<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x/mab behaviour with flexauth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3801104#M485375</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dooo.PNG" style="width: 461px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30030i69431BA349A847B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="dooo.PNG" alt="dooo.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 16:02:40 GMT</pubDate>
    <dc:creator>bern81</dc:creator>
    <dc:date>2019-02-13T16:02:40Z</dc:date>
    <item>
      <title>dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3797660#M485345</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;we have the following 802.1x config on our 802.1x switchport:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;dot1x system-auth-control&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;interface FastEthernet0/8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;description Bay_38_A036&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;switchport access vlan 238&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;switchport mode access&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;switchport nonegotiate&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;load-interval 30&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication event fail action next-method&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication order mab dot1x&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication priority dot1x mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication port-control auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication periodic&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication timer restart 90&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;authentication timer reauthenticate 60&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;mab&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;dot1x pae authenticator&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;dot1x max-reauth-req 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;storm-control broadcast level 5.00&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;storm-control action shutdown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;spanning-tree portfast&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;spanning-tree bpduguard enable.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;On this port we have win10 endpoint with eap-tls configured.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;I produced and error by removing the CA-cert that signed the identity certificate&amp;nbsp; of the ISE from this endpoint.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;When i shut/no shut the interface i see the following behaviour:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;debug radius authentication&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;MAB starts and after approx 1/2 sec 802.1x starts (i presume the switch receives an EAPoL Start from the endpoint.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Dot1X fails&amp;nbsp; and after 20 sec (10x (1+1)) it tries dot1x and timeouts.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;But we don't see any failover to MAB as next-method.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;SW130_A038#sh authentication sessions int f0/8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; UNKNOWN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A000C82000014EAAC2E4252&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x0001F8EC&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xF40004D8&lt;BR /&gt;&lt;BR /&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;and the port stays in this state forever. i don't see on the port any "restart timer" kicking off.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;============================================================================&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;If i modify this cmd:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;int f0/8&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;authentication event fail &lt;STRONG&gt;retry 1&lt;/STRONG&gt; action next-method&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt; and i bounce the port:&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;MAB starts and after approx 1/2 sec 802.1x starts (i presume the switch receives an EAPoL Start from the endpoint.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Dot1X fails&amp;nbsp; and after 20 sec (10x (1+1)) it tries dot1x and timeouts.it directly performs a failover to the next-method (MAB) and authenticate and authorize successfully.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;SW130_A038#sh authentication sessions int f0/8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 4c52.620c.3a37&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 4C-52-62-0C-3A-37&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; 60s (local), Remaining: 12s&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timeout action:&amp;nbsp; Reauthenticate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A000C82000014ECAC3E4816&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x0001F906&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xDA0004F3&lt;BR /&gt;&lt;BR /&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;And it periodically reauthenticate via MAB every 60sec (timer reauthenticate 60).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Is this behavior normal ? and why in the first config it is not failing over to the enxt method?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Am i missing something?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;&amp;nbsp;WS-C2960+24TC-S&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.0(2)SE6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C2960-LANLITEK9-M&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Please advise what normally should be the correct behavior and if there is something wrong in the configuration/timers.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;PS: we are using order MAB Dot1x because at the beginning we will have empty endpoints that will be provisioned via PXE boot.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;After the installation is successful the Win10 machine will have a pre-installed configuration with EAP-TLS and all the required digital certs in the cert store.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Many thanks in advance&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 11:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3797660#M485345</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-08T11:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798094#M485348</link>
      <description>&lt;P&gt;Your first test was invalid:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;SW130_A038#sh authentication sessions int f0/8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/8&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; Unknown&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; UNKNOWN&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;Nothing happens until the MAC address is learned on the port.&amp;nbsp; You have to map out the behavior after the MAC address is learned.&amp;nbsp; I don't ever do "order mab dot1x" as that can have other issues, but if it is working for you and your deployment continue to use it.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 20:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798094#M485348</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-02-08T20:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798095#M485352</link>
      <description>&lt;P&gt;I would not test missing certificate as failed scenario as Windows supplicant tends to keep on trying even when the supplicant lacks the certificate. Rather try to force supplicant to untrust ISE certificate instead for failure trigger. Remove '&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;authentication timer reauthenticate 60&lt;/FONT&gt;' and '&lt;FONT size="3" face="arial,helvetica,sans-serif"&gt;authentication periodic&lt;/FONT&gt;' as it is too frequent for reauth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 20:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798095#M485352</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-02-08T20:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798098#M485356</link>
      <description>authentication periodic is fine, but use "authentication timer reauthenticate server" and set the reauthentication timer in ISE.  I usually set my reauth timer to 65,000 seconds in ISE.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 08 Feb 2019 20:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798098#M485356</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-02-08T20:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798957#M485357</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;I lowered down the reauthentication timers just for lab purpose.&lt;/P&gt;
&lt;P&gt;This is weird to me why it is not learning the MAC and why when i add retry 1, it start working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 07:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798957#M485357</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-11T07:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798961#M485359</link>
      <description>&lt;P&gt;Hello Hosuk,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is exactly what i did.&lt;/P&gt;
&lt;P&gt;I removed the ISE-CA cert from the windows "Trusted root certificate store" to make the supplicant untrust the ISE-Cert.&lt;/P&gt;
&lt;P&gt;This issue here is that for some reason MAB is not working unless i add the retry 1 cmd which makes no sense at all.&lt;/P&gt;
&lt;P&gt;Could it be a bug ?&lt;/P&gt;
&lt;P&gt;Regarding the timers, i lowered them just for Lab purpose.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 07:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3798961#M485359</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-11T07:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3799242#M485364</link>
      <description>&lt;P&gt;It might be specific to your switch platform model and IOS release train.&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-cr-a3.html#wp1272896571" target="_blank"&gt;authentication event fail&lt;/A&gt;&amp;nbsp;shows the command default is that,&lt;/P&gt;
&lt;SECTION id="wp1272896571__GUID-3AC07EC0-3D17-4388-9A10-E4DCFB6C581F" class="section command_default"&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/SECTION&gt;
&lt;PRE&gt;Authentication is attempted two times after the initial failed attempt.
&lt;/PRE&gt;
&lt;P&gt;If you suspect it a bug, please open a TAC case so that TAC may help recreating it and gather the debugging info from the switch.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 14:40:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3799242#M485364</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-11T14:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3799253#M485368</link>
      <description>Hi Hslai,&lt;BR /&gt;Just to clarify things since the switch behavior is confusing me and i don't know anymore the correct behaviour.&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;in my config with order MAB Dot1X (with Failed Dot1X) what should it do?&lt;BR /&gt;If you can name the timers involved it would be great.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Feb 2019 14:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3799253#M485368</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-11T14:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3801093#M485371</link>
      <description>&lt;P style="text-align: left;"&gt;One more question regarding this topic: I have some switches with IOS Version&lt;/P&gt;
&lt;P style="text-align: left;"&gt;WS-C2960+24LC-S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.2(2)E6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C2960-LANLITEK9-M&lt;/P&gt;
&lt;P style="text-align: left;"&gt;on the interface level i don't see "authentication event fail server" command.&lt;/P&gt;
&lt;P style="text-align: left;"&gt;Is there any alternative to configure something similar to:&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;authentication event server dead action authorize vlan 238&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;To put the interface into critical Vlan in case ISE are dead?&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;Or do i have to upgrade the IOS ?&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: left;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 15:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3801093#M485371</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-13T15:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3801104#M485375</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dooo.PNG" style="width: 461px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30030i69431BA349A847B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="dooo.PNG" alt="dooo.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 16:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3801104#M485375</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-02-13T16:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x/mab behaviour with flexauth</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3803298#M485376</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-731907.html" target="_blank"&gt;Demystifying RADIUS Server Configurations - Cisco&lt;/A&gt;&amp;nbsp;explains about various timers.&lt;/P&gt;
&lt;P&gt;Your switch is &lt;SPAN&gt;C2960-&lt;STRONG&gt;LANLITE&lt;/STRONG&gt;K9-M&lt;/SPAN&gt;, which might have limited support on the features. Please check with the switch platform support teams.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2019 17:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-mab-behaviour-with-flexauth/m-p/3803298#M485376</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-16T17:54:06Z</dc:date>
    </item>
  </channel>
</rss>

