<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB authentication fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787089#M485950</link>
    <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are doing a MAB POC as we speak to enhance our level of port security for exotic non-dot1x devices.&lt;/P&gt;
&lt;P&gt;Our testdevice is a&amp;nbsp;IE3000 8p industrial switch with&amp;nbsp;Version 15.2(2)E4 (preferred IOS version for communication with ISE 2.2).&lt;/P&gt;
&lt;P&gt;When booting the device MAB authentication works 100% of time.&lt;/P&gt;
&lt;P&gt;When doing a shut/no shut of the network port or removing/inserting the network cable, in most of the cases MAB authentication fails and there is no more mac address of the end device in the mac address table.&lt;/P&gt;
&lt;P&gt;The only way to make things work again is a reboot of the device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;interface FastEthernet1/1&lt;BR /&gt; description ## Tel + PC dot1x mab ##&lt;BR /&gt; switchport access vlan 666&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 667&lt;BR /&gt; srr-queue bandwidth share 1 30 35 5&lt;BR /&gt; priority-queue out&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate 43200&lt;BR /&gt; mab&lt;BR /&gt; mls qos trust cos&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 5&lt;BR /&gt; auto qos trust&lt;BR /&gt; no mdix auto&lt;BR /&gt; storm-control broadcast level 60.00&lt;BR /&gt; storm-control action shutdown&lt;BR /&gt; storm-control action trap&lt;BR /&gt; macro description MAB&lt;BR /&gt; ip dhcp snooping limit rate 10&lt;BR /&gt; ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In attach you can find 2 debug files (debug mab all &amp;amp; debug authentication all)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Lieven Stubbe&lt;/P&gt;
&lt;P&gt;Belgian railways&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 10:05:46 GMT</pubDate>
    <dc:creator>lni1</dc:creator>
    <dc:date>2019-01-24T10:05:46Z</dc:date>
    <item>
      <title>MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787089#M485950</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are doing a MAB POC as we speak to enhance our level of port security for exotic non-dot1x devices.&lt;/P&gt;
&lt;P&gt;Our testdevice is a&amp;nbsp;IE3000 8p industrial switch with&amp;nbsp;Version 15.2(2)E4 (preferred IOS version for communication with ISE 2.2).&lt;/P&gt;
&lt;P&gt;When booting the device MAB authentication works 100% of time.&lt;/P&gt;
&lt;P&gt;When doing a shut/no shut of the network port or removing/inserting the network cable, in most of the cases MAB authentication fails and there is no more mac address of the end device in the mac address table.&lt;/P&gt;
&lt;P&gt;The only way to make things work again is a reboot of the device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;interface FastEthernet1/1&lt;BR /&gt; description ## Tel + PC dot1x mab ##&lt;BR /&gt; switchport access vlan 666&lt;BR /&gt; switchport mode access&lt;BR /&gt; switchport voice vlan 667&lt;BR /&gt; srr-queue bandwidth share 1 30 35 5&lt;BR /&gt; priority-queue out&lt;BR /&gt; authentication control-direction in&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x mab&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; authentication periodic&lt;BR /&gt; authentication timer reauthenticate 43200&lt;BR /&gt; mab&lt;BR /&gt; mls qos trust cos&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 5&lt;BR /&gt; auto qos trust&lt;BR /&gt; no mdix auto&lt;BR /&gt; storm-control broadcast level 60.00&lt;BR /&gt; storm-control action shutdown&lt;BR /&gt; storm-control action trap&lt;BR /&gt; macro description MAB&lt;BR /&gt; ip dhcp snooping limit rate 10&lt;BR /&gt; ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In attach you can find 2 debug files (debug mab all &amp;amp; debug authentication all)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Lieven Stubbe&lt;/P&gt;
&lt;P&gt;Belgian railways&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 10:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787089#M485950</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-01-24T10:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787175#M485952</link>
      <description>This looks like a switching issue and nothing to do with ISE. Would recommend querying them as well&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Jan 2019 12:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787175#M485952</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-01-24T12:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787243#M485953</link>
      <description>&lt;P&gt;your config should be in this order&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1/1&lt;BR /&gt;description ## Tel + PC dot1x mab ##&lt;BR /&gt;switchport access vlan 666&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 667&lt;BR /&gt;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;priority-queue out&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;&lt;STRONG&gt;authentication order mab dot1x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;authentication event fail next-method&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(optional-command authentication host-mode |single-host|multi-auth)&lt;/STRONG&gt;&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 43200&lt;BR /&gt;mab&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 5&lt;BR /&gt;auto qos trust&lt;BR /&gt;no mdix auto&lt;BR /&gt;storm-control broadcast level 60.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;storm-control action trap&lt;BR /&gt;macro description MAB&lt;BR /&gt;ip dhcp snooping limit rate 10&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 13:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787243#M485953</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-24T13:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787862#M485954</link>
      <description>&lt;P&gt;Already tried to change the authentication order, also tried serveral other options as proposed by the community:&lt;/P&gt;
&lt;P&gt;The problem is that when doing a shut/no shut or cable disconnect the switch loses the mac address of the end client and is unable to retrieve it again.&lt;/P&gt;
&lt;P&gt;Debug authentication all:&lt;/P&gt;
&lt;P&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] Link UP&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] &lt;STRONG&gt;No authorized client found in domain&lt;/STRONG&gt; [DATA]&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] Domain authorized client count: &lt;STRONG&gt;0&lt;/STRONG&gt;&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] No authorized client found in domain [DATA]&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] Domain authorized client count: &lt;STRONG&gt;0&lt;/STRONG&gt;&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] Link UP&lt;BR /&gt;Jan 25 08:55:55: AUTH-EVENT: [Fa1/1] Link already UP - ignoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does end client devices need to meet certain requirements to be able to do MAB? (EAPOL,...). With our laptops/desktops we never experience this&amp;nbsp; behaviour, it's only with more "exotic" devices our switches seem to lose the MAC address over time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 08:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787862#M485954</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-01-25T08:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787901#M485956</link>
      <description>&lt;P&gt;Does end client devices need to meet certain requirements to be able to do MAB? (EAPOL,...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why dont you run a packet capture and check if the EAPOL values from the both end.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 08:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3787901#M485956</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-25T08:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788076#M485957</link>
      <description>&lt;HR /&gt;
&lt;P&gt;We ran a packet capture and saw that the device had a fix Ip&lt;/P&gt;
&lt;P&gt;The moment we changed it to DHCP, MAB works.&lt;/P&gt;
&lt;P&gt;When we reconnect the cable, a DHCP discover is send out, and the MAC is learned by the switch, which can be used for MAB procedure.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 13:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788076#M485957</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-01-25T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788102#M485960</link>
      <description>&lt;P&gt;Interesting. so your issue is fixed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do not forget to rate&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 14:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788102#M485960</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-25T14:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788838#M485961</link>
      <description>&lt;P&gt;It sounds as if your hitting a bug on the switch side and this has nothing to do with ISE , especially if you modified your end point to DHCP and suddenly you have a mac entry in your mac table.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2019 08:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3788838#M485961</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-01-27T08:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3789258#M485962</link>
      <description>&lt;P&gt;We are running&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;IE3000 8p industrial switch with&amp;nbsp;Version 15.2(2)E4 (preferred IOS version for communication with ISE 2.2), if we can't even trust preferred Cisco versions anymore?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Excerpt from the Cisco doc: "During the MAC address learning stage, the switch begins MAB by opening the port to accept a single packet from which it will learn the source MAC address of the endpoint"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So if we do DHCP we see a "DHCP discover" packet, when we do IP fix we see no packets at all, the switch need to have a certain packet from the end device to learn the MAC or are there other options?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Lieven Stubbe&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Belgian railways&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 10:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3789258#M485962</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2019-01-28T10:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAB authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3891542#M485963</link>
      <description>&lt;P&gt;HI This seems to be a common issue with MAB and "quiet" endpoints espically static endpoint's.. IE endpoints that dont send a lot of traffic hence no mac address on the swtich port hence no auth session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had this issues and we fixed it by running "authentication control auth direction in" on the swtich port..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allow broadcast,arps etc into the switch port and hence prompting the endpoint to reply and send its source mac to the switch .&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2019 03:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-fails/m-p/3891542#M485963</guid>
      <dc:creator>x00008037</dc:creator>
      <dc:date>2019-07-17T03:06:17Z</dc:date>
    </item>
  </channel>
</rss>

