<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-Authenticate End hosts after ISE failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4073095#M559865</link>
    <description>&lt;P&gt;Hi Damien,&lt;BR /&gt;&lt;BR /&gt;Thanks for you assistance, it took me a while to test this and to be honest, IBNS2.0 is a bit tricky to get your head around after being used to the 'old' ways....but it now looks to be working well.&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2020 07:34:38 GMT</pubDate>
    <dc:creator>ShaunGreen</dc:creator>
    <dc:date>2020-04-24T07:34:38Z</dc:date>
    <item>
      <title>Re-Authenticate End hosts after ISE failure</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4068333#M559714</link>
      <description>&lt;P&gt;Dear All,&lt;BR /&gt;&lt;BR /&gt;We are using IBNS 2.0 with dot1x and mab.&lt;BR /&gt;&lt;BR /&gt;Everything so far is working in our testing and when we simulate an ISE failure the Critical service template allows the end hosts access to the network.&lt;BR /&gt;&lt;BR /&gt;When the ISE server comes back online, the dot1x hosts re-authenticate and pickup their correct policy sets.&lt;BR /&gt;&lt;BR /&gt;But the MAB (profiled) devices stay in the Critical state.&lt;BR /&gt;&lt;BR /&gt;Does anyone know the best procedure to automatically re-authenticate these devices once the ISE server is back online?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 18:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4068333#M559714</guid>
      <dc:creator>ShaunGreen</dc:creator>
      <dc:date>2020-04-17T18:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Authenticate End hosts after ISE failure</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4068904#M559733</link>
      <description>&lt;P&gt;Please attach the "sh tech" output from the switch.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2020 00:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4068904#M559733</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-04-19T00:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Authenticate End hosts after ISE failure</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4069452#M559760</link>
      <description>&lt;P&gt;Hi, Thanks for your interest.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To give some more information, I closed down the ISE application on Friday evening. Everything failed over using the 'Critical' service template (screen shot below).&lt;BR /&gt;&lt;BR /&gt;When the Radius servers are back online, the dot1x hosts re-autenticate, but the MAB profiled devices are still staying on the Critical service template.&lt;BR /&gt;&lt;BR /&gt;We could manually carry out a COA from ISE for these hosts, but I'm wondering if there is a way to configure re-authentication once the ISE is up and running without manual intervention?&lt;BR /&gt;&lt;BR /&gt;Code is 16.9.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 07:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4069452#M559760</guid>
      <dc:creator>ShaunGreen</dc:creator>
      <dc:date>2020-04-20T07:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Authenticate End hosts after ISE failure</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4069850#M559772</link>
      <description>&lt;P&gt;It appears you may be missing policy required to resume authentication once AAA comes back online, you need to exit critical auth.&amp;nbsp;If you follow Hari's secure wired access prescriptive guide you can see how this could be done. &lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;ex.&amp;nbsp;&lt;BR /&gt;"event aaa-available match-all&lt;BR /&gt;10 class IN_CRITICAL_AUTH do-until-failure&lt;BR /&gt;10 clear-session&lt;BR /&gt;20 class NOT_IN_CRITICAL_AUTH do-until-failure&lt;BR /&gt;10 resume reauthentication"&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Table7.png" style="width: 880px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72290i1AC90EAD775F51BF/image-dimensions/880x686?v=v2" width="880" height="686" role="button" title="Table7.png" alt="Table7.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 15:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4069850#M559772</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-04-20T15:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Authenticate End hosts after ISE failure</title>
      <link>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4073095#M559865</link>
      <description>&lt;P&gt;Hi Damien,&lt;BR /&gt;&lt;BR /&gt;Thanks for you assistance, it took me a while to test this and to be honest, IBNS2.0 is a bit tricky to get your head around after being used to the 'old' ways....but it now looks to be working well.&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 07:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/re-authenticate-end-hosts-after-ise-failure/m-p/4073095#M559865</guid>
      <dc:creator>ShaunGreen</dc:creator>
      <dc:date>2020-04-24T07:34:38Z</dc:date>
    </item>
  </channel>
</rss>

