<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x taking 30 seconds to machine or user authenticate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486058#M570392</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081844"&gt;@laurathaqi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run a capture on ISE, filter on the NAD ip address the host is connected to and run the test again, that may provide some clue as to whether the client or ISE is slow to respond. Check the ISE live logs and look for the latency for communication to the AD DCs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it just the one computer or NAD that is experiencing this issue?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Oct 2021 10:13:08 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-10-14T10:13:08Z</dc:date>
    <item>
      <title>dot1x taking 30 seconds to machine or user authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4485875#M570388</link>
      <description>&lt;P&gt;Dear community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I applied dot1x in a supplicant, authenticating via Cisco ISE. Authentication is successful, but whenever I restart the machine, the first authentication takes exactly 30 seconds to finish.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Show authentication session int f0/1 shows dot1x success, authentication via PEAP. Meaning that its not failing to MAB, thus that timeout delay is out of play.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration applied in the switch are:&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchport access vlan 1&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action authorize vlan 30&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule on ISE checks for the "is user is part of Domain Users or Domain Computers", then authenticate and allow access. Meanwhile the Supplicant is configured to authenticate via dot1x "User or Machine Authenticate".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please orient me towards what kind of delay this might be!? Its a usual behaviors, in meaning that it happens after each restart on my ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion would be highly appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward to hearing from you!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 07:22:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4485875#M570388</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-10-14T07:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x taking 30 seconds to machine or user authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486058#M570392</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081844"&gt;@laurathaqi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run a capture on ISE, filter on the NAD ip address the host is connected to and run the test again, that may provide some clue as to whether the client or ISE is slow to respond. Check the ISE live logs and look for the latency for communication to the AD DCs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it just the one computer or NAD that is experiencing this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 10:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486058#M570392</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-10-14T10:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x taking 30 seconds to machine or user authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486161#M570394</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is happening in all of the computers were I am activating dot1x PEAP at. Without dot1x configuration, it used to work all fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ISE Live Logs Error Messages are usually lack in explanations as all I get is, NAD or Supplicant may not be configured correctly. However, that's quite a wide scope to look at, specially as I doublechecked the configuration ten times now, and its all based on the Administration GUIDE of Cisco ISE.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With further troubleshooting I got another error on the way with information in the Event Logs of Microsoft, in the User Machine when trying to authenticate as following:&lt;STRONG&gt; A fatal error occurred while creating a TLS Client Credentials. The internal Error State is 10013.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I read that this is an issue when the server and the supplicant can not agree in a communication protocol to communicate with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a while now, I am getting the error of: "&lt;STRONG&gt;Windows can’t verify the certificate of the ise1.domainexample.com".&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on google, this message solution is either of the following three: Windows Update bug(build1803 to 1809), ISE Certificate missing or in the Host's NIC to disable the option to "&lt;STRONG&gt;Verify the server's identity by validating the certificate&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Windows 10 is on the OS Build 19043.1237&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. ISE Certificates were generated and signed from the Root CA, and the Root CA is distributed via GPO to Domain Users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Disabling "&lt;STRONG&gt;Verify the server's identity by validating the certificate&lt;/STRONG&gt;" does not seem to be best solution as the certificate its generated and Signed by the Root and it should be working properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am assuming that the logging delay issue has to do with the ones noted in this post. However, I am about to connect with the cliet in the upcoming hours and further troubleshoot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea or suggestion on how to further attack this problem?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Will run a capture, and update you after some hours from now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Laura&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 12:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486161#M570394</guid>
      <dc:creator>laurathaqi</dc:creator>
      <dc:date>2021-10-14T12:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x taking 30 seconds to machine or user authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486207#M570395</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081844"&gt;@laurathaqi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the ISE EAP certificate issued by the same CA as the computers?&lt;/P&gt;
&lt;P&gt;If you take a packet capture on the computer that would provide some useful information.&lt;/P&gt;
&lt;P&gt;If you enable radius and aaa debugs on the switch when the computer/user logs in that would provide a clue.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 12:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-taking-30-seconds-to-machine-or-user-authenticate/m-p/4486207#M570395</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-10-14T12:56:17Z</dc:date>
    </item>
  </channel>
</rss>

