<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PC user cannot get response from ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294798#M565599</link>
    <description>&lt;P&gt;ISE side that is the place to look -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check the config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG id="yui_3_17_2_1_1613856318028_443"&gt;auth-port 1812 acct-port 1813 &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x" target="_blank"&gt;http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 20 Feb 2021 21:33:21 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-02-20T21:33:21Z</dc:date>
    <item>
      <title>PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294784#M565596</link>
      <description>&lt;P&gt;Hello, The below is configuration on switch3560 and its port for 802.1x. The PC adapter is configured with authentication and enable IEEE 802.1x, but when the PC plugged into the switch port, the PC cannot get any response to promote to enter any credential . Anyone can give some suggestion? Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;aaa group server radius Name-dot1x_auth&lt;BR /&gt;server 10.0.10.21 auth-port 1645 acct-port 1646&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group Name-dot1x_auth&lt;BR /&gt;aaa authorization network default group Name-dot1x_auth&lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting dot1x default start-stop group Name-dot1x_auth&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 10.0.10.21 server-key Cisco123&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;mab request format attribute 32 vlan access-vlan&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/3&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize vlan 10&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf&lt;BR /&gt;radius-server dead-criteria tries 2&lt;BR /&gt;radius-server host 10.0.10.21 auth-port 1645 acct-port 1646&lt;BR /&gt;radius-server key Cisco123&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 21:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294784#M565596</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2021-02-20T21:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294787#M565597</link>
      <description>&lt;P&gt;the config is missed here - Look at ISE LiveLogs what you see there ? on the switch, is the Port come up ?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 21:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294787#M565597</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-20T21:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294794#M565598</link>
      <description>&lt;P&gt;Thank you for your reply. no logs message over there.&lt;/P&gt;&lt;P&gt;Going to Operations----&amp;gt; Radius or Tacacs -----&amp;gt; Live Logs or Live Sessions&lt;/P&gt;&lt;P&gt;Is this a good way to check?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 21:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294794#M565598</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2021-02-20T21:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294798#M565599</link>
      <description>&lt;P&gt;ISE side that is the place to look -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check the config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG id="yui_3_17_2_1_1613856318028_443"&gt;auth-port 1812 acct-port 1813 &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x" target="_blank"&gt;http://www.network-node.com/blog/2015/12/30/switch-configuration-for-dot1x&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 21:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294798#M565599</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-20T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294799#M565600</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/218127"&gt;@eigrpy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it just one user on this switch or all users?&lt;/P&gt;
&lt;P&gt;Is the switch defined as a NAD in ISE? and with the correct shared secret? This might explain why you see nothing in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you say the computer isn't prompting for credentials, what is your supplicant configuration? (provide screenshots). Normally if the computer was joined to AD, you'd pass through the user/computer credentials so you'd never be prompted.&lt;/P&gt;
&lt;P&gt;You can use tcpdump on ISE to determine whether the switch is even attempting to communicate with ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 22:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294799#M565600</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-02-20T22:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294805#M565601</link>
      <description>&lt;P&gt;&lt;SPAN&gt;switchport access vlan 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;switchport mode access&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication event fail action next-method&lt;STRONG&gt;&amp;lt;-NO NEED&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication event server dead action authorize vlan 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication event server dead action authorize voice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication event server alive action reinitialize&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication host-mode multi-domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication order mab dot1x&lt;STRONG&gt;&amp;lt;- NO NEED&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication priority dot1x&lt;STRONG&gt;&amp;lt;-NO NEED&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication port-control auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication periodic&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication timer reauthenticate server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authentication violation restrict&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dot1x pae authenticator&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dot1x timeout tx-period 3&lt;BR /&gt;switch port&amp;nbsp;voice vlan &amp;lt;-need this&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this misconfig&lt;BR /&gt;there are two&amp;nbsp;different method&amp;nbsp;&lt;BR /&gt;1-mab which is make SW fallback to mac when there is no EAPoL&amp;nbsp;&lt;BR /&gt;2-mab 802.1x order when there you want to next&amp;nbsp;method when first method&amp;nbsp;failed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 22:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294805#M565601</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-02-20T22:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294813#M565602</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it just one user on this switch or all users?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;----- there is only one users on the switch(lab)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the switch defined as a NAD in ISE? and with the correct shared secret? This might explain why you see nothing in the logs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;----- the switch is defined as NAD in the ISE&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tcpdump on ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;----- Did not find the switch ip address in this tcpdump file, and the PC have not joined the domain yet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you say the computer isn't prompting for credentials, what is your supplicant configuration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;----- Please see the below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 420px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104761iFD28B79A5BE746D9/image-dimensions/420x511?v=v2" width="420" height="511" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 23:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294813#M565602</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2021-02-20T23:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294814#M565603</link>
      <description>&lt;P&gt;Have you considered doing a pcap on the port and validating you are seeing EAPOL messages?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 23:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294814#M565603</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-02-20T23:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294816#M565604</link>
      <description>&lt;P&gt;Do you make change as i suggest above&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;show auth session interface&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;share the output to see what we get&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 00:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294816#M565604</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-02-21T00:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294826#M565607</link>
      <description>&lt;P&gt;Switch#sh authentication sessions interface fastEthernet 0/5&lt;BR /&gt;No Auth Manager contexts currently exist&lt;BR /&gt;Switch#&lt;BR /&gt;Switch#sh authentication sessions interface fastEthernet 0/3&lt;BR /&gt;No Auth Manager contexts currently exist&lt;BR /&gt;Switch#&lt;BR /&gt;Switch#sh authentication sessions interface fastEthernet 0/2&lt;BR /&gt;No Auth Manager contexts currently exist&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;interface FastEthernet0/2&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt;switchport access vlan 10&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize vlan 10&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 3&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 01:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294826#M565607</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2021-02-21T01:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: PC user cannot get response from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294838#M565610</link>
      <description>&lt;P&gt;dot1x system-auth-control &amp;lt;- this need&lt;BR /&gt;aaa new model &amp;lt;- this need&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Feb 2021 03:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pc-user-cannot-get-response-from-ise/m-p/4294838#M565610</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2021-02-21T03:45:58Z</dc:date>
    </item>
  </channel>
</rss>

