<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1X stuck in running state in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3830430#M474507</link>
    <description>Hi Hslai,&lt;BR /&gt;We are running ise2.4 patch 6.&lt;BR /&gt;I checked the interface it has already an MTU of 1500:&lt;BR /&gt;&lt;BR /&gt;GigabitEthernet 1&lt;BR /&gt;flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt; mtu 1500&lt;BR /&gt;inet6 fe80::2a3:8eff:fe39:c59 prefixlen 64 scopeid 0x20&amp;lt;link&amp;gt;&lt;BR /&gt;ether 00:a3:8e:39:0c:59 txqueuelen 1000 (Ethernet)&lt;BR /&gt;RX packets 1006235 bytes 60374712 (57.5 MiB)&lt;BR /&gt;RX errors 0 dropped 0 overruns 0 frame 0&lt;BR /&gt;TX packets 23 bytes 2106 (2.0 KiB)&lt;BR /&gt;TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0&lt;BR /&gt;device memory 0xfb000000-fb0fffff&lt;BR /&gt;</description>
    <pubDate>Tue, 02 Apr 2019 07:49:42 GMT</pubDate>
    <dc:creator>bern81</dc:creator>
    <dc:date>2019-04-02T07:49:42Z</dc:date>
    <item>
      <title>Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3825623#M474501</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have configured dot1x on some switches and endpoint is windows native supplicant configured for EAP-TLS.&lt;/P&gt;&lt;P&gt;I noticed that some times the port is stuck in dot1x running state for about 45 sec&amp;nbsp; when i perform : sh authen session int g0/8&lt;/P&gt;&lt;P&gt;knowing that during this state i am able to ping normally the endpoint.&lt;/P&gt;&lt;P&gt;After that i see some kind of re-authentication in the radius debug logs and the port is in authc success state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group radius&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;aaa accounting update newinfo periodic 2880&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 send nas-port-detail mac-only&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server deadtime 3&lt;/P&gt;&lt;P&gt;ip device tracking probe interval 30&lt;BR /&gt;ip device tracking probe delay 10&lt;BR /&gt;authentication mac-move permit&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol&lt;BR /&gt;access-session acl default passthrough&lt;BR /&gt;epm logging&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#sh system mtu&lt;/P&gt;&lt;P&gt;System MTU size is 1500 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;port config:&lt;/P&gt;&lt;P&gt;int g0/8&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/8&lt;BR /&gt;description Bay13_MAB_8021x&lt;BR /&gt;switchport access vlan 482&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;load-interval 30&lt;BR /&gt;authentication event server dead action authorize&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer restart 75&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;BR /&gt;storm-control broadcast level 5.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am honestly suspecting something related to EAP-fragments.&lt;/P&gt;&lt;P&gt;because in the first authentication attempt i see the following message:&lt;/P&gt;&lt;P&gt;RADIUS(00000000): Received from id 1645/49&lt;BR /&gt;RADIUS/DECODE: EAP-Message fragments, 253+253+253+148, total 907 bytes&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;sh authentication sessions int g0/8 de&amp;nbsp; (during the running state)&lt;BR /&gt;Interface: GigabitEthernet0/8&lt;BR /&gt;MAC Address: 4c52.620c.3a37&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.77.39.181&lt;BR /&gt;Status: &lt;STRONG&gt;Unauthorized&lt;/STRONG&gt;&lt;BR /&gt;Domain: UNKNOWN&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 23s&lt;BR /&gt;Common Session ID: 0A000C89000000661F29EFA5&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0xC6000004&lt;BR /&gt;Current Policy: POLICY_Gi0/8&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dot1x Running&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After around 45 sec i see the following message along with the endpoint certificate:&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE: EAP-Message fragment 1492 into 253+253+253+253+253+227, total 1492 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#sh authentication sessions int g0/8 de&lt;BR /&gt;Interface: GigabitEthernet0/8&lt;BR /&gt;MAC Address: 4c52.620c.3a37&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.77.39.181&lt;BR /&gt;User-Name: U600BC0A.company.biz&lt;BR /&gt;Status: &lt;STRONG&gt;Authorized&lt;/STRONG&gt;&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: single-host&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: 43200s (server), Remaining: 43194s&lt;BR /&gt;Timeout action: Reauthenticate&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: 172800s (local), Remaining: 172794s&lt;BR /&gt;Session Uptime: 8s&lt;BR /&gt;Common Session ID: 0A000C890000006F1F5B500E&lt;BR /&gt;Acct Session ID: 0x00000132&lt;BR /&gt;Handle: 0x0F00000A&lt;BR /&gt;Current Policy: POLICY_Gi0/8&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Idle timeout: 300 sec&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dot1x Authc Success&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh version:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;C2960L Software (C2960L-UNIVERSALK9-M), Version 15.2(6)E1, RELEASE SOFTWARE (fc4) running LAN-Lite license.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did anyone faced this behavior&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 14:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3825623#M474501</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-25T14:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3825870#M474502</link>
      <description>&lt;P&gt;tricky one.&amp;nbsp; A few years back I had a customer who had enabled jumbo frames everywhere and ISE couldn't handle it when a large cert chain was exchanged during TLS negotiation.&amp;nbsp; Everything else was working fine though.&amp;nbsp; We eventually had to set the MTU on the switch to something less than 1450 or roundabout.&amp;nbsp; I think I sort of understand MTU but there are always some subtleties.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 21:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3825870#M474502</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-03-25T21:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3826071#M474503</link>
      <description>&lt;P&gt;Hi Arne,&lt;/P&gt;&lt;P&gt;The MTU is the default 1500 all the way to the ISE (At least i think that, i have to check the complete path since the ISEs reside in the Data center and reachable via VPLS lines)&lt;/P&gt;&lt;P&gt;I hope this will not create issues in production, because the weird thing is that the endpoint is reachable during the Running State even though the "sh authen session int g0/8 de" shows that the port is unauthorized!&lt;/P&gt;&lt;P&gt;If someone else is facing similar issue please advise if there is a workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 08:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3826071#M474503</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-26T08:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3829089#M474504</link>
      <description>Are you attempting any type of CoA? I am wondering if you would have the same issue if you were running a LAN Base License. LAN Lite supports dot1x, but pretty sure LAN Base provides advanced dot1x features. Not sure if this is the fix, but may be something you want to check here just to check another troubleshooting box.</description>
      <pubDate>Fri, 29 Mar 2019 19:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3829089#M474504</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-29T19:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3829391#M474505</link>
      <description>&lt;P&gt;ISE 2.4 Patch 2 addressed CSCvf52213, which adds CLI option for MTU --&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/cli_guide/b_ise_CLIReferenceGuide_24/b_ise_CLIReferenceGuide_24_chapter_011.html#wp6473719150" target="_blank"&gt;ip mtu&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 21:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3829391#M474505</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-03-30T21:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3830425#M474506</link>
      <description>Hi Mike,&lt;BR /&gt;I will test on a LAN base box to see if behavior is the same&lt;BR /&gt;The issue is that we have more than 2k switches that has to run on LAN-Lite for financial reason (so unfortunately i am stuck with this).</description>
      <pubDate>Tue, 02 Apr 2019 07:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3830425#M474506</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-04-02T07:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1X stuck in running state</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3830430#M474507</link>
      <description>Hi Hslai,&lt;BR /&gt;We are running ise2.4 patch 6.&lt;BR /&gt;I checked the interface it has already an MTU of 1500:&lt;BR /&gt;&lt;BR /&gt;GigabitEthernet 1&lt;BR /&gt;flags=4163&amp;lt;UP,BROADCAST,RUNNING,MULTICAST&amp;gt; mtu 1500&lt;BR /&gt;inet6 fe80::2a3:8eff:fe39:c59 prefixlen 64 scopeid 0x20&amp;lt;link&amp;gt;&lt;BR /&gt;ether 00:a3:8e:39:0c:59 txqueuelen 1000 (Ethernet)&lt;BR /&gt;RX packets 1006235 bytes 60374712 (57.5 MiB)&lt;BR /&gt;RX errors 0 dropped 0 overruns 0 frame 0&lt;BR /&gt;TX packets 23 bytes 2106 (2.0 KiB)&lt;BR /&gt;TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0&lt;BR /&gt;device memory 0xfb000000-fb0fffff&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Apr 2019 07:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-stuck-in-running-state/m-p/3830430#M474507</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-04-02T07:49:42Z</dc:date>
    </item>
  </channel>
</rss>

