<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Rejected with OpenOTP Token Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435783#M536648</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a standalone ISE, try restarting ISE services. If a secondary ISE nodes, try a manual re-sync.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Dec 2016 19:33:36 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2016-12-28T19:33:36Z</dc:date>
    <item>
      <title>Authentication Rejected with OpenOTP Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435780#M536644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Configured ASA VPN access with OpenOTP as the token server.&amp;nbsp; Running an authentication test and getting Deny Access result.&amp;nbsp; Reason is defined as "Rejected per authorization profile"&amp;nbsp; Per OTP logs and ISE authentication,&amp;nbsp; user authentication is successful.&amp;nbsp; Using Policy Sets. Authorization policy has no Deny Access statement in it.&amp;nbsp; First rule is a Permit access with no conditions.&amp;nbsp; The default rule is Permit access.&amp;nbsp; Appears to be failing before hitting the authorization table even though authentication succeeds.&amp;nbsp; ISE 2.1 patch 2. &lt;IMG alt="Screen Shot 2016-12-26 at 10.20.03 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/103432_Screen Shot 2016-12-26 at 10.20.03 AM.png" style="height: 388px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2016-12-26 at 10.24.19 AM.png" class="jive-image image-2" src="/legacyfs/online/fusion/103442_Screen Shot 2016-12-26 at 10.24.19 AM.png" style="height: 388px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Dec 2016 16:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435780#M536644</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-12-26T16:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Rejected with OpenOTP Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435781#M536646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the live log details?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2016 06:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435781#M536646</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2016-12-27T06:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Rejected with OpenOTP Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435782#M536647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Authc Failure Entire Page.png" class="image-1 jive-image" src="/legacyfs/online/fusion/103443_Authc Failure Entire Page.png" style="height: 972px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2016 14:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435782#M536647</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2016-12-27T14:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Rejected with OpenOTP Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435783#M536648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a standalone ISE, try restarting ISE services. If a secondary ISE nodes, try a manual re-sync.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Dec 2016 19:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435783#M536648</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-12-28T19:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Rejected with OpenOTP Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435784#M536649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The deployment is two nodes.&amp;nbsp; I've gone ahead and resynced and restarted.&amp;nbsp; Still same result.&amp;nbsp; Session is coming up as Denied even though I have everything set to permit.&amp;nbsp;&amp;nbsp; Happening on both nodes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2017 14:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-rejected-with-openotp-token-server/m-p/3435784#M536649</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2017-01-03T14:35:35Z</dc:date>
    </item>
  </channel>
</rss>

