<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Authentication bypass in critical situation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530659#M518332</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can disable posture policies on ISE in such cases, also change the authorization policies to permit network access irrespective of the posture status. Modifying the switch configuration is not necessary, as long it can talk to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a TAC case open to understand why the NAC agent failed to do posture?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jan 2018 18:09:14 GMT</pubDate>
    <dc:creator>hariholla</dc:creator>
    <dc:date>2018-01-25T18:09:14Z</dc:date>
    <item>
      <title>ISE Authentication bypass in critical situation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530658#M518331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;My self Ram Mohan from INDIA. I am using Cisco ISE in our organization. I faced one issue recent days which is created a big problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;&lt;EM style="color: #000000; text-decoration: underline;"&gt;Incident ;-&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;3 days back all the end-users login into the system, after login NAC agent not initiated to check the posture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;This issue effected in entire organization. so that they can't able to access intranet as well as internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;For temporarily...i just removed NAC configuration on switch-port and allowed the network access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;in that situation i struggled a lot to remove NAC configuration in entire access switches (52 Switches) which is located in all floors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;My query ... is there any option or specific configuration to bypass the ISE system in above critical situation ??&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Please let me know if there is any chance to overcome this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;&lt;EM style="text-decoration: underline;"&gt;&lt;SPAN style="color: #000000; text-decoration: underline;"&gt;Version Details:-&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.2.0.470&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;NAC Agent Ver&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.9.5.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;ADE OS Ver&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.0.2.218&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG style="font-size: 12pt;"&gt;&lt;EM&gt;Thanks ,&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12pt;"&gt;&lt;EM&gt;Rama Mohan Rao P&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2018 07:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530658#M518331</guid>
      <dc:creator>pasupuleti.rmr</dc:creator>
      <dc:date>2018-01-25T07:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication bypass in critical situation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530659#M518332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can disable posture policies on ISE in such cases, also change the authorization policies to permit network access irrespective of the posture status. Modifying the switch configuration is not necessary, as long it can talk to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a TAC case open to understand why the NAC agent failed to do posture?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530659#M518332</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2018-01-25T18:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication bypass in critical situation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530660#M518333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps, this is what you are looking for -- &lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-2_2_e/security/configuration_guide/b_sec_1522e_2960x_cg/b_sec_1522e_2960x_cg_chapter_010000.html#ID778"&gt;802.1x Authentication with Inaccessible Authentication Bypass&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Jan 2018 05:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530660#M518333</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-27T05:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication bypass in critical situation</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530661#M518334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mr.Hari,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;actually I just disabled the posture policies on ISE when the incident happened. But before that all the systems hang on and showing exclamation mark (Yellow colour triangle) on LAN Icon. I just capture the Posture Policy for your reference.&lt;/P&gt;&lt;P&gt;lease check and let me know is any further step I have to take.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2018-01-29_114925.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114873_2018-01-29_114925.jpg" style="width: 620px; height: 113px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reg TAC Case :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TAC engineer suggested to upgrade Patch 5 and done the same.&lt;/P&gt;&lt;P&gt;I just discussed with TAC Engineer and sent &lt;STRONG&gt;ise-support-bundle logs&lt;/STRONG&gt; before and after the issue was raised.&lt;/P&gt;&lt;P&gt;waiting for his response to know exact cause of the problem.&lt;/P&gt;&lt;P&gt;wander is before patch 5 up gradation it self, problem has resolved.&lt;/P&gt;&lt;P&gt;only that day getting issue with NAC agent. next day I just tried in test systems its running well..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 06:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-bypass-in-critical-situation/m-p/3530661#M518334</guid>
      <dc:creator>pasupuleti.rmr</dc:creator>
      <dc:date>2018-01-29T06:45:24Z</dc:date>
    </item>
  </channel>
</rss>

