<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE shows auth passed but switch unauth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704017#M507721</link>
    <description>&lt;P&gt;The auth profile is simly set to permit access. The auth policy currently looks like that:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18417i5C70C068773E79F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under condition we're using predefined set of Wired_802.1X, source sequence contains AD lookup + internal identity store. Allowed protocols contain several like EAP-TLS and PEAP MSCHAPv2 but also EAP-FAST (with inner MSCHAPv2, EAP-GTC and EAP-TLS). Use PACs is enabled with anonymous and authenticated in-band PAC provisioning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the hit counter you can see it is/was working several times but not for the specific AP mentioned in the earlier attached debug info. Several others are not working either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 13:52:06 GMT</pubDate>
    <dc:creator>jayage</dc:creator>
    <dc:date>2018-09-10T13:52:06Z</dc:date>
    <item>
      <title>ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3703903#M507717</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we got a strange situation where ISE shows Accesspoints (2702 / PAC provisioned) as authenticated but the switch (mainly cat3650 / 16.3.6) does not. We do have the same issue on different switches, also on 9300 with 16.6.3. I compared switch dot1x session ID with audit session ID in ISE, excactly the same. Might we hit a bug or is there something other wrong? We're using ISE internal user for the AP supplicant. APs are controller based, controller version is 8.3.140.0. When we close the port, no traffic flows. I attached show sess int gx/x/x + ISE auth details for reference. Can someone please advice?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3703903#M507717</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-10T11:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3703921#M507719</link>
      <description>&lt;P&gt;Can you please share what your Authorization profile looks like?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 12:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3703921#M507719</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2018-09-10T12:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704017#M507721</link>
      <description>&lt;P&gt;The auth profile is simly set to permit access. The auth policy currently looks like that:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18417i5C70C068773E79F3/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under condition we're using predefined set of Wired_802.1X, source sequence contains AD lookup + internal identity store. Allowed protocols contain several like EAP-TLS and PEAP MSCHAPv2 but also EAP-FAST (with inner MSCHAPv2, EAP-GTC and EAP-TLS). Use PACs is enabled with anonymous and authenticated in-band PAC provisioning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the hit counter you can see it is/was working several times but not for the specific AP mentioned in the earlier attached debug info. Several others are not working either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 13:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704017#M507721</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-10T13:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704021#M507722</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is the Authentication profile. I am interested in what your Authorization profile (Result) looks like.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 13:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704021#M507722</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2018-09-10T13:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704027#M507723</link>
      <description>&lt;P&gt;The result is the standard permit access.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:01:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704027#M507723</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-10T14:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704030#M507724</link>
      <description>&lt;P&gt;Do you have a Pre-auth ACL on the switch ports? Or is this only in monitor mode?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704030#M507724</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2018-09-10T14:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704043#M507725</link>
      <description>&lt;P&gt;PAC provisioned is not authentication.&amp;nbsp; When you are using EAP-FAST the client will first connect to ISE to do PAC provisioning then it will authenticate.&amp;nbsp; So the AP is only doing the first part.&amp;nbsp; &amp;nbsp;You should see a Dot1x authentication attempt closely following the PAC provisioning.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704043#M507725</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T14:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704050#M507726</link>
      <description>&lt;P&gt;Also if the step data you posted is from the actual authentication and not the PAC provisioning log entry it looks like you are passing authentication but failing authorization.&amp;nbsp; I see an authentication succeeded, but the selected authorization profile is blank.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;22037 Authentication Passed&lt;/P&gt;
&lt;P&gt;15036 Evaluating Authorization Policy&lt;/P&gt;
&lt;P&gt;15016 Selected Authorization Profile -&lt;/P&gt;
&lt;P&gt;11401 Prepared RADIUS Access-Reject after the successful in-band PAC provisioning&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704050#M507726</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T14:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704127#M507727</link>
      <description>&lt;P&gt;Don't know if pre-auth ACL are set, I only know pre-auth ACLs for web authentictaion at our guest wifi. Is there maybe the supplicant wrong on these APs?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 15:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704127#M507727</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-10T15:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704128#M507728</link>
      <description>&lt;P&gt;I just restarted one AP to watch the behavoir. PAC suceeded but no authentication session followed.&lt;/P&gt;
&lt;P&gt;Is it normal that it got rejected at the end of the PAC prov:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="content_table_steps" style="width: 500px;" cellpadding="3" border="0"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;11018&lt;/TD&gt;
&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;12104&lt;/TD&gt;
&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;11401&lt;/TD&gt;
&lt;TD&gt;Prepared RADIUS Access-Reject after the successful in-band PAC provisioning&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;61025&lt;/TD&gt;
&lt;TD&gt;Open secure connection with TLS peer&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;11504&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Failure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;11003&lt;/TD&gt;
&lt;TD&gt;Returned RADIUS Access-Reject&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Honestly I don't know how to proceed.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 15:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704128#M507728</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-10T15:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704598#M507729</link>
      <description>&lt;P&gt;New finding, I recognized that only access points with trunk ports and wlan-vlan mapping are not working properly but only on IOS XE. Got some ISE 3750v2 with IOS 15.0.2SEx, using same static trunk port config for APs where authentication works as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Port config looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;switchport trunk native vlan 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;switchport trunk allowed vlan 2,100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;switchport mode trunk&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;device-tracking&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;authentication host-mode multi-host&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;authentication open&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;authentication port-control auto&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;dot1x pae authenticator&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;spanning-tree portfast trunk&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Auth open ofc as it is not working atm. VLAN 2 is the standard 'client' VLAN used for the internal ssid while 100 is for voice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any clue?&amp;nbsp; While researching I stumbled over the following article:&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Do I have to go for NEAT? Or can we get it working with static port config?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704598#M507729</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2018-09-11T08:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704644#M507731</link>
      <description>You shouldn’t be doing authentication on trunk ports.  If your APs are FlexConnect the shouldn’t have ISE on the ports.  If the are local mode APs the shouldn’t be trunks.  If you are worried about someone unplugging the AP and plugging in when the port is trunked, you can use Autosmart port macro applied by ISE to reconfigure the port.&lt;BR /&gt;&lt;BR /&gt;So the port would be standard access port with  authentication on it.  When AP plugs in ISE would invoke macro to reconfigure port to a trunk and remove authentication.  If AP is unplugged it goes back to access port with Auth enabled.&lt;BR /&gt;&lt;BR /&gt;Search forums for smart port.  I and others have posted on it.&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Sep 2018 09:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/3704644#M507731</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-11T09:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE shows auth passed but switch unauth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/5255226#M594691</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Did you ever get to the bottom of this one, please? I too have an issue where some MAB devices are showing as authenticated in the ISE RADIUS Live Logs but showing as un-auth on the switch.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 09:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-shows-auth-passed-but-switch-unauth/m-p/5255226#M594691</guid>
      <dc:creator>tom-ingram</dc:creator>
      <dc:date>2025-01-31T09:53:49Z</dc:date>
    </item>
  </channel>
</rss>

