<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wired MAB Reauthentication / Retries in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529022#M572112</link>
    <description>&lt;P&gt;I have successfully configured wired MAB with redirect to an ISE Self-Registered Guest Portal. Along with the redirect ACL, I also send a 15 second reauthentication time out. This way the user transitions to full network access quickly after registering a device.&lt;/P&gt;&lt;P&gt;However, I question if such a low timeout value will be problematic with potentially hundreds of devices at a time that get stuck in redirect state. Is there a best practice for reauthenticating MAB clients quickly and minimize re-auth traffic?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jan 2022 18:37:53 GMT</pubDate>
    <dc:creator>neteng1</dc:creator>
    <dc:date>2022-01-10T18:37:53Z</dc:date>
    <item>
      <title>Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529022#M572112</link>
      <description>&lt;P&gt;I have successfully configured wired MAB with redirect to an ISE Self-Registered Guest Portal. Along with the redirect ACL, I also send a 15 second reauthentication time out. This way the user transitions to full network access quickly after registering a device.&lt;/P&gt;&lt;P&gt;However, I question if such a low timeout value will be problematic with potentially hundreds of devices at a time that get stuck in redirect state. Is there a best practice for reauthenticating MAB clients quickly and minimize re-auth traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 18:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529022#M572112</guid>
      <dc:creator>neteng1</dc:creator>
      <dc:date>2022-01-10T18:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529048#M572113</link>
      <description>&lt;PRE&gt;I question if such a low timeout value will be problematic with potentially hundreds of devices at a time that get stuck in redirect state.&lt;/PRE&gt;
&lt;P&gt;This where we design the system based on the device, so ISE can handle all this stuff. ignore best pracitice and security practice may have different side effect on security and access point of view - this is my personal suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is best practice posted by cisco :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is good presentation help you :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECSEC-3416.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECSEC-3416.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 19:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529048#M572113</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-01-10T19:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529073#M572114</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/856468"&gt;@neteng1&lt;/a&gt; if you are doing wired guest, the user will stay in the redirection state until they've registered/authenticated to the guest portal. No need for a 15sec reauthentication timer, once the user has successfully registered/authenticated in the guest portal a Change of Authorisation (CoA) would be initiated and the user would be re-authorised again, the user would be authorised against a different authorisation rule. &lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 20:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529073#M572114</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-01-10T20:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529076#M572115</link>
      <description>&lt;P&gt;Thank you. I think I have problem with my CoA. I see the following error in live logs. I'll have to troubleshoot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event 5417 Dynamic Authorization failed&lt;BR /&gt;Failure Reason 11213 No response received from Network Access Device after sending a Dynamic Authorization request&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 20:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529076#M572115</guid>
      <dc:creator>neteng1</dc:creator>
      <dc:date>2022-01-10T20:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529080#M572116</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/856468"&gt;@neteng1&lt;/a&gt; check your switch config and ensure the following is configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;&lt;SPAN style="left: 120px; top: 1075.8px; font-size: 18.4008px; font-family: serif; transform: scaleX(1.02108);"&gt;aaa server radius dynamic-author&lt;BR /&gt; client &amp;lt;ise psn 1&amp;gt; server-key &amp;lt;shared secret&amp;gt;&lt;BR /&gt; client &amp;lt;ise psn 2&amp;gt; server-key &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face="lucida sans unicode,lucida sans"&gt;&lt;SPAN style="left: 124.16px; top: 1127.4px; font-size: 18.4008px; font-family: serif; transform: scaleX(0.908348);"&gt;&lt;SPAN style="left: 120px; top: 1075.8px; font-size: 18.4008px; font-family: serif; transform: scaleX(1.02108);"&gt;&amp;lt;shared secret&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 20:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529080#M572116</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-01-10T20:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Wired MAB Reauthentication / Retries</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529111#M572118</link>
      <description>&lt;P&gt;I did have that config entered. I found out my problem was an F5 rule, working as expected now. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 21:20:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-mab-reauthentication-retries/m-p/4529111#M572118</guid>
      <dc:creator>neteng1</dc:creator>
      <dc:date>2022-01-10T21:20:58Z</dc:date>
    </item>
  </channel>
</rss>

