<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 802.1x and Windows Logoff in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119969#M561743</link>
    <description>&lt;P&gt;Since you are configured to do user authentication only, the computer cannot authenticate to the switch once the user logs out.&amp;nbsp; Change your supplicant to do machine or user and in your policies, just allow basic access for Domain Computer.&amp;nbsp; That allows the computer to authenticate when the user is not logged in and can get GPO's and do user authentication if cached credentials aren't being used.&lt;/P&gt;&lt;P&gt;You can also SPAN the switchport and grab a capture of what is happening in that scenario.&amp;nbsp; Sounds like you can recreate it very easily.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2020 14:29:11 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2020-07-16T14:29:11Z</dc:date>
    <item>
      <title>ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264384#M144746</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;i have a ISE works fine using 802.1x but we have a strange behavior when the client just logoff the windows machine, after the client login again, the machine does not authenticate and stuck as a message " not possible to authenticate". Then I need to take off the cable machine and put again, after this everything works fine.&lt;/P&gt;&lt;P&gt;This happens just using logoff windows. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could someone help me about it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264384#M144746</guid>
      <dc:creator>danielnunes</dc:creator>
      <dc:date>2019-03-11T03:28:22Z</dc:date>
    </item>
    <item>
      <title>ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264385#M144758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Need more detail.. What Config have you got on the switchport and what authentication Config have you got on the Client? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 20:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264385#M144758</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-05-28T20:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264386#M144778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rik,&lt;/P&gt;&lt;P&gt;I am using this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet3/33&lt;/P&gt;&lt;P&gt;switchport access vlan 22&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport voice vlan 23&lt;/P&gt;&lt;P&gt;ip access-group ACL-DEFAULT in&lt;/P&gt;&lt;P&gt;logging event link-status&lt;/P&gt;&lt;P&gt;authentication event fail action next-method&lt;/P&gt;&lt;P&gt;authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt;authentication order dot1x mab&lt;/P&gt;&lt;P&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;authentication port-control auto&lt;/P&gt;&lt;P&gt;authentication violation restrict&lt;/P&gt;&lt;P&gt;mab&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt;dot1x pae authenticator&lt;/P&gt;&lt;P&gt;dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt;qos trust device cisco-phone&lt;/P&gt;&lt;P&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;service-policy input AutoQos-4.0-Cisco-Phone-Input-Policy&lt;/P&gt;&lt;P&gt;service-policy output AutoQos-4.0-Output-Policy&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the client are using the NAC Agent the way to perform a posture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i take off the cable and put again, everything works fine, but if the client try to logoff and after a time login again, the NIC Card can not be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 20:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264386#M144778</guid>
      <dc:creator>danielnunes</dc:creator>
      <dc:date>2013-05-28T20:36:06Z</dc:date>
    </item>
    <item>
      <title>ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264387#M144799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so its MDA that means a PC is connected behind the phone. If I'm not wrong the &lt;STRONG&gt;CDP Enhancement for Second Port Disconnect working fine &lt;/STRONG&gt;when we plug/unplug the cable but when a user logoff it doesn't (only if we are using cisco phones). In order to clear the sessions switch need to detect link state for devices connected behind IP phones. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are we using 802.1x or MAB on the windows PC's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we also look at the debugs when clients are unable to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show authentication session interface &lt;INTERFACE-ID&gt;&lt;/INTERFACE-ID&gt;&lt;/P&gt;&lt;P&gt;debug dot1x all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264387#M144799</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-28T21:22:30Z</dc:date>
    </item>
    <item>
      <title>ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264388#M144842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And have you got Machine Authentication enabled on the Clients?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 21:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264388#M144842</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-05-28T21:27:32Z</dc:date>
    </item>
    <item>
      <title>Hi Jatin,I was looking for</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264389#M144876</link>
      <description>&lt;P&gt;Hi Jatin,&lt;BR /&gt;&lt;BR /&gt;I was looking for some information on the forum and am having exactly the problem that you put in your post, users have the PC is connected behind the ip phone. Some users lose authentication, and only come back when plug/unplug the cable.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;How you managed to solve this problem.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Fernando Silva&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 15:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/2264389#M144876</guid>
      <dc:creator>fernandossilva</dc:creator>
      <dc:date>2017-06-05T15:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4118914#M561708</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone got a solution to this problem,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its affecting almost all of my clients' regardless of whatever&amp;nbsp; ise version i'm using&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 06:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4118914#M561708</guid>
      <dc:creator>mikisa.timothy2</dc:creator>
      <dc:date>2020-07-15T06:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119208#M561721</link>
      <description>&lt;P&gt;On Windows, when a user is logged in, the computer is in the "user state" and sends user credentials.&amp;nbsp; When a user logs off, the computer switches to "machine state" and sends machine credentials.&amp;nbsp; If your supplicant is configured to do machine OR user authentication, then make sure the machine is passing authentication and getting enough access to reach AD domain controllers.&amp;nbsp; When you are having this issue, do a "show authentication sessions interface X details".&amp;nbsp; See what it shows there.&amp;nbsp; If it shows Authorized, then make sure that the ACL applied (if any) is allowing connection to domain controllers.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 13:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119208#M561721</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-07-15T13:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119620#M561733</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No ACL is applied, and the supplicant is using 802.1x user authentication only.&lt;/P&gt;&lt;P&gt;this problem happens only when the user logoff and then back in, when they login the network adapter card shows authentication failure and the show authentication command on the switch also gives a result of authentication failed.&lt;/P&gt;&lt;P&gt;until you unplug the computer cable and plug it again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This happens regardless of the switch model, supplicant windows version and ise version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 05:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119620#M561733</guid>
      <dc:creator>mikisa.timothy2</dc:creator>
      <dc:date>2020-07-16T05:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119969#M561743</link>
      <description>&lt;P&gt;Since you are configured to do user authentication only, the computer cannot authenticate to the switch once the user logs out.&amp;nbsp; Change your supplicant to do machine or user and in your policies, just allow basic access for Domain Computer.&amp;nbsp; That allows the computer to authenticate when the user is not logged in and can get GPO's and do user authentication if cached credentials aren't being used.&lt;/P&gt;&lt;P&gt;You can also SPAN the switchport and grab a capture of what is happening in that scenario.&amp;nbsp; Sounds like you can recreate it very easily.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 14:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4119969#M561743</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-07-16T14:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x and Windows Logoff</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4120080#M561748</link>
      <description>&lt;P&gt;This is very helpful and it makes alot of sense let me do that thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 16:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-and-windows-logoff/m-p/4120080#M561748</guid>
      <dc:creator>mikisa.timothy2</dc:creator>
      <dc:date>2020-07-16T16:46:30Z</dc:date>
    </item>
  </channel>
</rss>

