<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 patch 4 &amp;amp; HP H3C Comware 5 - Basic dot1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765119#M487205</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes it is working. I configured it manually for H3C switch, as h3c-av-pair = device-traffic-class = voice and this is working good.&lt;/P&gt;
&lt;P&gt;Phones are being put in the voice VLAN while computers and other endpoints are not.&lt;/P&gt;
&lt;P&gt;At the moment and for test purposes, the re-authentication timer on the switch is set to 2 minutes, but the behavior is exactly the same if it is set at 2 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I might be wrong, but I have the feeling that this is not timers related, only radius / dot1x.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2018 15:37:20 GMT</pubDate>
    <dc:creator>vncnt</dc:creator>
    <dc:date>2018-12-17T15:37:20Z</dc:date>
    <item>
      <title>ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3761950#M487191</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm getting stuck with an ISE deployement and HP H3C 5500 Comware 5 switch. Basically, that's a very simple DOT1X configuration, with just PermitAccess and some device-traffic-class=voice attribute to handle IP Phone authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The authentication itself is working like a charm. The problem occurs when the reauth timer is reached : I got two different "red" logs. See attachment : the 1st one seems to indicate that on the first Access-Challenge, the switch is initiating a new EAP session. Meaning the current session is discarded by ISE. The 2nd one refers to an invalid state attribute, session being discarded again.&lt;/P&gt;
&lt;P&gt;Looking at a packet capture, I can see that in the first Access-Challenge, ISE sends a state attribute (=1st log). But then, the switch seems to start a new session (still 1st log), meaning the state attribute is not valid anymore. There comes the second log : switch is starting a new EAP session with the state attribute that has been discarded by ISE (=2nd log).&lt;/P&gt;
&lt;P&gt;The second log looks like a consequence of the first behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, everything is reseted on both sides, a new EAP session is built and the endpoint is authenticated again. The problem is that during the two tenths of second this whole procedure takes, the phone is losing its connectivity and reboots...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea ? Thank you.&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Vincent&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 13:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3761950#M487191</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-12T13:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3764103#M487196</link>
      <description>&lt;P&gt;Have you confirmed that device-traffic-class=voice works with H3C switches? The AVP is Cisco AVP so not sure if it applies to the 3rd party switch like H3C. Also, if the attribute is accepted, then I would suggest looking into 802.1X and RADIUS timers on the switch to address the timing issue.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 20:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3764103#M487196</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-12-14T20:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3764725#M487200</link>
      <description>&lt;P&gt;For DOT1X like this, the endpoint is the IP phone but not the switch. Thus, please also check the auth timer(s) on the phone.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 03:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3764725#M487200</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T03:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765119#M487205</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes it is working. I configured it manually for H3C switch, as h3c-av-pair = device-traffic-class = voice and this is working good.&lt;/P&gt;
&lt;P&gt;Phones are being put in the voice VLAN while computers and other endpoints are not.&lt;/P&gt;
&lt;P&gt;At the moment and for test purposes, the re-authentication timer on the switch is set to 2 minutes, but the behavior is exactly the same if it is set at 2 hours.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I might be wrong, but I have the feeling that this is not timers related, only radius / dot1x.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 15:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765119#M487205</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-17T15:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765121#M487207</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you mean ? Of course the endpoint is the phone, but the phone never discuss with ISE.&lt;/P&gt;
&lt;P&gt;It gets challenged by the switch, and the switch is acting as authenticator, isn't it ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, I got the same behavior with Windows 7 or Windows 10 supplicant...&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 15:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765121#M487207</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-17T15:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765220#M487209</link>
      <description>&lt;P&gt;All three components are involved and each has its own timers, which may influence the outcomes.&lt;/P&gt;
&lt;P&gt;It seems CoA-reauth is not working&amp;nbsp;properly. As I do not have such NAD gear myself, I can't comment more. A good workaround is to avoid reauth during business hours.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 17:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765220#M487209</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T17:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765227#M487211</link>
      <description>&lt;P&gt;Alright, what would you advice for the timeouts on the three devices ?&lt;/P&gt;
&lt;P&gt;ISE EAP timeout greater than switch timeout greater than endpoint timeout ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 17:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765227#M487211</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-17T17:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765359#M487213</link>
      <description>&lt;P&gt;I think they should be about the same value. The first error you got is due to either the switch or the endpoint restarting the EAP conversation while ISE waiting for it. ISE has a fixed timer of 2 minutes.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 21:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765359#M487213</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T21:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765705#M487214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No it did not help : I configured everything with a 2 minutes timer, still same behavior.&lt;/P&gt;
&lt;P&gt;What I'm seeing in the PCAP and in the logs :&lt;/P&gt;
&lt;P&gt;- NAD sends a re-auth access-request&lt;/P&gt;
&lt;P&gt;- ISE is challenging the NAD, a state attribute is sent&lt;/P&gt;
&lt;P&gt;- NAD is starting a new EAP session, the state attribute previously sent is discarded on ISE side (that's a guess, but it would make sense)&lt;/P&gt;
&lt;P&gt;- NAD sends a new access-request... which contains the attribute received&lt;/P&gt;
&lt;P&gt;- ISE has probably discarded the state attribute, which became invalid, and drop the request&lt;/P&gt;
&lt;P&gt;&amp;gt; a new EAP session is starting again&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 10:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3765705#M487214</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-18T10:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3768108#M487215</link>
      <description>&lt;P&gt;Since re-auth problematic, then just disable it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 23:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3768108#M487215</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-21T23:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3769055#M487216</link>
      <description>&lt;P&gt;If your car's engine oil consumption is getting high, will you stop using it ? No, you will fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot say " well if a basic feature is not working, let's not use it ".&lt;/P&gt;
&lt;P&gt;This is basic DOT1X and according the compatibility matrix, this should work like a charm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2018 11:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/3769055#M487216</guid>
      <dc:creator>vncnt</dc:creator>
      <dc:date>2018-12-26T11:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 patch 4 &amp; HP H3C Comware 5 - Basic dot1x</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/4472880#M569910</link>
      <description>&lt;P&gt;i think this question solved&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please try config this under your interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;inter g1/0/3&amp;nbsp;&lt;/P&gt;&lt;P&gt;undo dot1x multicast-trigger&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 04:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-patch-4-amp-hp-h3c-comware-5-basic-dot1x/m-p/4472880#M569910</guid>
      <dc:creator>ethan_11</dc:creator>
      <dc:date>2021-09-24T04:23:40Z</dc:date>
    </item>
  </channel>
</rss>

