<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DATA Domain MAB Failure; VOICE Domain Succeeds in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848878#M473521</link>
    <description>&lt;P&gt;Please open TAC case regarding your switch.&lt;/P&gt;
&lt;P&gt;I will close this thread as it is not due to ISE.&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2019 07:13:19 GMT</pubDate>
    <dc:creator>ldanny</dc:creator>
    <dc:date>2019-05-02T07:13:19Z</dc:date>
    <item>
      <title>DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848238#M473421</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I'm in the process of testing ISE on a switch that is currently in production.&amp;nbsp; I had a phone and laptop connected to a port and configured that port only for AAA.&amp;nbsp; The rest of the switch is bootstrapped with all required AAA/RADIUS commands.&amp;nbsp; However, I'm getting the following log messages:&lt;/P&gt;&lt;P&gt;.Apr 30 21:10:54.146: %LINK-3-UPDOWN: Interface FastEthernet0/14, changed state to down&lt;BR /&gt;.Apr 30 21:10:55.748: %AUTHMGR-5-START: Starting 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000056792A7B&lt;BR /&gt;.Apr 30 21:10:55.824: %MAB-5-FAIL: Authentication failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000056792A7B&lt;BR /&gt;.Apr 30 21:10:55.832: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000056792A7B&lt;BR /&gt;.Apr 30 21:10:55.832: %AUTHMGR-5-FAIL: Authorization failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000056792A7B&lt;BR /&gt;.Apr 30 21:10:56.856: %LINK-3-UPDOWN: Interface FastEthernet0/14, changed state to up&lt;BR /&gt;.Apr 30 21:10:57.862: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/14, changed state to up&lt;BR /&gt;.Apr 30 21:11:08.122: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/14, changed state to down&lt;BR /&gt;.Apr 30 21:11:09.128: %LINK-3-UPDOWN: Interface FastEthernet0/14, changed state to down&lt;BR /&gt;.Apr 30 21:11:11.762: %AUTHMGR-5-START: Starting 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:11:11.796: %MAB-5-FAIL: Authentication failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:11:11.804: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:11:11.804: %AUTHMGR-5-FAIL: Authorization failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:11:12.693: %LINK-3-UPDOWN: Interface FastEthernet0/14, changed state to up&lt;BR /&gt;.Apr 30 21:11:13.700: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/14, changed state to up&lt;BR /&gt;.Apr 30 21:11:13.843: %AUTHMGR-5-START: Starting 'mab' for client (0800.0fb2.de2f) on Interface Fa0/14 AuditSessionID C0A83C0D000000035679748A&lt;BR /&gt;.Apr 30 21:11:13.876: %MAB-5-SUCCESS: Authentication successful for client (0800.0fb2.de2f) on Interface Fa0/14 AuditSessionID C0A83C0D000000035679748A&lt;BR /&gt;.Apr 30 21:11:13.885: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (0800.0fb2.de2f) on Interface Fa0/14 AuditSessionID C0A83C0D000000035679748A&lt;BR /&gt;.Apr 30 21:11:14.891: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0800.0fb2.de2f) on Interface Fa0/14 AuditSessionID C0A83C0D000000035679748A&lt;BR /&gt;.Apr 30 21:12:12.638: %MAB-5-FAIL: Authentication failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:12:12.647: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:12:12.647: %AUTHMGR-5-FAIL: Authorization failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:13:13.448: %MAB-5-FAIL: Authentication failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:13:13.448: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;.Apr 30 21:13:13.456: %AUTHMGR-5-FAIL: Authorization failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0D0000000256796851&lt;BR /&gt;*Aug 19 11:24:19.481: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.2.138.253:1812,1813 is not responding.&lt;BR /&gt;*Aug 19 11:24:19.490: %MAB-5-FAIL: Authentication failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0E00000010730736D6&lt;BR /&gt;*Aug 19 11:24:19.507: %AUTHMGR-7-RESULT: Authentication result 'server dead' from 'mab' for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0E00000010730736D6&lt;BR /&gt;*Aug 19 11:24:19.507: %AUTHMGR-5-FAIL: Authorization failed for client (0023.5ad6.6ce8) on Interface Fa0/14 AuditSessionID C0A83C0E00000010730736D6&lt;BR /&gt;*Aug 19 11:24:35.781: %ILPOWER-5-IEEE_DISCONNECT: Interface Fa0/14: PD removed&lt;BR /&gt;*Aug 19 11:24:36.024: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/14, changed state to down&lt;BR /&gt;*Aug 19 11:24:37.022: %LINK-3-UPDOWN: Interface FastEthernet0/14, changed state to down&lt;BR /&gt;*Aug 19 11:25:16.172: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.2.138.252:1812,1813 is being marked alive.&lt;/P&gt;&lt;P&gt;Notice that it appears that the RADIUS server is marked dead when the phone and laptop connects to the port.&amp;nbsp; When the clients are disconnected, the server is marked alive again.&amp;nbsp; I know my ISE configuration and policies are correct because everything works perfect from a switch that runs IOS version 15.&amp;nbsp; The switch generating the logs above is running 12.2(55)SE12.&amp;nbsp; What's more is that the phone passes MAB authentication but the laptop behind it fails.&amp;nbsp; I have confirmed that the aaa server state was up but soon went down when the port status change from down to up.&amp;nbsp; When the client disconnects the server status changes back to up.&amp;nbsp; Even more, when I check my ISE RADIUS logs, I see that both phone and PC MAC is hitting the correct policy for authc &amp;amp; authz but my tester couldn't pull our guest hotspot AUP page.&lt;/P&gt;&lt;P&gt;The port config in question is as follows (please note that I tried it with and without the event server dead commands but still no difference):&lt;/P&gt;&lt;P&gt;interface FastEthernet0/14&lt;BR /&gt;description *** Shortel Phones DHCP ***&lt;BR /&gt;switchport access vlan 60&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;switchport voice vlan 30&lt;BR /&gt;ip device tracking maximum 2&lt;BR /&gt;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;priority-queue out&lt;BR /&gt;authentication event server dead action authorize vlan 30&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order mab&lt;BR /&gt;authentication priority mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;storm-control broadcast level 20.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;auto qos trust&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;This is the same config commands I use on the 3560CX 8 port switch I use for testing.&amp;nbsp; Could this be an IOS bug I'm running into?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Terence&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 22:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848238#M473421</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-04-30T22:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848295#M473424</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/compatibility/b_ise_sdt_26.html#supportedciscoaccessswitches" target="_blank"&gt;ISE 2.6 NAD Compatibility &amp;gt; Validated Cisco Access Switches&lt;/A&gt;&amp;nbsp;shows IOS 15.2(3)E is the minimal required for 3560-CX to work with ISE.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 00:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848295#M473424</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-05-01T00:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848319#M473515</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;MAB works perfectly with my 3560CX. Its the 2960 that the logs I shared are coming from. It runs 12.2(55)SE12.&lt;BR /&gt;</description>
      <pubDate>Wed, 01 May 2019 01:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848319#M473515</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-05-01T01:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848321#M473517</link>
      <description>&lt;P&gt;Also, I'm running ISE 2.3 patch 6&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 02:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848321#M473517</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-05-01T02:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848322#M473518</link>
      <description>&lt;P&gt;I did find this URL and see that there is limited support for Guest and no support for Guest Originating URL for minimum version 12.2(55)SE5.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/compatibility/ise_sdt.html#13367" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/compatibility/ise_sdt.html#13367&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming this limited support is why I'm running into this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 02:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848322#M473518</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-05-01T02:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848540#M473519</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you share the config of your port and some screenshots of ISE configuration?</description>
      <pubDate>Wed, 01 May 2019 14:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848540#M473519</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-05-01T14:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848562#M473520</link>
      <description>My port config is in my original post. I'm out of the office today so I won't be able to get the ISE screen shots until tomorrow.&lt;BR /&gt;&lt;BR /&gt;Again, the issue isn't ISE because I see success attempts and the correct AuthZ profile for the MAC the switch is showing failed AuthC messages. The issue has to be the 2960 switch. All works perfectly fine from my 3560CX with no changes to my ISE policies.&lt;BR /&gt;</description>
      <pubDate>Wed, 01 May 2019 15:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848562#M473520</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-05-01T15:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848878#M473521</link>
      <description>&lt;P&gt;Please open TAC case regarding your switch.&lt;/P&gt;
&lt;P&gt;I will close this thread as it is not due to ISE.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 07:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3848878#M473521</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-05-02T07:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: DATA Domain MAB Failure; VOICE Domain Succeeds</title>
      <link>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3849011#M473522</link>
      <description>&lt;P&gt;No TAC assistance needed.&amp;nbsp; The IOS 12.2(55)SE image was indeed the cause of the issue.&amp;nbsp; I upgraded the image to 15.0 for my 2960 PST-L and now it's authenticating both domains rather than just the voice domain.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 12:18:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/data-domain-mab-failure-voice-domain-succeeds/m-p/3849011#M473522</guid>
      <dc:creator>Terence Lockette</dc:creator>
      <dc:date>2019-05-02T12:18:59Z</dc:date>
    </item>
  </channel>
</rss>

