<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DOT1X Authentication Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822943#M474608</link>
    <description>&lt;P&gt;When you look at the switch side do you see the session go into an authenticated state?&amp;nbsp; There could be attributes that you are passing back from ISE that cause the session to go Unauth so it never truly completes even though ISE authenticated it.&amp;nbsp; If you see everything look good on the switch side watch the detailed "show auth session" or "show access-session" output for that port.&amp;nbsp; You will probably see Dot1x rerunning constantly.&amp;nbsp; If the switch is satisfied with the authentication the only way it would rerun Dot1x is if it received a EAPol start message from the client.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 13:57:40 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2019-03-20T13:57:40Z</dc:date>
    <item>
      <title>DOT1X Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822863#M474605</link>
      <description>&lt;P&gt;Running a C4506-E 15.2(2)E8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Machines are authenticating through ISE. Within 30 seconds one will fail to authenticate (After it has already passed authentication)..It seems like a round robin of machines that are failing to authenticate after they already authenticate. This process continues forever. Its like ISE is only accepting so many Mac addresses from this switch to authenticate at once, and every time that limit is reached one is forced to fail authentication to make room for another machine. Im not too sure where to start as far as troubleshooting this issue. Any advice would help.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 12:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822863#M474605</guid>
      <dc:creator>fredrick.pettiford</dc:creator>
      <dc:date>2019-03-20T12:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1X Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822892#M474606</link>
      <description>&lt;P&gt;the first place to look is in ISE under LiveLogs (or in Reports) to see why ISE had to fail the authentication.&amp;nbsp; Sometimes the reason that ISE gives is not the real reason/cause, but it's a starting point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version of ISE?&lt;/P&gt;
&lt;P&gt;What type of PAN/PSN? SNS-34 or SNS-35 etc.&lt;/P&gt;
&lt;P&gt;How many endpoints do you see in the dashboard?&lt;/P&gt;
&lt;P&gt;I doubt this makes any difference, but is the CPU trending high?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 13:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822892#M474606</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-03-20T13:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1X Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822938#M474607</link>
      <description>Thanks for the reply,&lt;BR /&gt;&lt;BR /&gt;Total endpoints = 92335&lt;BR /&gt;Active endpoints = 22148&lt;BR /&gt;&lt;BR /&gt;ISE Version = 2.1.0.474 &lt;BR /&gt;PID= SNS-3495-K9&lt;BR /&gt;Installed Patched 1.2.3.5.7.8&lt;BR /&gt;&lt;BR /&gt;CPU is not trending high. Steady around 10%&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Also when checking the live logs i see the machine authenticating..but it shows it authenticating 1033 times.&lt;BR /&gt;Like i mentioned about the devices just keep re-authenticating.&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Mar 2019 13:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822938#M474607</guid>
      <dc:creator>fredrick.pettiford</dc:creator>
      <dc:date>2019-03-20T13:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: DOT1X Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822943#M474608</link>
      <description>&lt;P&gt;When you look at the switch side do you see the session go into an authenticated state?&amp;nbsp; There could be attributes that you are passing back from ISE that cause the session to go Unauth so it never truly completes even though ISE authenticated it.&amp;nbsp; If you see everything look good on the switch side watch the detailed "show auth session" or "show access-session" output for that port.&amp;nbsp; You will probably see Dot1x rerunning constantly.&amp;nbsp; If the switch is satisfied with the authentication the only way it would rerun Dot1x is if it received a EAPol start message from the client.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 13:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authentication-problem/m-p/3822943#M474608</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-20T13:57:40Z</dc:date>
    </item>
  </channel>
</rss>

