<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Undocking and docking back puts the PC on the default VLAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3337595#M550465</link>
    <description>&lt;P&gt;Cool, glad&amp;nbsp;you got it working, do you still see multiple&amp;nbsp;auth from the PCs?&lt;/P&gt;
&lt;P&gt;Like always trying MAB first?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2018 06:03:14 GMT</pubDate>
    <dc:creator>edondurguti</dc:creator>
    <dc:date>2018-02-26T06:03:14Z</dc:date>
    <item>
      <title>Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320335#M550457</link>
      <description>&lt;P&gt;We are using ISE 2.2 patch 5 and AnyConnect 4.5 NAM module as the supplicant for 802.1x authentication. We are using Cisco 3850x switch with 16.6.1 Everest code.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have run into a weird issue: When a laptop (WIN 10) is undocked and docked back, wireless adapter gets disabled (which is expected behavior) and the wired adapter takes over, but instead of doing dot1x again, the port does MAB and gets&amp;nbsp;on the default VLAN (ISE policy is configured to put all devices doing MAB on default switch port VLAN and is redirected to a guest portal). We then go the NAM module, select the wired profile which fires the supplicant and puts the PC on correct network doing dot1x authentication.&lt;/P&gt;
&lt;P&gt;Has anyone else using the AnyConnect NAM module seen this issue? I did read a discussion about windows supplicant having same issue and disabling fast-reconnect solved the issue. We have tried this with the NAM module too and it does not resolve the issue. We have IP device tracking enabled too.&lt;/P&gt;
&lt;P&gt;Any information on this would be really appreciated. I haven't been able to search any bugs related to this too.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320335#M550457</guid>
      <dc:creator>abhishek.marat1</dc:creator>
      <dc:date>2020-02-21T18:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320356#M550458</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://supportforums.cisco.com/t5/aaa-identity-and-nac/802-1x-and-laptop-docking-why-does-it-want-to-do-mab/td-p/2857868" target="_blank"&gt;https://supportforums.cisco.com/t5/aaa-identity-and-nac/802-1x-and-laptop-docking-why-does-it-want-to-do-mab/td-p/2857868&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2018 08:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320356#M550458</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2018-01-28T08:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320570#M550461</link>
      <description>&lt;P&gt;This is exactly the link I referred in the discussion. We have tried disabling fast reconnect in the AnyConnect NAM profile, but it does not help.&lt;/P&gt;
&lt;P&gt;Any other&amp;nbsp;options to try?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2018 21:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3320570#M550461</guid>
      <dc:creator>abhishek.marat1</dc:creator>
      <dc:date>2018-01-28T21:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3323889#M550462</link>
      <description>&lt;P&gt;From the Device Manager, disable all power options (hopefully you don't use Wake on Lan).&lt;/P&gt;
&lt;P&gt;It's important that you disable all of the options not just wake on lan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="10_95_237_54.png" style="width: 986px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7122i9D9E7C47D68DB7B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="10_95_237_54.png" alt="10_95_237_54.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 05:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3323889#M550462</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2018-02-02T05:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3326134#M550463</link>
      <description>&lt;P&gt;Hi @edondurgut&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wake on LAN was disabled. So we unchecked that option of&amp;nbsp; 'Allow computer to..' in the power management settings. Rebooted the PC and still no luck. PC still does MAB and falls on the default VLAN of the port.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 17:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3326134#M550463</guid>
      <dc:creator>abhishek.marat1</dc:creator>
      <dc:date>2018-02-06T17:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3328220#M550464</link>
      <description>&lt;P&gt;So, we tried that and that did not help. Also, wake-on-lan was disabled. We had a TAC case open for this and realized that the the priority was set incorrectly. We had configured the ports with a policy. The port was not set to do dot1x and MAB simultaneously.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;policy-map type control subscriber ISE-POLICY-TEST2&lt;/P&gt;
&lt;P&gt;event session-started match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 authenticate using mab priority 20&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using dot1x priority 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 30 authenticate using webauth parameter-map WEBAUTH_DEFAULT priority 30&lt;/P&gt;
&lt;P&gt;event authentication-failure match-first&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class ALL_FAILED do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 authentication-restart 60&lt;/P&gt;
&lt;P&gt;event authentication-success match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class DOT1X do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 terminate webauth&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 20 class MAB do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate webauth&lt;/P&gt;
&lt;P&gt;event agent-found match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 authenticate using dot1x priority 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We applied this through the policy and then it worked. Thank you for all your insights!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2018 14:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3328220#M550464</guid>
      <dc:creator>abhishek.marat1</dc:creator>
      <dc:date>2018-02-09T14:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Undocking and docking back puts the PC on the default VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3337595#M550465</link>
      <description>&lt;P&gt;Cool, glad&amp;nbsp;you got it working, do you still see multiple&amp;nbsp;auth from the PCs?&lt;/P&gt;
&lt;P&gt;Like always trying MAB first?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 06:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/undocking-and-docking-back-puts-the-pc-on-the-default-vlan/m-p/3337595#M550465</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2018-02-26T06:03:14Z</dc:date>
    </item>
  </channel>
</rss>

