<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re-authentication force dot1X in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710294#M507476</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a switch port configured to authenticate with order first MAB and then dot1X. The priority has been setup in the opposite way, first dot1X then MAB. I would like to re-authenticate devices (phones in this case) but it seems when I run "clear dot1x int ..." or "clear authentication sessions int ..." the switch is not sending the EAP-Request/Identity and MAB occurs after running them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any command to force the switch to use dot1X send the&amp;nbsp;&lt;SPAN&gt;EAP-Request/Identity to the endpoint? Unfortunately, I cannot change the switch port configuration and shut/no shut is not allowed either.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Víctor.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Sep 2018 09:31:07 GMT</pubDate>
    <dc:creator>victguti</dc:creator>
    <dc:date>2018-09-20T09:31:07Z</dc:date>
    <item>
      <title>Re-authentication force dot1X</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710294#M507476</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a switch port configured to authenticate with order first MAB and then dot1X. The priority has been setup in the opposite way, first dot1X then MAB. I would like to re-authenticate devices (phones in this case) but it seems when I run "clear dot1x int ..." or "clear authentication sessions int ..." the switch is not sending the EAP-Request/Identity and MAB occurs after running them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any command to force the switch to use dot1X send the&amp;nbsp;&lt;SPAN&gt;EAP-Request/Identity to the endpoint? Unfortunately, I cannot change the switch port configuration and shut/no shut is not allowed either.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Víctor.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 09:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710294#M507476</guid>
      <dc:creator>victguti</dc:creator>
      <dc:date>2018-09-20T09:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re-authentication force dot1X</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710397#M507478</link>
      <description>&lt;P&gt;I believe that is the downside of doing mab first, which is something I never do.&amp;nbsp; When you do MAB first you are forcing the connecting device to initiate Dot1x which some devices like Macs are only responders.&amp;nbsp; In addition, as you are seeing you may have issues during reauthentication.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 12:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710397#M507478</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-20T12:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Re-authentication force dot1X</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710674#M507483</link>
      <description>&lt;P&gt;You can force reauthentcation using 802.1X by adding Cisco VSA:termination-action-modifier=1 to the authorization profile along with the reauthentication parameters even when the ordering dictates MAB first. Please see '802.1X and MAB ordering section' of the following document for more information:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/top-ten-mis-configured-cisco-ios-switch-settings-for-ise/ta-p/3643912#toc-hId--1759816418" target="_blank"&gt;https://community.cisco.com/t5/security-documents/top-ten-mis-configured-cisco-ios-switch-settings-for-ise/ta-p/3643912#toc-hId--1759816418&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="115156_Screen Shot 2018-02-11 at 8.43.48 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19009i733666665DB80D3E/image-size/large?v=v2&amp;amp;px=999" role="button" title="115156_Screen Shot 2018-02-11 at 8.43.48 AM.png" alt="115156_Screen Shot 2018-02-11 at 8.43.48 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 19:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authentication-force-dot1x/m-p/3710674#M507483</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-09-20T19:20:03Z</dc:date>
    </item>
  </channel>
</rss>

