<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic VLAN Assignment in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4501938#M571030</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently implementing dynamic VLAN assignment for both our 802.1X clients &amp;amp; profiled devices via MAB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The condition matches the device in ISE with the full summary report showing "authentication succeeded" , authorization profile selected, Radius Access-Accept returned &amp;amp; VLAN attributes visible under "result".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I hop over to the switch and run "show auth session interface [] detail" the status shows as "unath" with there no change in VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone experienced this issue before or know when to look for troubleshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already made sure Dynamic Author is configured on the switch with my clients. Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 12 Nov 2021 10:27:35 GMT</pubDate>
    <dc:creator>connor.jaques</dc:creator>
    <dc:date>2021-11-12T10:27:35Z</dc:date>
    <item>
      <title>Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4501938#M571030</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently implementing dynamic VLAN assignment for both our 802.1X clients &amp;amp; profiled devices via MAB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The condition matches the device in ISE with the full summary report showing "authentication succeeded" , authorization profile selected, Radius Access-Accept returned &amp;amp; VLAN attributes visible under "result".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I hop over to the switch and run "show auth session interface [] detail" the status shows as "unath" with there no change in VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone experienced this issue before or know when to look for troubleshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already made sure Dynamic Author is configured on the switch with my clients. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 10:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4501938#M571030</guid>
      <dc:creator>connor.jaques</dc:creator>
      <dc:date>2021-11-12T10:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4502252#M571036</link>
      <description>&lt;P&gt;Maybe a COA issue? &amp;nbsp;I notice these tend to pop up a lot. What switch model and version are you running? &amp;nbsp;Run a debug on the switch to see if your receiving the COA. I believe the command is “debug aaa COA”&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 20:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4502252#M571036</guid>
      <dc:creator>BryanHefner2568</dc:creator>
      <dc:date>2021-11-12T20:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4503718#M571076</link>
      <description>&lt;P&gt;Have you verified that the VLAN is created on the switch? If so, are you using VLAN name in your auth profile? Make sure it matches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like its possibly failing AuthZ. Check your epm logs to see if you can find some helpful information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 18:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4503718#M571076</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2021-11-16T18:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504082#M571097</link>
      <description>&lt;P&gt;VLAN name is used in the auth profile and does exist on the switch as an exact match. I'll enable EPM logging and see if that produces anything of help then revert back. Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 09:18:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504082#M571097</guid>
      <dc:creator>connor.jaques</dc:creator>
      <dc:date>2021-11-17T09:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504086#M571098</link>
      <description>&lt;P&gt;We are running C9300's on version 16.12. Debug Coa gives me a "Authc fail. Authc failure reason: Cred Fail". This log is only produced when applying my own authorization policy as a pose to the default "permit access".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 09:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504086#M571098</guid>
      <dc:creator>connor.jaques</dc:creator>
      <dc:date>2021-11-17T09:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504181#M571104</link>
      <description>&lt;P&gt;This tells you what the issue is.&amp;nbsp; Failed Authentication due to credentials.&amp;nbsp; Default permit access policy that you use does not require a COA, and is probably providing access whether or not you authenticate properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you provide a screen grab of your Live Logs, showing just the specific device that you are authenticating?&amp;nbsp; And also once that is displayed in the live logs, can you click on the paper icon to show the authentication process for that devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Excellent guide on troubleshooting authentications in ISE:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-troubleshoot-ise-failed-authentications-amp/ta-p/3630960" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-troubleshoot-ise-failed-authentications-amp/ta-p/3630960&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 12:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504181#M571104</guid>
      <dc:creator>BryanHefner2568</dc:creator>
      <dc:date>2021-11-17T12:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VLAN Assignment in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504217#M571107</link>
      <description>&lt;P&gt;Thanks Bryan, will review that link. Agree it appears to be a CoA problem here. I've copied the details below from the logs in ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;11001&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;11017&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;RADIUS created a new session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;11027&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Detected Host Lookup UseCase (Service-Type = Call Check (10))&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15049&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Evaluating Policy Group&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15008&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Evaluating Service Selection Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15048&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Queried PIP - Radius.NAS-IP-Address&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15041&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Evaluating Identity Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15013&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Selected Identity Source - Internal Endpoints&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;24209&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Looking up Endpoint in Internal Endpoints IDStore - 7C:D3:0A:20:C0:28&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;24211&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Found Endpoint in Internal Endpoints IDStore&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;22037&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Authentication Passed&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;24715&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15036&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Evaluating Authorization Policy&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;11055&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;User name change detected for the session. Attributes for the session will be removed from the cache&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;15016&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Selected Authorization Profile - WORKSTATION&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;24209&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Looking up Endpoint in Internal Endpoints IDStore - 7C:D3:0A:20:C0:28&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;24211&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Found Endpoint in Internal Endpoints IDStore&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;11002&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Returned RADIUS Access-Accept&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 17 Nov 2021 13:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-vlan-assignment-in-ise/m-p/4504217#M571107</guid>
      <dc:creator>connor.jaques</dc:creator>
      <dc:date>2021-11-17T13:27:41Z</dc:date>
    </item>
  </channel>
</rss>

