<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Connect to Endpoint when user logs off in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051368#M559102</link>
    <description>&lt;P&gt;We are in the process of deploying ISE 2.6 Patch 3 and are using Cisco AnyConnect Network Access Manager for EAP Chaining. We have ran into a a situation where whenever no user is logged into the machine it becomes unreachable (no ping, VNC, etc.). I have attached screenshots of our NAM configuration from the AnyConnect Profile Editor. Are there additional settings in ISE that could be causing this behavior? We currently have a rule in our Policy in ISE that is Temp Roll Out rule that basically allows anything that is profiled as a Workstation, etc. to connect. I have a TAC case open as well but they aren't being very responsive.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2020 16:21:24 GMT</pubDate>
    <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
    <dc:date>2020-03-24T16:21:24Z</dc:date>
    <item>
      <title>Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051368#M559102</link>
      <description>&lt;P&gt;We are in the process of deploying ISE 2.6 Patch 3 and are using Cisco AnyConnect Network Access Manager for EAP Chaining. We have ran into a a situation where whenever no user is logged into the machine it becomes unreachable (no ping, VNC, etc.). I have attached screenshots of our NAM configuration from the AnyConnect Profile Editor. Are there additional settings in ISE that could be causing this behavior? We currently have a rule in our Policy in ISE that is Temp Roll Out rule that basically allows anything that is profiled as a Workstation, etc. to connect. I have a TAC case open as well but they aren't being very responsive.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 16:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051368#M559102</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T16:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051389#M559104</link>
      <description>Can you please share screenshots or further describe how you have your test authz policies configured?  There is a condition you should be utilizing that would allow access based on the eap-chaining result.  It sounds like the issue you are facing is that hosts are dropping off the network when eap-chaining is user fail and machine pass.  The authz condition is this: Network Access: EAPChainingResult EQUALS: User failed and machine succeeded.  In your test case you would want to maybe push this type of result into a restricted area.</description>
      <pubDate>Tue, 24 Mar 2020 16:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051389#M559104</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T16:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051400#M559105</link>
      <description>&lt;P&gt;I've attached screenshots of our Authz Policy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 16:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051400#M559105</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T16:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051408#M559106</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;The required three authorisation policies seem to be in place. Ensure that the configuration is correct though, following &lt;A title="this guide" href="https://community.cisco.com/t5/security-documents/how-to-deploy-eap-chaining-with-anyconnect-nam-and-ise/ta-p/3630969" target="_self"&gt;this guide&lt;/A&gt;. When only the machine is authenticated, what is the status on ISE (what is the currently pushed policy) and on the switch "show authentication session" for the interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051408#M559106</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-24T17:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051420#M559107</link>
      <description>&lt;P&gt;Authz policy is configured as expected (right). Can you share what is configured in this authz profile (Computer Wired Access)? It looks like you have a few hundred hits on that authz policy. As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295226"&gt;@Cristian Matei&lt;/a&gt;&amp;nbsp;mentioned see what the switch is showing for auth detail.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051420#M559107</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T17:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051428#M559109</link>
      <description>&lt;P&gt;I can't seem to find the Computer Wired Access auth profile to be able to check the configuration. I'll be glad to provide some screenshots but I seem to only be able to find it listed in&amp;nbsp; the Policy Set&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:27:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051428#M559109</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T17:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051439#M559110</link>
      <description>Policy-&amp;gt;Policy Elements-&amp;gt;Results-&amp;gt;Authorization-&amp;gt;Authz Profiles</description>
      <pubDate>Tue, 24 Mar 2020 17:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051439#M559110</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051447#M559111</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 811px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69846i6885C8965C276E9E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051447#M559111</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T17:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051449#M559112</link>
      <description>&lt;P&gt;This is what the switch port shows:&amp;nbsp;sh auth sessions | i Gi3/11&lt;BR /&gt;Gi3/11 d89e.f39e.7d5e dot1x DATA Auth 0A800A050000387C2389F8B4&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051449#M559112</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T17:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051454#M559113</link>
      <description>What vlan is being pushed? Is this vlan in the switch vlan.db?  Show from switch: #Show auth session interface XXX detail</description>
      <pubDate>Tue, 24 Mar 2020 17:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051454#M559113</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T17:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051459#M559114</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 706px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69850i09BF9ADDD7CDA44A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051459#M559114</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T17:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051462#M559115</link>
      <description>Could be a dacl issue.  I would verify your dacl contains (allows) your test host where you are pinging from.  Dacl in ISE can be found here: Policy-&amp;gt;Policy Elements-&amp;gt;Results-&amp;gt;Authorization-&amp;gt;Downloadable ACLs&lt;BR /&gt;Can you share that interface config as well please</description>
      <pubDate>Tue, 24 Mar 2020 17:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051462#M559115</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T17:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051464#M559116</link>
      <description>&lt;P&gt;switchport access vlan 11&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 64&lt;BR /&gt;switchport port-security maximum 5&lt;BR /&gt;authentication event server dead action authorize vlan 254&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity 60&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;qos trust device cisco-phone&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input AutoQos-4.0-Cisco-Phone-Input-Policy&lt;BR /&gt;service-policy output AutoQos-4.0-Output-Policy&lt;BR /&gt;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 17:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051464#M559116</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T17:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051469#M559117</link>
      <description>I don't think that I have a DACL assigned to that Authz Profile. My DACL config is:&lt;BR /&gt;&lt;BR /&gt;permit udp any eq 68 any eq 67&lt;BR /&gt;permit udp any any eq 53&lt;BR /&gt;permit ip any host &amp;lt;DNS SERVER IP&amp;gt;&lt;BR /&gt;permit ip any host &amp;lt;DC IP&amp;gt;&lt;BR /&gt;deny ip any any</description>
      <pubDate>Tue, 24 Mar 2020 18:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051469#M559117</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T18:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051486#M559118</link>
      <description>Your sh auth detail output (server policies) tells me ISE authz profile is pushing dacl. Does sh ip access-list int XX return anything? Try adding your test host iip n that dacl, then force reauth, then try to ping.  &lt;BR /&gt;I would take a peek at an admin guide: &lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3650/sec-user-8021x-xe-3se-3650-book/sec-ieee-open-auth.html#GUID-65E5A890-B7C0-43AC-976D-D76BF6135085" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3650/sec-user-8021x-xe-3se-3650-book/sec-ieee-open-auth.html#GUID-65E5A890-B7C0-43AC-976D-D76BF6135085&lt;/A&gt;&lt;BR /&gt;Also, for future reference I recommend starting with less configs, get it working, then slowly add things back.  May help with identifying root cause.  Check out labminutes.com/sec as well for free config tutorials.  HTH!</description>
      <pubDate>Tue, 24 Mar 2020 18:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051486#M559118</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-03-24T18:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Endpoint when user logs off</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051495#M559119</link>
      <description>&lt;P&gt;Thank you so much! The issue was the DACL which I didn't event think that I had applied anywhere but clearly I had somehow managed to do just that. I really appreciate it and I have made adjustments to the DACL and now I am able to connect to the machine as expected when no user is logged in.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 18:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-endpoint-when-user-logs-off/m-p/4051495#M559119</guid>
      <dc:creator>jmartin@mooresvillenc.gov</dc:creator>
      <dc:date>2020-03-24T18:26:22Z</dc:date>
    </item>
  </channel>
</rss>

