<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is the device updated with in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734285#M54114</link>
    <description>&lt;P&gt;Is the device updated with the correct ip in ISE Network Devices?&lt;/P&gt;&lt;P&gt;its able to talk with ISE if you try "test aaa group radius ..."&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2015 17:17:33 GMT</pubDate>
    <dc:creator>Tobias Svensson</dc:creator>
    <dc:date>2015-09-08T17:17:33Z</dc:date>
    <item>
      <title>ISE blocking PC's after switch native vlan change</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734284#M54113</link>
      <description>&lt;P&gt;So i encountered a strange problem the other day after changing the Native/Mgt vlan on a switch. It was set to 1 and i changed it to 10. after that none of the PC's could get DHCP addresses. restarted the router and switch and pc's to no avial. they would get the windows pipa address 169.254.x.x. as soon as i did a auth open, they got ip's before i could even say "how about now" and all are working just fine. I need to know what caused this blockage before i start down the road of doing the other 170 networks that need to be done.&lt;/P&gt;&lt;P&gt;my steps were:&lt;/P&gt;&lt;P&gt;create new vlan on switch with ip, ssh into new vlan IP, change original mgt vlan, set native command on trunk ports and PC ports, change encap dot1q on router subint for new vlan. rebooted router and switch, and PC's. Had to "auth open" ports do PC's could get DHCP, then everything was fine. No auth open to return to normal and all is well.&lt;/P&gt;&lt;P&gt;ISE version 1.1.0876 patch 4&lt;/P&gt;&lt;P&gt;distributed deployment&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734284#M54113</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2019-03-11T06:02:14Z</dc:date>
    </item>
    <item>
      <title>Is the device updated with</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734285#M54114</link>
      <description>&lt;P&gt;Is the device updated with the correct ip in ISE Network Devices?&lt;/P&gt;&lt;P&gt;its able to talk with ISE if you try "test aaa group radius ..."&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 17:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734285#M54114</guid>
      <dc:creator>Tobias Svensson</dc:creator>
      <dc:date>2015-09-08T17:17:33Z</dc:date>
    </item>
    <item>
      <title>yes i added the new IP to</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734286#M54115</link>
      <description>&lt;P&gt;yes i added the new IP to Network devices.&lt;/P&gt;&lt;P&gt;that i don't know because i am investigating this after it happened.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 17:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734286#M54115</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-08T17:29:41Z</dc:date>
    </item>
    <item>
      <title>Ok, make sure its talking</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734287#M54116</link>
      <description>&lt;P&gt;Ok, make sure its talking with the right interface via "ip radius source-interface" on the switch/routers.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 17:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734287#M54116</guid>
      <dc:creator>Tobias Svensson</dc:creator>
      <dc:date>2015-09-08T17:33:37Z</dc:date>
    </item>
    <item>
      <title>just to clarify, the switch</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734288#M54117</link>
      <description>&lt;P&gt;just to clarify, the switch and router were already in ISE and everything worked fine. we were just getting the mgt vlan off 1.&lt;/P&gt;&lt;P&gt;here is the port config on the switch before the change&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 25&lt;BR /&gt;&amp;nbsp;authentication event fail action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;&lt;P&gt;int g0/3&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;spanning-tree portfast trunk&lt;/P&gt;&lt;P&gt;router :&lt;/P&gt;&lt;P&gt;int g0/0.20&lt;/P&gt;&lt;P&gt;encap dot1q 1 native&lt;/P&gt;&lt;P&gt;and after the change:&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport access vlan 20&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 25&lt;BR /&gt;&amp;nbsp;authentication event fail action authorize vlan 20&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 20&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;int g0/3&lt;/P&gt;&lt;P&gt;switchport trunk native vlan 20&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;spanning-tree portfast trunk&lt;/P&gt;&lt;P&gt;router&lt;/P&gt;&lt;P&gt;int g0/0.20&lt;/P&gt;&lt;P&gt;encap dot1q 20 native&lt;/P&gt;&lt;P&gt;after making and writing the changes i rebooted both devices and the PC's&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 18:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734288#M54117</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-08T18:58:04Z</dc:date>
    </item>
    <item>
      <title>any help is appreciated.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734289#M54118</link>
      <description>&lt;P&gt;any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 21:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734289#M54118</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-09T21:13:30Z</dc:date>
    </item>
    <item>
      <title>What is the status of "show</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734290#M54119</link>
      <description>&lt;P&gt;What is the status of "show auth sess interface x/x", when the pc is trying to get an ip address ? Try running it with a few secs interval after you plug the pc in.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2015 23:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734290#M54119</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-09-09T23:13:54Z</dc:date>
    </item>
    <item>
      <title>it would say running or</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734291#M54121</link>
      <description>&lt;P&gt;it would say running or failed&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 15:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734291#M54121</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-11T15:25:01Z</dc:date>
    </item>
    <item>
      <title>where is your dhcp server, is</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734292#M54122</link>
      <description>&lt;P&gt;where is your dhcp server, is it your router? or is it another device on your network? if yes, just make sure your new vlan is exist all along the path between your switch and your dhcp server.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 00:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734292#M54122</guid>
      <dc:creator>adam kalabadzi</dc:creator>
      <dc:date>2015-09-14T00:02:57Z</dc:date>
    </item>
    <item>
      <title>i dont think you read the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734293#M54124</link>
      <description>&lt;P&gt;i dont think you read the entire post. how would an auth open fix that?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 13:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734293#M54124</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-14T13:25:11Z</dc:date>
    </item>
    <item>
      <title>Could you post the complete</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734294#M54126</link>
      <description>&lt;P&gt;Could you post the complete config (without passwords of course) ?&lt;/P&gt;&lt;P&gt;Also, are you running dhcp snooping and ip device tracking ?&lt;/P&gt;&lt;P&gt;When your PC's don't get a dhcp address, do they actually do a successfull dot1x authentication? Are you assigning the new vlan id in your authorization result ?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 13:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734294#M54126</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-09-14T13:37:08Z</dc:date>
    </item>
    <item>
      <title>from what i remember, yes,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734295#M54129</link>
      <description>&lt;P&gt;from what i remember, yes, some did get successful dot1x on the switch. We are assigning a new vlan to that port as well.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 13:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734295#M54129</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-14T13:54:07Z</dc:date>
    </item>
    <item>
      <title>anything else you can think</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734296#M54130</link>
      <description>&lt;P&gt;anything else you can think of?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 18:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-blocking-pc-s-after-switch-native-vlan-change/m-p/2734296#M54130</guid>
      <dc:creator>preston trogden</dc:creator>
      <dc:date>2015-09-18T18:48:30Z</dc:date>
    </item>
  </channel>
</rss>

