<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Works... and sometimes doesn't in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872242#M472309</link>
    <description>&lt;P&gt;I recommend you work in&amp;nbsp; Limited Access Mode ( authentication open ) on your switch ports ,with a pre-defined ACL so that you dont impact your users.&lt;/P&gt;
&lt;P&gt;You can then start looking at your logs and get a better understanding of why dot1x is failing without impacting anyone, as well as understand your policy structure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2019 07:36:32 GMT</pubDate>
    <dc:creator>ldanny</dc:creator>
    <dc:date>2019-06-13T07:36:32Z</dc:date>
    <item>
      <title>Cisco ISE Works... and sometimes doesn't</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872091#M472307</link>
      <description>&lt;P&gt;I'm not sure how to describe this issue.&amp;nbsp; Or what to even look for to resolve it.&amp;nbsp; But here goes nothing:&lt;BR /&gt;&lt;BR /&gt;My company has recently deployed ISE to a facility for Identity management.&amp;nbsp; After several months we ran into a host and myriad of problems which, thankfully, were resolved in one form or another.&amp;nbsp; Recently we've had users report network related issues as ISE issues.&amp;nbsp; 9 times out of 10, they're false alarms or red-herrings.&amp;nbsp; A user mistyped there password, or an update was rolled out that knocked them offline, stuff like this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However for the 1 out of 10... I can't explain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A bit of background - We deployed ISE in an Apple majority environment.&amp;nbsp; With only a handful of users on Windows.&amp;nbsp; So features like EAP-Chaining are a no-go (Apple doesn't natively support it, and we haven't tested a 'supposedly' updated Cisco Anyconnect version that fixes this).&amp;nbsp; Again this is all fine, we've been working around certain limitations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the user's perspective, they've logged into there machine without issues.&amp;nbsp; But now the internet isn't working, and they have a Guest portal asking them to register with the network.&amp;nbsp; And ISE is none-the-wiser that they're a corporate user.&amp;nbsp; A simple reboot corrects the problem.&amp;nbsp; But it's still an issue I'm trying to solve and prevent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 01:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872091#M472307</guid>
      <dc:creator>TitanAE</dc:creator>
      <dc:date>2019-06-13T01:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Works... and sometimes doesn't</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872130#M472308</link>
      <description>Sounds like dot1x is failing on the laptops and it’s falling back to MAB and redirect to guest portal&lt;BR /&gt;&lt;BR /&gt;Please open a tac case to look at switch ise and even desktop logs&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Jun 2019 03:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872130#M472308</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-13T03:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Works... and sometimes doesn't</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872242#M472309</link>
      <description>&lt;P&gt;I recommend you work in&amp;nbsp; Limited Access Mode ( authentication open ) on your switch ports ,with a pre-defined ACL so that you dont impact your users.&lt;/P&gt;
&lt;P&gt;You can then start looking at your logs and get a better understanding of why dot1x is failing without impacting anyone, as well as understand your policy structure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 07:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-works-and-sometimes-doesn-t/m-p/3872242#M472309</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-06-13T07:36:32Z</dc:date>
    </item>
  </channel>
</rss>

