9BD1111E&lt;BR /&gt;Gi1/0/3 000b.ab81.58f6 N/A DATA Unauth U AC101F0B0009F7FA8D42EAED&lt;BR /&gt;Gi1/0/3 000b.ab85.00f5 N/A DATA Unauth U AC101F0B00098ED1882B25E9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;A - Applying Policy (multi-line status for details)&lt;BR /&gt;D - Awaiting Deletion&lt;BR /&gt;F - Final Removal in progress&lt;BR /&gt;I - Awaiting IIF ID allocation&lt;BR /&gt;P - Pushed Session&lt;BR /&gt;R - Removing User Profile (multi-line status for details)&lt;BR /&gt;U - Applying User Profile (multi-line status for details)&lt;BR /&gt;X - Unknown Blocker&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/3&lt;BR /&gt;IIF-ID: 0x13280E3F&lt;BR /&gt;MAC Address: fc0a.81c0.a350&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: FC-0A-81-C0-A3-50&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC101F0B000A04C78DDBD673&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x20000f07&lt;BR /&gt;Current Policy: POLICY_Gi1/0/3&lt;BR /&gt;Blocked On: apply user profile - RX_METHOD_NEW_MAC (1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else had this type of issue??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/3&lt;BR /&gt;description [EDGE] Wireless&lt;BR /&gt;switchport access vlan 102&lt;BR /&gt;switchport mode access&lt;BR /&gt;power inline never&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;authentication timer unauthorized 5&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;storm-control broadcast level 1.00&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;spanning-tree guard root&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 02:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3881173#M471905</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2019-06-28T02:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3881572#M471909</link>
      <description>&lt;P&gt;Few questions:&lt;/P&gt;
&lt;P&gt;- What is the auth status for these endpoints on the 3850 'show auth sess int gig1/0/3 detail'?&lt;/P&gt;
&lt;P&gt;- What is the AuthC status of these endpoints on ISE?&lt;/P&gt;
&lt;P&gt;- What is the AuthZ profile sent for these endpoints?&lt;/P&gt;
&lt;P&gt;- Are these endpoints still connected?&lt;/P&gt;
&lt;P&gt;- How are these endpoints authenticated on the Motorola AP?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 15:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3881572#M471909</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-06-28T15:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882257#M471910</link>
      <description>&lt;P&gt;- What is the auth status for these endpoints on the 3850 'show auth sess int gig1/0/3 detail'? IT is Success but it should get a 5 second inactivity timer pushed from ISE like the second example below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch#sho authentication sessions interface gigabitEthernet 1/0/26 details&lt;BR /&gt;Interface: GigabitEthernet1/0/26&lt;BR /&gt;IIF-ID: 0x2A3D51D4&lt;BR /&gt;MAC Address: fc0a.81c2.0024&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: FC-0A-81-C2-00-24&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC103F07000C790EA7603412&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x33000750&lt;BR /&gt;Current Policy: POLICY_Gi1/0/26&lt;BR /&gt;Blocked On: apply user profile - RX_METHOD_NEW_MAC (1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;----------------------------------------&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/26&lt;BR /&gt;IIF-ID: 0x2DD24675&lt;BR /&gt;MAC Address: fc0a.81c3.32c0&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.16.34.212&lt;BR /&gt;User-Name: FC-0A-81-C3-32-C0&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: AC103F07000CC0DDAB3D0860&lt;BR /&gt;Acct Session ID: 0x00038722&lt;BR /&gt;Handle: 0xb900007d&lt;BR /&gt;Current Policy: POLICY_Gi1/0/26&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Idle timeout: 5 sec&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What is the AuthC status of these endpoints on ISE? -- Unauthorized&lt;/P&gt;&lt;P&gt;- What is the AuthZ profile sent for these endpoints?--&amp;nbsp; the below gets pushed&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Idle-Timeout = 5&lt;/P&gt;&lt;P&gt;- Are these endpoints still connected? These are endpoint's that are in a moving vesicle and connect to each AP at the vehicle station&lt;/P&gt;&lt;P&gt;- How are these endpoints authenticated on the Motorola AP? The just associate to the Motorolla AP but this systme i dont have too much visibility of. We just MAB them once they appear on the switch port..&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 02:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882257#M471910</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2019-07-01T02:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882946#M471911</link>
      <description>&lt;P&gt;The error is similar to that found in&amp;nbsp;CSCvm07425. As this is a switch IOS platform code issue, please open a Cisco TAC case to troubleshoot and get advised on which release might work for your deployment.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 02:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882946#M471911</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-02T02:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882953#M471915</link>
      <description>&lt;P&gt;This link to the bug is not working&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 03:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882953#M471915</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2019-07-02T03:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882960#M471921</link>
      <description>&lt;P&gt;That bug is customer visible. Likely, you are not currently entitled to, somehow.&lt;/P&gt;
&lt;P&gt;As it's not an ISE issue, I am unable to tell whether you hitting that particular bug or which IOS releases have the fix. That is why I asked you to engage TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 03:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882960#M471921</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-02T03:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: 3850 (RX_METHOD_NEW_MAC) un-authenticated clients</title>
      <link>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882965#M471923</link>
      <description>OK Thanks for your help.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I have TAC case opened&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;cheers&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Jul 2019 04:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/3850-rx-method-new-mac-un-authenticated-clients/m-p/3882965#M471923</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2019-07-02T04:03:17Z</dc:date>
    </item>
  </channel>
</rss>

