<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE High Repeat Counts in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3808920#M484868</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've noticed a quirky issue within&amp;nbsp;our ISE console and the repeat counter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our system has been running fine with just the odd issue we can easily resolve (mainly phones being unable to drop the session behind then from laptops).&lt;/P&gt;
&lt;P&gt;However, we noticed that if a building&amp;nbsp;connectivity is dropped back to the core network switch, all devices that are use a MAB rule to authenticate (phones and printers) from that switch stack experience high repeat counts for a day or two, which then drops down to "normal".&amp;nbsp; Laptops and PCs which are using a certificate to authenticate are fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know why this could happen?&amp;nbsp; To me, it appears as though the switch is queing up authentication requests and the ISE console is just taking time to "catch up" with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch IOS version: 15.2(2)E7&lt;/P&gt;
&lt;P&gt;ISE Version: 2.4.0.357&lt;/P&gt;
&lt;P&gt;Installed Patches: 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can provide some more information if needed to help identify the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Graeme&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 09 Mar 2019 03:14:04 GMT</pubDate>
    <dc:creator>graeme.walker</dc:creator>
    <dc:date>2019-03-09T03:14:04Z</dc:date>
    <item>
      <title>ISE High Repeat Counts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3808920#M484868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've noticed a quirky issue within&amp;nbsp;our ISE console and the repeat counter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our system has been running fine with just the odd issue we can easily resolve (mainly phones being unable to drop the session behind then from laptops).&lt;/P&gt;
&lt;P&gt;However, we noticed that if a building&amp;nbsp;connectivity is dropped back to the core network switch, all devices that are use a MAB rule to authenticate (phones and printers) from that switch stack experience high repeat counts for a day or two, which then drops down to "normal".&amp;nbsp; Laptops and PCs which are using a certificate to authenticate are fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know why this could happen?&amp;nbsp; To me, it appears as though the switch is queing up authentication requests and the ISE console is just taking time to "catch up" with this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch IOS version: 15.2(2)E7&lt;/P&gt;
&lt;P&gt;ISE Version: 2.4.0.357&lt;/P&gt;
&lt;P&gt;Installed Patches: 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can provide some more information if needed to help identify the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Graeme&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 03:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3808920#M484868</guid>
      <dc:creator>graeme.walker</dc:creator>
      <dc:date>2019-03-09T03:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE High Repeat Counts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3808996#M484870</link>
      <description>The repeat counter will increment when there are authentication requests that have been repeated with no change in 24 hours. Do you have a re-authentication timer configured in your authz profiles OR manually deployed on your switchports? If you do, this may be the reason as to why you are seeing the repeat counter increment.&lt;BR /&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Mon, 25 Feb 2019 13:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3808996#M484870</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-02-25T13:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE High Repeat Counts</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3809792#M484871</link>
      <description>&lt;P&gt;Thanks Mike,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I can see it is configured on each individual port:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;Current configuration : 814 bytes&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;interface GigabitEthernet3/0/48&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;description Standard User/Voice Port&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;switchport mode access&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;switchport voice vlan 10&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication control-direction in&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication event fail action next-method&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication event server dead action authorize&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication host-mode multi-domain&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication order dot1x mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication priority dot1x mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication port-control auto&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication periodic&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication timer inactivity server&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;authentication violation restrict&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;mab&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;dot1x pae authenticator&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;dot1x timeout quiet-period 1800&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;dot1x max-req 1&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;dot1x max-reauth-req 1&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;&amp;nbsp;spanning-tree portfast&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000ff"&gt;&lt;EM&gt;end&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue I am having is when a switch stack has a loss of connectifity back to the ISE server (which is rare but has happened after some fiber repatching), that stack seems to run slow and devices have continuous repeat attempts just from devices connected to that stack hitting MAB rules.&amp;nbsp; The stacks in other buildings are fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have reset the repeat counter and will monitor this - I've also asked for the stack in question to be reloaded but that is like asking for blood...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Graeme&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 10:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-high-repeat-counts/m-p/3809792#M484871</guid>
      <dc:creator>graeme.walker</dc:creator>
      <dc:date>2019-02-26T10:24:25Z</dc:date>
    </item>
  </channel>
</rss>

