<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect NAM EAPoL logoff messages in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694566#M495021</link>
    <description>Do you have a computer based option setup in your NAM profile?  For example, I usually would set it up for Computer certificates or User certificates.   When the user logs off there should be a fresh authentication with the computer cert.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 24 Aug 2018 13:40:33 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-08-24T13:40:33Z</dc:date>
    <item>
      <title>Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694391#M495017</link>
      <description>&lt;P&gt;Hello Friends!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We implemented dot1x in our test environment with Anyconnect NAM 4.6 as a supplicant.&lt;/P&gt;
&lt;P&gt;But I don`t understand why NAM doesn`t send&amp;nbsp;EAPoL logoff messages when the user logging off the system.&lt;/P&gt;
&lt;P&gt;NAM just doing nothing. And technically machine staying with previous authorization profile until someone loging in(in this moment NAM initiate new EAP session)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there some configuration regard this feature that I need to enble for&amp;nbsp;EAPoL logoff?&lt;/P&gt;
&lt;P&gt;Does&amp;nbsp;&lt;SPAN&gt;EAPoL logoff not&lt;/SPAN&gt; requred anymore?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 10:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694391#M495017</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-24T10:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694406#M495018</link>
      <description>Probably one for TAC?..</description>
      <pubDate>Fri, 24 Aug 2018 11:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694406#M495018</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-08-24T11:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694437#M495019</link>
      <description>&lt;P&gt;Are you sure you don't have the "Extend User connection beyond log off" option checked under User Auth in your NAM profile?&amp;nbsp; If you do then what you are seeing is the expected behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 11:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694437#M495019</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-24T11:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694554#M495020</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yep, I`ve already uncheked this option in profile..&lt;/P&gt;
&lt;P&gt;I tryed to reinstall nam, clear register etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason it doesn`t work, anyconnect or PC doesn`t send eap logoff to switch((&lt;/P&gt;
&lt;P&gt;But it nessesary for me, I need to refresh&amp;nbsp; User-Role in switch cache..(it refreshes when eap logoff comes up)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My test PC on win7x64, maybe there is some bug..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694554#M495020</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-24T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694566#M495021</link>
      <description>Do you have a computer based option setup in your NAM profile?  For example, I usually would set it up for Computer certificates or User certificates.   When the user logs off there should be a fresh authentication with the computer cert.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694566#M495021</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-24T13:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694609#M495022</link>
      <description>&lt;P&gt;Thanks Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I`m really missed machine auth parameters(no cert or static pass), I just put dummy password for static machine auth.&lt;/P&gt;
&lt;P&gt;So it helped in some way) When user is doing logoff anyconnect is starting machine authentication(with dummy password).&lt;/P&gt;
&lt;P&gt;But it`s still not sending eapol logoff message at this moment. In switch access-session cache doesn`t refresh((&lt;/P&gt;
&lt;P&gt;Maybe eapol logoff it`s some kind of deprecated feature on anyconnect and we need to utilize machine auth only..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now it works like workaround, I can now send new User-role in authz profile when PC initiate machine authentication after user logoff.&lt;/P&gt;
&lt;P&gt;But It would be great if there will be no need to invoke ISE to just refresh cached attributes under acces-session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 14:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694609#M495022</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-24T14:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect NAM EAPoL logoff messages</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694681#M495023</link>
      <description>&lt;P&gt;So, I was doing some testing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found that anyconnect sends EAPoL Logoff when we use only User authentication without Machine in nam-profile.&lt;/P&gt;
&lt;P&gt;In fact it use eapol logoff when there is no methods left to authenticate endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But accordingly to guide Deploying ISE for Wired Network Access switch needs to get eapol-logoff for access-session cache clearing.(or reboot :))&lt;/P&gt;
&lt;P&gt;In guide we can see&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Role Based Critical Authorization&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;One of the many advantages of using IBNS 2.0 is that it can handle failure scenarios efficiently. With a few additional tweaks to&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;the previously configured IBNS 2.0 configuration, endpoints that have been authorized previously by ISE can be given the same&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;level of network access even when the server is not reachable next time. The idea is to grant role-based access during critical&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;condition, instead of applying a common critical authorization.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;NOTE !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#993366"&gt;&lt;EM&gt;&lt;STRONG&gt;The access-session cache is cleared either when switch reloads or the endpoint does EAPOL-Logoff.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;EM&gt;&lt;STRONG&gt;EAPOL-Logoff typically happens in most of the operating systems when user logs off the&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#993366"&gt;&lt;EM&gt;&lt;STRONG&gt;system.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ROLE_BASED_CRITICAL_AUTH.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/17453iE3173BBF1C368970/image-size/large?v=v2&amp;amp;px=999" role="button" title="ROLE_BASED_CRITICAL_AUTH.JPG" alt="ROLE_BASED_CRITICAL_AUTH.JPG" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I found another problem))&lt;/P&gt;
&lt;P&gt;Looks like there is some bug on 16.9.1 version, even if supplicant sends EAPoL-logoff the switch doesn`t refresh access-session cache and RoleBased critical auth can be security vulnerability.&lt;/P&gt;
&lt;P&gt;But it for TAC I think))&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 16:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-eapol-logoff-messages/m-p/3694681#M495023</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-24T16:22:58Z</dc:date>
    </item>
  </channel>
</rss>

