<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;no sessions match supplied criteria&amp;quot; on a dot1x enabled interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497893#M539149</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suggest downgrading the IOS on the switch. Current recommended version for Cat 4500 Sup8 is 3.6.3 per &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html"&gt;Cisco Identity Services Engine Network Component Compatibility, Release 2.0 - Cisco&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Apr 2016 04:32:19 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2016-04-20T04:32:19Z</dc:date>
    <item>
      <title>"no sessions match supplied criteria" on a dot1x enabled interface</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497892#M539147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are seeing some strange &lt;SPAN data-dobid="hdw"&gt;behaviour on Catalyst 4K SUP 8 running 03.06.04.E &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1. One configuring the below interface commands the machine is denied access as "no sessions match supplied criteria" message is displayed by issuing "show authentication session interface gi4/15 de" command.&lt;/P&gt;&lt;P&gt;2. The ISE logs show that the machine is trying to authenticate via MAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By removing dot1x configuration everything is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;interface GigabitEthernet4/15&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; switchport access vlan 912&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; switchport mode access&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; switchport voice vlan 942&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; ip access-group Dot1x_Preauth_Restricted_IN in&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; logging event link-status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication event fail action next-method&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication host-mode multi-auth&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication open&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication order dot1x mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication priority dot1x mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication port-control auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; authentication violation replace&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; no snmp trap link-status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; dot1x timeout tx-period 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; dot1x max-reauth-req 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; storm-control broadcast include multicast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; storm-control broadcast level 0.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; spanning-tree portfast&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt; spanning-tree bpduguard enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri,verdana,arial,sans-serif;"&gt;end&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The endpoint is correctly configured with dot1x. After stopping wired autoconfig&amp;nbsp; "no sessions match supplied criteria" is displayed again even though we should be expecting MAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be an issue with a particular machine as other machines are able to authenticate from the same port.&lt;/P&gt;&lt;P&gt;However shouldn't the switch still be able authenticate the machine via MAB if for some reason the supplicant is corrupted ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if anyone has encountered the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Utkarsh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2016 12:54:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497892#M539147</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-04-18T12:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: "no sessions match supplied criteria" on a dot1x enabled interface</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497893#M539149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suggest downgrading the IOS on the switch. Current recommended version for Cat 4500 Sup8 is 3.6.3 per &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/compatibility/ise_sdt.html"&gt;Cisco Identity Services Engine Network Component Compatibility, Release 2.0 - Cisco&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2016 04:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497893#M539149</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-04-20T04:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: "no sessions match supplied criteria" on a dot1x enabled interface</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497894#M539151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue was solved by Windows team by applying Windows patches. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 May 2016 06:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497894#M539151</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2016-05-12T06:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: "no sessions match supplied criteria" on a dot1x enabled interface</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497895#M539152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which windows OS was this? I might be having the same problem with windows 10 on Wired Dot1x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 16:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-no-sessions-match-supplied-criteria-quot-on-a-dot1x-enabled/m-p/3497895#M539152</guid>
      <dc:creator>kngitonga</dc:creator>
      <dc:date>2018-05-30T16:45:17Z</dc:date>
    </item>
  </channel>
</rss>

