<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication Sessions detailed incorrect in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-sessions-detailed-incorrect/m-p/4052253#M559145</link>
    <description>&lt;P&gt;This is a unique issue as TAC has been having a hard time figuring it out.&amp;nbsp; One minute it starts working, another it doesnt.&amp;nbsp; So to break it down, we are using:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Not Working&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Catalyst 9410 -- Latest version&amp;nbsp;16.9.4 with two patches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Working&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Catalyst 4506&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;--Same usual configuration.&amp;nbsp; Works flawlessly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;What RADIUS?&lt;/U&gt;&lt;/P&gt;&lt;P&gt;ISE 2.6 - Base License -- Uses same policies for both.&amp;nbsp; So we know that is not the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, you would believe its just a cut-and-paste of the configs..not so.&amp;nbsp; So here is what I have, I hope you all can shed some light as I'm hitting a dead end here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip dhcp snooping glean&lt;BR /&gt;ip dhcp snooping vlan 200,400, 800&lt;BR /&gt;no ip dhcp snooping information option&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; --They said this is not supposed to work, but this is causing it to sort-of-work.&lt;BR /&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device-tracking logging packet drop&lt;BR /&gt;device-tracking logging theft&lt;BR /&gt;device-tracking tracking auto-source fallback 0.0.0.10 255.255.255.0 override&lt;BR /&gt;device-tracking tracking retry-interval 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;authentication critical recovery delay 1000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;switchport access vlan 200&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 800&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;spanning-tree bpdufilter enable&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;authentication event fail retry 3 action authorize vlan 400&lt;BR /&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;qos trust device cisco-phone&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 32 include-in-access-req format %h&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf&lt;BR /&gt;radius-server dead-criteria time 10 tries 3&lt;BR /&gt;radius-server vsa send cisco-nas-port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If looking at show device-tracking database.&amp;nbsp; It shows all is reachable; cool.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If looking at show authentication sessions interface Blah/Blah/Blah detail.&amp;nbsp; It shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernetBlah/Blah/Blah&lt;BR /&gt;IIF-ID: 0x16105801&lt;BR /&gt;MAC Address: 0050.0000.0000 (Filtered MAC but It's a Thin Client)&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----But yet I can ping it and https to it??&lt;BR /&gt;User-Name: 00-50-00-00-00-00&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: 0B6410AC000000F311D980CA&lt;BR /&gt;Acct Session ID: 0x000000d4&lt;BR /&gt;Handle: 0x8a0000e2&lt;BR /&gt;Current Policy: POLICY_GiBlah/Blah/Blah&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;ACS ACL: xACSACLx-IP-DATA_THINCLIENT_ACL_backup-5e7a240c&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the Authentication is a success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VLAN is where it should be&lt;/P&gt;&lt;P&gt;The dACL is what it should be (includes bootps and bootpc in the dACL)&lt;/P&gt;&lt;P&gt;if its voice phone, its where it should be&lt;/P&gt;&lt;P&gt;if its a guest it gets blackholed (as it should be)&lt;/P&gt;&lt;P&gt;after next business day, I can't connect to it any longer.&amp;nbsp; So since then I put in:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding down-lifetime 600&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding reachable-lifetime 86400&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding stale-lifetime 600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I look at ISE RADIUS Logs, it reads and authenticates, but does not show the IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping, https to it but it does not show correctly on there as it shows up on the database.&amp;nbsp; I have other ports within the same switch that is &lt;U&gt;not&lt;/U&gt; using RADIUS and it works well too.&amp;nbsp;&amp;nbsp;What am I missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Mar 2020 17:00:28 GMT</pubDate>
    <dc:creator>NetEngineerKC15</dc:creator>
    <dc:date>2020-03-25T17:00:28Z</dc:date>
    <item>
      <title>Authentication Sessions detailed incorrect</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-sessions-detailed-incorrect/m-p/4052253#M559145</link>
      <description>&lt;P&gt;This is a unique issue as TAC has been having a hard time figuring it out.&amp;nbsp; One minute it starts working, another it doesnt.&amp;nbsp; So to break it down, we are using:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Not Working&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Catalyst 9410 -- Latest version&amp;nbsp;16.9.4 with two patches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Working&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Catalyst 4506&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;--Same usual configuration.&amp;nbsp; Works flawlessly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;What RADIUS?&lt;/U&gt;&lt;/P&gt;&lt;P&gt;ISE 2.6 - Base License -- Uses same policies for both.&amp;nbsp; So we know that is not the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, you would believe its just a cut-and-paste of the configs..not so.&amp;nbsp; So here is what I have, I hope you all can shed some light as I'm hitting a dead end here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip dhcp snooping glean&lt;BR /&gt;ip dhcp snooping vlan 200,400, 800&lt;BR /&gt;no ip dhcp snooping information option&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; --They said this is not supposed to work, but this is causing it to sort-of-work.&lt;BR /&gt;ip dhcp snooping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device-tracking logging packet drop&lt;BR /&gt;device-tracking logging theft&lt;BR /&gt;device-tracking tracking auto-source fallback 0.0.0.10 255.255.255.0 override&lt;BR /&gt;device-tracking tracking retry-interval 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;authentication critical recovery delay 1000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;switchport access vlan 200&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 800&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;spanning-tree bpdufilter enable&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;authentication event fail retry 3 action authorize vlan 400&lt;BR /&gt;mab&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;qos trust device cisco-phone&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 32 include-in-access-req format %h&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf&lt;BR /&gt;radius-server dead-criteria time 10 tries 3&lt;BR /&gt;radius-server vsa send cisco-nas-port&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If looking at show device-tracking database.&amp;nbsp; It shows all is reachable; cool.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If looking at show authentication sessions interface Blah/Blah/Blah detail.&amp;nbsp; It shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernetBlah/Blah/Blah&lt;BR /&gt;IIF-ID: 0x16105801&lt;BR /&gt;MAC Address: 0050.0000.0000 (Filtered MAC but It's a Thin Client)&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----But yet I can ping it and https to it??&lt;BR /&gt;User-Name: 00-50-00-00-00-00&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: 0B6410AC000000F311D980CA&lt;BR /&gt;Acct Session ID: 0x000000d4&lt;BR /&gt;Handle: 0x8a0000e2&lt;BR /&gt;Current Policy: POLICY_GiBlah/Blah/Blah&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;ACS ACL: xACSACLx-IP-DATA_THINCLIENT_ACL_backup-5e7a240c&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the Authentication is a success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VLAN is where it should be&lt;/P&gt;&lt;P&gt;The dACL is what it should be (includes bootps and bootpc in the dACL)&lt;/P&gt;&lt;P&gt;if its voice phone, its where it should be&lt;/P&gt;&lt;P&gt;if its a guest it gets blackholed (as it should be)&lt;/P&gt;&lt;P&gt;after next business day, I can't connect to it any longer.&amp;nbsp; So since then I put in:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding down-lifetime 600&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding reachable-lifetime 86400&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;device-tracking binding stale-lifetime 600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I look at ISE RADIUS Logs, it reads and authenticates, but does not show the IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping, https to it but it does not show correctly on there as it shows up on the database.&amp;nbsp; I have other ports within the same switch that is &lt;U&gt;not&lt;/U&gt; using RADIUS and it works well too.&amp;nbsp;&amp;nbsp;What am I missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 17:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-sessions-detailed-incorrect/m-p/4052253#M559145</guid>
      <dc:creator>NetEngineerKC15</dc:creator>
      <dc:date>2020-03-25T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sessions detailed incorrect</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-sessions-detailed-incorrect/m-p/4052515#M559160</link>
      <description>&lt;P&gt;Duplicate question.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://community.cisco.com/t5/network-access-control/device-tracking-set-authentication-session-detailed-ip-missing/m-p/4052238" target="_self"&gt;this community post&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 23:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-sessions-detailed-incorrect/m-p/4052515#M559160</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-03-25T23:10:15Z</dc:date>
    </item>
  </channel>
</rss>

