<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic multiple Failed authentication attempts in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-failed-authentication-attempts/m-p/2679048#M54744</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ISE 1.2 patch 14 running.&amp;nbsp; We are getting a lot of failed authentications.&amp;nbsp; I found a handful of PCs that are failing, and the failing authentication is not the issue.&amp;nbsp; The problem is that they continuously try to re-authenticate, ever few minutes.&amp;nbsp; I checked the authorization profile they are hitting and Reauthentication checkbox is not selected.&amp;nbsp; The port this one PC is connected to had the command 'authentication timer reauthenticate server'.&amp;nbsp; In testing I changed this to 'authentication timer reauthenticate 14400' (4 hours) but the PC still tries to authenticate every couple minutes.&amp;nbsp; What am I doing wrong or what am I missing??&lt;/P&gt;&lt;P&gt;This is the entire port config:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/6&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport access vlan 200&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;ip access-group ACL-ALLOW in&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate 14400&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change added&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change removed&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast edge&lt;BR /&gt;&amp;nbsp;ip dhcp snooping limit rate 15&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:54:48 GMT</pubDate>
    <dc:creator>mosc9562</dc:creator>
    <dc:date>2019-03-11T05:54:48Z</dc:date>
    <item>
      <title>multiple Failed authentication attempts</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-failed-authentication-attempts/m-p/2679048#M54744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ISE 1.2 patch 14 running.&amp;nbsp; We are getting a lot of failed authentications.&amp;nbsp; I found a handful of PCs that are failing, and the failing authentication is not the issue.&amp;nbsp; The problem is that they continuously try to re-authenticate, ever few minutes.&amp;nbsp; I checked the authorization profile they are hitting and Reauthentication checkbox is not selected.&amp;nbsp; The port this one PC is connected to had the command 'authentication timer reauthenticate server'.&amp;nbsp; In testing I changed this to 'authentication timer reauthenticate 14400' (4 hours) but the PC still tries to authenticate every couple minutes.&amp;nbsp; What am I doing wrong or what am I missing??&lt;/P&gt;&lt;P&gt;This is the entire port config:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/6&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport access vlan 200&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;ip access-group ACL-ALLOW in&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate 14400&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change added&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change removed&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast edge&lt;BR /&gt;&amp;nbsp;ip dhcp snooping limit rate 15&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-failed-authentication-attempts/m-p/2679048#M54744</guid>
      <dc:creator>mosc9562</dc:creator>
      <dc:date>2019-03-11T05:54:48Z</dc:date>
    </item>
    <item>
      <title>Hi, try authentication timer</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-failed-authentication-attempts/m-p/2679049#M54745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try&amp;nbsp;authentication timer restart 900 (= 15 minutes.).&lt;/P&gt;&lt;P&gt;If you are using MAB you should not use reauthentication.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2015 12:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-failed-authentication-attempts/m-p/2679049#M54745</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2015-07-27T12:25:44Z</dc:date>
    </item>
  </channel>
</rss>

