<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Authentication Succeed but the Windows not obtaining IP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151800#M562851</link>
    <description>&lt;P&gt;The DHCP and POOL are on the same switch.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2020 06:05:03 GMT</pubDate>
    <dc:creator>BASILISGKOGKOS7311</dc:creator>
    <dc:date>2020-09-16T06:05:03Z</dc:date>
    <item>
      <title>ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151402#M562842</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;after enabling NAC on a&amp;nbsp;C2960S-UNIVERSALK9-M , the authentication result in success but WKS doesn't obtain IP&lt;/P&gt;&lt;P&gt;I receive the following log;&lt;/P&gt;&lt;P&gt;194541: Sep 15 16:40:21.116 EET: %EPM-6-POLICY_REQ: IP 0.0.0.0| MAC 1803.7322.ff73| AuditSessionID 0A2E080D00000A45825AABF8| EVENT APPLY&lt;BR /&gt;194542: Sep 15 16:40:21.116 EET: %EPM-6-AAA: POLICY xACSACLx-IP-PERMIT_ALL_TRAFFIC-531f2938| EVENT DOWNLOAD_REQUEST&lt;BR /&gt;194543: Sep 15 16:40:21.116 EET: %EPM-6-POLICY_REQ: IP 0.0.0.0| MAC 1803.7322.ff73| AuditSessionID 0A2E080D00000A45825AABF8| EVENT APPLY&lt;BR /&gt;194544: Sep 15 16:40:21.132 EET: %EPM-6-AAA: POLICY xACSACLx-IP-PERMIT_ALL_TRAFFIC-531f2938| EVENT DOWNLOAD-SUCCESS&lt;BR /&gt;194545: Sep 15 16:40:21.153 EET: %EPM-6-IPEVENT: IP 0.0.0.0| MAC 1803.7322.ff73| AuditSessionID 0A2E080D00000A45825AABF8| EVENT IP-WAIT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the switchport configuration:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;dot1x max-reauth-req 1&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and :&lt;/P&gt;&lt;P&gt;#show authentication sessions interface g0/3 details&lt;BR /&gt;Interface: GigabitEthernet0/3&lt;BR /&gt;MAC Address: 1803.7322.ff73&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: CENTRAL-DOMAIN\xxxxxxx&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: single-host&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: 86400s (local), Remaining: 86331s&lt;BR /&gt;Session Uptime: 72s&lt;BR /&gt;Common Session ID: 0A2E080D00000A45825AABF8&lt;BR /&gt;Acct Session ID: 0x000009BB&lt;BR /&gt;Handle: 0x0C0000D9&lt;BR /&gt;Current Policy: POLICY_Gi0/3&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Authc Success&lt;/P&gt;&lt;P&gt;can anyone help with the above?&lt;/P&gt;&lt;P&gt;To receive a valid authentication, I implement machine and user changing against AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the problem appears after&amp;nbsp; upgrading&amp;nbsp; to Windows 10&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 13:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151402#M562842</guid>
      <dc:creator>BASILISGKOGKOS7311</dc:creator>
      <dc:date>2020-09-15T13:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151587#M562845</link>
      <description>&lt;P&gt;First thing I see is that you are not setting the access vlan on the port so it is defaulting to VLAN 1.&amp;nbsp; Does VLAN 1 have an SVI interface with an "ip helper-address" configured to forward DHCP requests to the DHCP server?&amp;nbsp; I don't recommend using VLAN 1.&amp;nbsp; Should probably set that to another VLAN.&amp;nbsp; Also, do you have IP Device Tracking enabled on the switch?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 18:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151587#M562845</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-09-15T18:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151598#M562846</link>
      <description>&lt;P&gt;hello.&lt;/P&gt;&lt;P&gt;DHCP is local on the switch.&lt;/P&gt;&lt;P&gt;i configure new vlan 101&amp;nbsp; :&lt;/P&gt;&lt;P&gt;interface Vlan101&lt;BR /&gt;ip address 10.99.99.1 255.255.255.0&lt;BR /&gt;end&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and :&lt;/P&gt;&lt;P&gt;ip dhcp pool Test&lt;BR /&gt;network 10.99.99.0 255.255.255.0&lt;BR /&gt;domain-name YYYYYYY&lt;BR /&gt;dns-server X.X.X.X&lt;/P&gt;&lt;P&gt;netbios-node-type p-node&lt;BR /&gt;default-router 10.99.99.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface configuration:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;BR /&gt;switchport access vlan 101&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;snmp trap mac-notification change removed&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;dot1x max-reauth-req 1&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I receive the same log and same result :&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet0/3&lt;BR /&gt;MAC Address: 1803.7322.ff73&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: CENTRAL-DOMAIN\XXXXX&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: single-host&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: 86400s (local), Remaining: 86285s&lt;BR /&gt;Session Uptime: 121s&lt;BR /&gt;Common Session ID: 0A2E080D00000A48837D4370&lt;BR /&gt;Acct Session ID: 0x000009BE&lt;BR /&gt;Handle: 0x610000DB&lt;BR /&gt;Current Policy: POLICY_Gi0/3&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP device tracking is enabled.&lt;/P&gt;&lt;P&gt;#show run | i device&lt;BR /&gt;ip device tracking probe delay 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SVI of vlan 101 is in another switch that is connected with this one via trunk interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 19:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151598#M562846</guid>
      <dc:creator>BASILISGKOGKOS7311</dc:creator>
      <dc:date>2020-09-15T19:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151691#M562850</link>
      <description>&lt;P&gt;So your VLAN 101 interface with IP 10.99.99.1 is on a different switch across a trunk?&amp;nbsp; But you are configuring your DHCP server and pool on the L2 switch that the client is plugging into?&amp;nbsp; I believe the SVI and DHCP server need to be on the same switch OR you need to configure an ip helper-address to tell the SVI where to forward DHCP requests to.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 23:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151691#M562850</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-09-15T23:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151800#M562851</link>
      <description>&lt;P&gt;The DHCP and POOL are on the same switch.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 06:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151800#M562851</guid>
      <dc:creator>BASILISGKOGKOS7311</dc:creator>
      <dc:date>2020-09-16T06:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151819#M562852</link>
      <description>&lt;P&gt;Sorry for the dumb question, does the switch where dhcp pool resides have a L3 interface on the same vlan?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 07:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151819#M562852</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2020-09-16T07:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151823#M562853</link>
      <description>&lt;P&gt;Yes, it has L3. The switch that has the SVI and POOL works well with NAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Gi1/0/10 0025.64d9.3d9c dot1x DATA Auth 0A09017600000180B34DA926&lt;BR /&gt;Gi1/0/12 000d.0284.2d39 mab DATA Auth 0A090176000001ACC7435330&lt;BR /&gt;Gi1/0/7 0025.64d9.017c dot1x DATA Auth 0A0901760000000D000195D1&lt;BR /&gt;Gi1/0/13 1803.734c.0a22 dot1x DATA Auth 0A090176000001C7D180A9CE&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 07:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151823#M562853</guid>
      <dc:creator>BASILISGKOGKOS7311</dc:creator>
      <dc:date>2020-09-16T07:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Authentication Succeed but the Windows not obtaining IP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151843#M562855</link>
      <description>&lt;P&gt;If the issue is on that host only most probably it's not a network issue, have you tried to upgrade network interface drivers?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 07:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authentication-succeed-but-the-windows-not-obtaining-ip/m-p/4151843#M562855</guid>
      <dc:creator>Massimo Baschieri</dc:creator>
      <dc:date>2020-09-16T07:50:09Z</dc:date>
    </item>
  </channel>
</rss>

