<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLIENT AUTHENTICATION FAILURE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819501#M541670</link>
    <description>&lt;P&gt;In your snapshot you will see the column "details"&lt;/P&gt;
&lt;P&gt;Please click on that and provide a screen shot of those lots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As well please provide your Authentication policy you have setup.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 12:35:46 GMT</pubDate>
    <dc:creator>ldanny</dc:creator>
    <dc:date>2019-03-14T12:35:46Z</dc:date>
    <item>
      <title>CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819367#M541665</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have setup ise on vmware and using a real switch for authentication configurations and a test pc. Network device is setup in ise together with mac-address of client however there is authentication failure! i have disabled windows firewall on host and test pc but no success. Kindly advise how i can sort this. Please find the switch configs attached!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 09:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819367#M541665</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-14T09:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819439#M541666</link>
      <description>Can you provide us with the ISE authentication details log. ISE often gives a pretty direct reason for an authentication failure, or we can at least infer quite a bit from it.</description>
      <pubDate>Thu, 14 Mar 2019 11:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819439#M541666</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-03-14T11:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819446#M541667</link>
      <description>&lt;P&gt;In addition to other post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to check radius connectivity on ports 1812 and 1813 udp.&lt;/P&gt;
&lt;P&gt;If you type &lt;STRONG&gt;show aaa serve&lt;/STRONG&gt;r in the switch you will see the radius status dead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you also Enable debug : ( to see what is wrong) , since if the packet not reached to ISE, ISE would not have any logs in this case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;debug radius&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;debug authentication all&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;debug authentication feature all&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 11:17:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819446#M541667</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-03-14T11:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819489#M541668</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Firstly,thanks for the prompt response. I have captured logs from switch(please find attached). Kindly, clarify which device i am checking for ports 1812/1813 and if its switch how will i check this. I have check form ISE GUI ,operations&amp;gt;live authentication(is this the correct place?), there is much there just old authentication failure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to clarify f0/1 is connected to my laptop where ise is running, f0/3 is connected to test pc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i come across this lines in the logs,does it mean dot1x is not enabled on test pc?&lt;/P&gt;
&lt;P&gt;Jan 2 04:47:38.428: AUTH-FEAT-CRITICAL-EVENT (Fa0/3) Critcal authc fail, mac a0d3.c19c.5956, auth_event 2&lt;BR /&gt;*Jan 2 04:47:38.428: AUTH-FEAT-CRITICAL-EVENT (Fa0/3) Critical auth not applicable. Feature is not enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks once more!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819489#M541668</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-14T12:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819493#M541669</link>
      <description>&lt;P&gt;Hi Damien,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the quick response! from ISE side i didn't see much in the operations&amp;gt;live authentication section just old authentication failures. I hope am checking the right place. Here is snapshot attached.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:31:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819493#M541669</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-14T12:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819501#M541670</link>
      <description>&lt;P&gt;In your snapshot you will see the column "details"&lt;/P&gt;
&lt;P&gt;Please click on that and provide a screen shot of those lots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As well please provide your Authentication policy you have setup.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819501#M541670</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-03-14T12:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819522#M541671</link>
      <description>&lt;P&gt;Hi Idanny,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response. I have taken snapshots of the detail column. Its a fresh installation and am just beginning to use ise so i didn't set any authentication policy on ise.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snapshot-section1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31919iC733DC7C9176B2F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="snapshot-section1.PNG" alt="snapshot-section1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snapshot-section2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31922i6DB2017479D5C5E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="snapshot-section2.PNG" alt="snapshot-section2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snapshot-section3.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31920i74A7AFF75FF4A504/image-size/large?v=v2&amp;amp;px=999" role="button" title="snapshot-section3.PNG" alt="snapshot-section3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snapshot-section4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31921i4BA6FF632A3F113A/image-size/large?v=v2&amp;amp;px=999" role="button" title="snapshot-section4.PNG" alt="snapshot-section4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819522#M541671</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-14T12:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819530#M541672</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;An update on authentication policy.See attached!&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 13:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3819530#M541672</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-14T13:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: CLIENT AUTHENTICATION FAILURE</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3820230#M541673</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find more debugs from todays tshooting. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SW1#&lt;BR /&gt;*Jan 2 03:03:18.387: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;*Jan 2 03:03:18.387: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;*Jan 2 03:03:18.387: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;*Jan 2 03:03:18.387: %AUTHMGR-7-NOM&lt;BR /&gt;SW1#OREMETHODS: Exhausted all authentication methods for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;*Jan 2 03:03:18.387: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:04:06.999: %AUTHMGR-5-START: Starting 'dot1x' for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#test aaa group radisu&amp;#8; &amp;#8;&amp;#8; &amp;#8;us j&amp;#8; &amp;#8;Joseph @i&amp;#8; &amp;#8;&amp;#8; &amp;#8;Winter2019 ke&amp;#8; &amp;#8;&amp;#8; &amp;#8;legacy&lt;BR /&gt;Attempting authentication test to server-group radius using radius&lt;BR /&gt;User was successfully authenticated.&lt;/P&gt;
&lt;P&gt;SW1#&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: Pick NAS IP for u=0x593D66C tableid=0 cfg_addr=0.0.0.0&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS(00000000): Config NAS IPv6: ::&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: ustruct sharecount=1&lt;BR /&gt;*Jan 2 03:04:50.905: Radius: radius_port_info() success=0 radius_nas_port=1&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS/ENCODE: Best Local IP-Address 192.168.159.2 for Radius-Server 192.168.159.145&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS(00000000): Send Access-Requ&lt;BR /&gt;SW1#est to 192.168.159.145:1645 id 1645/6, len 58&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: authenticator FD 02 72 DE 6F 30 CD 7A - C1 2C 09 6A B0 2D 02 9E&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: NAS-IP-Address [4] 6 192.168.159.2 &lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: NAS-Port-Type [61] 6 Async [0]&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: User-Name [1] 8 "Joseph"&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS: User-Password [2] 18 *&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS(00000000): Sending a IP&lt;BR /&gt;SW1#v4 Radius Packet&lt;BR /&gt;*Jan 2 03:04:50.905: RADIUS(00000000): Started 5 sec timeout&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: Received from id 1645/6 192.168.159.145:1645, Access-Accept, len 122&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: authenticator F1 D9 34 78 8E DE 1A 14 - 96 23 04 67 EA 4A D3 8A&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: User-Name [1] 8 "Joseph"&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: State [24] 40 &lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 52 65 61 75 74 68 53 65 73 73 69 6F 6E 3A 63 30 [ReauthSession:c0] SW1#&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 61 38 39 66 39 31 30 30 30 30 30 30 30 35 35 43 [a89f91000000055C]&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 38 42 42 37 46 32 [ 8BB7F2]&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: Class [25] 48 &lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 43 41 43 53 3A 63 30 61 38 39 66 39 31 30 30 30 [CACS:c0a89f91000]&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 30 30 30 30 35 35 43 38 42 42 37 46 32 3A 49 53 [000055C8BB7F2:IS]&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: 45 31 2F 33 34 32 30 30 33 38 35 33 2F &lt;BR /&gt;SW1#36 [ E1/342003853/6]&lt;BR /&gt;*Jan 2 03:04:50.972: RADIUS: Termination-Action [29] 6 1 &lt;BR /&gt;*Jan 2 03:04:50.980: RADIUS: saved authorization data for user 593D66C at 593AC94&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:05:32.429: %DOT1X-5-FAIL: Authentication failed for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;*Jan 2 03:05:32.429: %AUTHMGR-7-RESULT: Authentication result 'fail' from 'dot1x' for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:05:32.429: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:08:05.068: %DOT1X-5-FAIL: Authentication failed for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:08:05.068: %AUTHMGR-7-RESULT: Authentication result 'timeout' from 'dot1x' for client (0022.64b3.0b38) on Interface Fa0/3 AuditSessionID C0A80A010000002700A1FF8A&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:09:38.005: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:09:38.005: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:09:38.005: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:09:38.005: %AUTHMGR-7-NOM&lt;BR /&gt;SW1#OREMETHODS: Exhausted all authentication methods for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:09:38.005: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:12:10.661: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:12:10.661: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:12:10.661: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:12:10.661: %AUTHMGR-7-NOM&lt;BR /&gt;SW1#OREMETHODS: Exhausted all authentication methods for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:12:10.661: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;SW1#&lt;BR /&gt;*Jan 2 03:14:43.988: %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:14:43.988: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:14:43.988: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Fa0/3 AuditSessionID C0A80A010000002800AC74FB&lt;BR /&gt;*Jan 2 03:14:43.988: %AUTHMGR-7-NOM&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 14:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-failure/m-p/3820230#M541673</guid>
      <dc:creator>isaaco001</dc:creator>
      <dc:date>2019-03-15T14:57:21Z</dc:date>
    </item>
  </channel>
</rss>

