<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mab authentication loses connection to printer after days/weeks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179866#M563664</link>
    <description>&lt;P&gt;Thanks for your quick reply. I also had that thought.&lt;/P&gt;&lt;P&gt;The weird thing is show auth sess int g1/0/19 det shows this. Only thing which is different from other ports is, that IPv4 address is empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/19&lt;BR /&gt;MAC Address: 9c93.1234.5678&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: 9c9312345678&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: 28800s (local), Remaining: 966s&lt;BR /&gt;Timeout action: Reauthenticate&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: AC163FA000000470DE5E0AFA&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x28000464&lt;BR /&gt;Current Policy: POLICY_Gi1/0/19&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also MAC is shown with show mac command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log from NAC:&lt;/P&gt;&lt;P&gt;Mac User Radius Access granted Access time Access type Authentification Switch NAS IP NAS Port NAS Port ID VLAN&lt;BR /&gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 16:06:56 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 08:05:47 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 00:04:35 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I remove the NAC config and shut no shut the Port the MAC is gone. Then you need to reboot the printer (true, printer is in sleep mode at that time) to&amp;nbsp; get it back online. After that you can apply the NAC config again and everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current state after reboot and applying NAC again:&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/19&lt;BR /&gt;MAC Address: 9c93.1234.5678&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.22.x.xxx&lt;BR /&gt;User-Name: 9c9312345678&lt;/P&gt;&lt;P&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: 28800s (local), Remaining: 28428s&lt;BR /&gt;Timeout action: Reauthenticate&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: AC163FA00000047DE920BE37&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x14000469&lt;BR /&gt;Current Policy: POLICY_Gi1/0/19&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 09:37:47 GMT</pubDate>
    <dc:creator>Rainer Woerthwein</dc:creator>
    <dc:date>2020-11-06T09:37:47Z</dc:date>
    <item>
      <title>Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179318#M563646</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;I'm facing a really strange problem with NAC.&lt;/P&gt;&lt;P&gt;We use a NAC software (not ISE) to perform port authentication. Windows Clients use dot1x, printers and phones Mab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From time to time our Xerox printers are losing the connection, no ping etc. Windows clients and phones are fine.&lt;/P&gt;&lt;P&gt;On the switches and in the NAC tool everything looks fine.&lt;/P&gt;&lt;P&gt;We are using 2960X with&amp;nbsp;15.2(4)E8.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;sh auth sess:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Gi1/0/19 9c93.1234.5678 mab DATA Auth AC163FA000000xxxxxxxxxxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port config as following:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface GigabitEthernet1/0/19&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport access vlan xx&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport mode access&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switchport voice vlan xx&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;queue-set 2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication control-direction in&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server dead action authorize &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication host-mode multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication order dot1x mab&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication periodic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer reauthenticate 28800&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication violation replace&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mab&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mls qos trust device cisco-phone&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mls qos trust cos&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x pae authenticator&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout supp-timeout 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast edge&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree bpduguard enable&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;end&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh inter statu&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Gi1/0/19 connected VID a-full a-1000 10/100/1000BaseTX&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Where VID is issued correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;shut, no shut doesn't help. Only thing that helps is removing NAC config from switchport and reboot the printer.&lt;/P&gt;&lt;P&gt;After that I can reenable NAC config and it's still fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what's going on here? Please let me know if I should provide more information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 13:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179318#M563646</guid>
      <dc:creator>Rainer Woerthwein</dc:creator>
      <dc:date>2020-11-05T13:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179391#M563649</link>
      <description>&lt;P&gt;Sounds like the printer may be going to sleep and then your reauthentication is not able to complete because the printer's MAC address timed out due to no activity for a while.&amp;nbsp; For MAB to work, the switch has to see some traffic from the device to grab the source MAC address.&amp;nbsp; During the time when the issue is happening, do the "show authentication session int gx/y detail" and see what is shown for the MAC address or username.&amp;nbsp; It is likely showing "unknown".&amp;nbsp; And if it is unknown, the switch cannot even attempt authentication to your NAC system.&amp;nbsp; So in your NAC system logs, you probably don't see any of the reauthentication attempts once it is in that state.&amp;nbsp; If that is the issue, then check the printer for any settings related to going to sleep and turning the NIC off.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 15:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179391#M563649</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-11-05T15:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179866#M563664</link>
      <description>&lt;P&gt;Thanks for your quick reply. I also had that thought.&lt;/P&gt;&lt;P&gt;The weird thing is show auth sess int g1/0/19 det shows this. Only thing which is different from other ports is, that IPv4 address is empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/19&lt;BR /&gt;MAC Address: 9c93.1234.5678&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: 9c9312345678&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: 28800s (local), Remaining: 966s&lt;BR /&gt;Timeout action: Reauthenticate&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: AC163FA000000470DE5E0AFA&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x28000464&lt;BR /&gt;Current Policy: POLICY_Gi1/0/19&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also MAC is shown with show mac command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log from NAC:&lt;/P&gt;&lt;P&gt;Mac User Radius Access granted Access time Access type Authentification Switch NAS IP NAS Port NAS Port ID VLAN&lt;BR /&gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 16:06:56 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 08:05:47 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;BR /&gt;9C-93-12-34-56-78 9c9312345678 localhost yes 2020-11-05 00:04:35 LOW PAP authentication 172.22.xx.xxx 172.22.xx.xxx 50119 GigabitEthernet1/0/19 &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I remove the NAC config and shut no shut the Port the MAC is gone. Then you need to reboot the printer (true, printer is in sleep mode at that time) to&amp;nbsp; get it back online. After that you can apply the NAC config again and everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current state after reboot and applying NAC again:&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/19&lt;BR /&gt;MAC Address: 9c93.1234.5678&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.22.x.xxx&lt;BR /&gt;User-Name: 9c9312345678&lt;/P&gt;&lt;P&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: 28800s (local), Remaining: 28428s&lt;BR /&gt;Timeout action: Reauthenticate&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: AC163FA00000047DE920BE37&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x14000469&lt;BR /&gt;Current Policy: POLICY_Gi1/0/19&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;Vlan Group: Vlan: &amp;lt;correct VID&amp;gt;&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 09:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4179866#M563664</guid>
      <dc:creator>Rainer Woerthwein</dc:creator>
      <dc:date>2020-11-06T09:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180041#M563667</link>
      <description>&lt;P&gt;Check for firmware/software updates for your printer.&amp;nbsp; See if there are any settings that tell the printer to sleep and turn networking off.&amp;nbsp; My guess is that the issue is with the printer and how it handles network connectivity or wake events.&amp;nbsp; What specific model printer is the Xerox?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 15:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180041#M563667</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-11-06T15:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180090#M563668</link>
      <description>&lt;P&gt;If you don't find any options on the printer try lowering the DHCP Lease time causing the printer to renew it's IP-Address and therefore not go into silent mode. If it doesn't run DHCP try configuring your switchports to reauthenticate once in a while causing the device to generate some traffic as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 17:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180090#M563668</guid>
      <dc:creator>Nicolai Borchorst</dc:creator>
      <dc:date>2020-11-06T17:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180540#M563687</link>
      <description>&lt;P&gt;Also consider configuring 802.1X on your printers so they can authenticate properly when they do wake up rather than relying on MAB.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2020 17:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4180540#M563687</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-11-08T17:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mab authentication loses connection to printer after days/weeks</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4268334#M564614</link>
      <description>&lt;P&gt;Sorry for my late reply was ooo for a while.&lt;/P&gt;&lt;P&gt;Thanks for all your suggestions - now I'm sure it's only a printer issue. All other MAB devices like Cisco phones are working.&lt;/P&gt;&lt;P&gt;I'll try both - lowering DHCP lease time and switching to dot1x.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 10:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-loses-connection-to-printer-after-days-weeks/m-p/4268334#M564614</guid>
      <dc:creator>Rainer Woerthwein</dc:creator>
      <dc:date>2021-01-07T10:51:34Z</dc:date>
    </item>
  </channel>
</rss>

