<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3840759#M543423</link>
    <description>&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;hopefully u've already resolved the problem. If u didnt just&amp;nbsp;dont change host-mode within dynamic server template. Just stay with single host-mode multi-auth.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2019 02:04:03 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2019-04-18T02:04:03Z</dc:date>
    <item>
      <title>IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3779354#M543422</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm attemping to automatically configure an interface using a template. The template is already on the switch, ISE is pushing the template name with the Authz. Standard IBNS 2.0 stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config here:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;template APAutoConfig&lt;BR /&gt;switchport trunk native vlan 120&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;access-session host-mode multi-host&lt;/P&gt;&lt;P&gt;access-session interface-template sticky timer 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template Dot1x-Port&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;switchport access vlan 120&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 170&lt;BR /&gt;mab&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;service-policy type control subscriber DOT1X_AND_MAB&lt;BR /&gt;description - Dot1x -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/22&lt;BR /&gt;no logging event link-status&lt;BR /&gt;access-session closed&lt;BR /&gt;no snmp trap link-status&lt;BR /&gt;snmp ifindex persist&lt;BR /&gt;source template Dot1x-Port&lt;BR /&gt;spanning-tree portfast edge&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I'm&amp;nbsp;on&amp;nbsp;Version 15.2(4)E7. The&amp;nbsp;&lt;SPAN&gt;APAutoConfig template gets applied, then seconds later gets unapplied and it goes through this constantly, every 3-20 seconds.&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;TEMPLATE EVENT: Gi1/0/22: Unbinding template APAutoConfig&lt;BR /&gt;TEMPLATE EVENT: APAutoConfig :ccb_bound(FALSE), visible(TRUE), pref_count(0)&lt;BR /&gt;TEMPLATE EVENT: Gi1/0/22: Binding template APAutoConfig&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What's going on here? I've taken each line out of the base Dot1x-Port to see if it's causing a problem but it's made no change. Changing the sticky timer made no difference. I'm sure this worked on an older IOS version because I tested it before putting it on this switch config. I had to update for another reason - I've tried 2 different IOS versions - and it's simply not working. Is this a bug or am I missing something here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3779354#M543422</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2019-03-11T08:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3840759#M543423</link>
      <description>&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;hopefully u've already resolved the problem. If u didnt just&amp;nbsp;dont change host-mode within dynamic server template. Just stay with single host-mode multi-auth.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 02:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3840759#M543423</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2019-04-18T02:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3840939#M543424</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately that wouldn't work, for the access point to work you need 'host-mode multi-host' to work, but we don't want the same on an access port connected to a PC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did figure it out though - for whatever reason, in certain versions, Cisco have broken the template assignment. We were trying the newer, recommended IOS versions and they were all giving us problems. Luckily, the version that came with all ~330 of our 2960Xs works most of the time with a few configuration tweaks. Certain things in this version can't be applied on an interface-template, that could be in the newer versions.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 09:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/3840939#M543424</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2019-04-18T09:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4758632#M579326</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;Has there been any resolution to this at all please? I am coming across the same problem using 9300 switches and this is the only thing on the Internet I can find about it. The testing we have done on a switch using code&amp;nbsp;16.12.02 worked fine, however moving to&amp;nbsp;17.6.1r[FC2] the scripts try to apply but then give the same log messages as Dan has displayed. Our script only applies native VLAN, trunk mode and allowed VLANs on the trunk.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 10:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4758632#M579326</guid>
      <dc:creator>joeswain1</dc:creator>
      <dc:date>2023-01-20T10:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4758761#M579329</link>
      <description>&lt;P&gt;more clarification on the workaround with "&lt;SPAN&gt;host-mode multi-auth". it's still possible with "open" authentication. but pre-authen acl is needed to allow AP to authenticate with AuthZ result built with template (port trunk + native VLAN) &amp;amp; DACL allowing traffic for clients.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Drawback is obvious: switch will perform configured on the port aaa sequence for wireless clients (ISE will be full of fails) but with authen open &amp;amp; proper authZ profile it wont block users.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 19:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4758761#M579329</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-01-21T19:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: IBNS 2.0: 2960X, ISE2.4, Interface Template Unbinding</title>
      <link>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4759173#M579349</link>
      <description>&lt;P&gt;as u might understood from above u have 2 choices:&lt;BR /&gt;1) configure host mode multi-host on flex-AP port &amp;amp; dont try to change it. it's something u cant change dynamically&lt;/P&gt;
&lt;P&gt;2) configure host mode multi-auth with mentioned above precautions. if u want to be unified across all the access ports it will change model of your deployment from close to low-impact&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 19:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ibns-2-0-2960x-ise2-4-interface-template-unbinding/m-p/4759173#M579349</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-01-21T19:24:45Z</dc:date>
    </item>
  </channel>
</rss>

