<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x with Windows 10 / ISE / AnyConnect 4.9 / Stuck on Acquiring IP Address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129214#M562055</link>
    <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;&lt;BR /&gt;I have been labbing some 802.1x up, I am using ISE for my Auth policies. The basic Windows 10 supplicant works fine, so I thought I would go to the 'next level' and break out some AnyConnect. If I try and establish a new connection with AnyConnect, I can see the Authentication and Authorization requests pass and succeed in ISE, but the client is stuck on Acquiring IP Address, and eventually times out. I have tried this on two ISE installs I have, the only thing that's the same is that the clients are both virtual. ISE version is 2.6, AnyConnect 4.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-08-02 at 15.03.56.png" style="width: 556px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80655iE36BA98D1828234C/image-dimensions/556x25?v=v2" width="556" height="25" role="button" title="Screenshot 2020-08-02 at 15.03.56.png" alt="Screenshot 2020-08-02 at 15.03.56.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-08-02 at 15.04.06.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80656iC5ABE733BA526CBB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2020-08-02 at 15.04.06.png" alt="Screenshot 2020-08-02 at 15.04.06.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Aug 2020 14:06:27 GMT</pubDate>
    <dc:creator>Xividar</dc:creator>
    <dc:date>2020-08-02T14:06:27Z</dc:date>
    <item>
      <title>802.1x with Windows 10 / ISE / AnyConnect 4.9 / Stuck on Acquiring IP Address</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129214#M562055</link>
      <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;&lt;BR /&gt;I have been labbing some 802.1x up, I am using ISE for my Auth policies. The basic Windows 10 supplicant works fine, so I thought I would go to the 'next level' and break out some AnyConnect. If I try and establish a new connection with AnyConnect, I can see the Authentication and Authorization requests pass and succeed in ISE, but the client is stuck on Acquiring IP Address, and eventually times out. I have tried this on two ISE installs I have, the only thing that's the same is that the clients are both virtual. ISE version is 2.6, AnyConnect 4.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-08-02 at 15.03.56.png" style="width: 556px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80655iE36BA98D1828234C/image-dimensions/556x25?v=v2" width="556" height="25" role="button" title="Screenshot 2020-08-02 at 15.03.56.png" alt="Screenshot 2020-08-02 at 15.03.56.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2020-08-02 at 15.04.06.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/80656iC5ABE733BA526CBB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2020-08-02 at 15.04.06.png" alt="Screenshot 2020-08-02 at 15.04.06.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2020 14:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129214#M562055</guid>
      <dc:creator>Xividar</dc:creator>
      <dc:date>2020-08-02T14:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with Windows 10 / ISE / AnyConnect 4.9 / Stuck on Acquiring IP Address</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129232#M562056</link>
      <description>DART bundle from user machine need to be checked for DHCP issue along with the "show authentication session int &amp;lt;&amp;gt; detail&amp;gt; output on the switch .</description>
      <pubDate>Sun, 02 Aug 2020 16:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129232#M562056</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-08-02T16:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with Windows 10 / ISE / AnyConnect 4.9 / Stuck on Acquiring IP Address</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129625#M562067</link>
      <description>&lt;P&gt;It is possible that ISE is showing the authentication/authorization pass and returns an Access-Accept; however, the switch may not be able to apply the policy you are returning.&amp;nbsp; In that case, the switchport remains closed since it cannot apply the policy.&amp;nbsp; But ISE still shows it as good.&amp;nbsp; I have seen this happen a few times over the years.&amp;nbsp; It can happen if you push down a VLAN assignment but the VLAN doesn't exist on the switch.&amp;nbsp; It can also happen when the dACL has an issue with it such as being too long (&amp;gt;63 lines) for older switches (3750) or if the dACL syntax is incorrect.&amp;nbsp; I have seen where ISE says the dACL is fine even when one of the IP addresses was missing an entire octet (3 versus 4).&lt;/P&gt;&lt;P&gt;Do a "show authentication session interface gx/y detail" and make sure it shows "Authorized".&amp;nbsp; Also, if using a dACL, you need to be using IP device tracking.&lt;/P&gt;&lt;P&gt;Another thing to look at is with your Anyconnect profile, there is an option to allow traffic to flow before authentication.&amp;nbsp; I recommend allowing the traffic to flow and let the switch control access with default ACLs.&amp;nbsp; Because with Windows, you will probably want to allow some basic connectivity at a minimum to not break GPO's and domain logins.&amp;nbsp; This would include DHCP too.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 15:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/4129625#M562067</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-08-03T15:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x with Windows 10 / ISE / AnyConnect 4.9 / Stuck on Acquiring</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/5376134#M600026</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/327312"&gt;@Xividar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you fix it ? and how ? please share&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 06:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-windows-10-ise-anyconnect-4-9-stuck-on-acquiring-ip/m-p/5376134#M600026</guid>
      <dc:creator>ADC Lane</dc:creator>
      <dc:date>2026-03-12T06:41:59Z</dc:date>
    </item>
  </channel>
</rss>

