<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x failures in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4535355#M572323</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Maybe you find the solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 21:24:34 GMT</pubDate>
    <dc:creator>Adrian Collantes</dc:creator>
    <dc:date>2022-01-20T21:24:34Z</dc:date>
    <item>
      <title>802.1x failures</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4436134#M568559</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have recently come across an issue in our environment that we hope you can assist us with.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the live logs, we noticed that some devices are failing authentication, leaving them in a disconnected state (i.e. no LAN or Wifi connectivity). We can identify the devices as their identity shows as "host/{deviceName.domain}" whereas when they successfully authenticate they show as {DeviceName.domain}.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes the devices reauthenticate and connects successfully (can take up to 35 minutes although the average is around 1 minute), other times a port bounce is required to get them reconnected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The strange thing is that the issue is intermittent and not linked to a particular device or type.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Background&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Windows 10 20H2 devices&lt;/P&gt;&lt;P&gt;- Cisco 2960x user switches&lt;/P&gt;&lt;P&gt;- Cisco ISE 2.7 patch 2 running on VMWare&lt;/P&gt;&lt;P&gt;- User devices are authenticated using a machine certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Device Error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Event: &lt;/SPAN&gt;&lt;/STRONG&gt;5411 Supplicant stopped responding to ISE&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Failure Reason:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;12934 Supplicant stopped responding to ISE during PEAP tunnel establishment&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Resolution:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Verify that supplicant is configured properly to conduct a full EAP conversation with ISE. Verify that NAS is configured properly to transfer EAP messages to/from supplicant. Verify that supplicant or NAS does not have a short timeout for EAP conversation. Check the network that connects the Network Access Server to ISE. Verify that ISE local server certificate is trusted on supplicant.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Root Cause:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Supplicant stopped responding to ISE during PEAP tunnel establishment&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached a screenshot of the errors and an output of a result, any help would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI a TAC has been opened with Cisco.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 16:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4436134#M568559</guid>
      <dc:creator>InfraISE2020</dc:creator>
      <dc:date>2021-07-20T16:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x failures</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4436320#M568573</link>
      <description>&lt;P&gt;If possible please share the following:&lt;/P&gt;
&lt;P&gt;-Supplicant being used (native/nam)&lt;/P&gt;
&lt;P&gt;-Interface config&lt;/P&gt;
&lt;P&gt;-Supplicant config&lt;/P&gt;
&lt;P&gt;-Switch debugs&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 00:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4436320#M568573</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-07-21T00:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x failures</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4445754#M568905</link>
      <description>&lt;P&gt;You already opened a TAC case - I am closing this thread to prevent duplicate efforts and not waste people's time.&lt;/P&gt;
&lt;P&gt;In the future it would be great if you could post a followup to your thread for what solved the problem so others could learn from it.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 02:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4445754#M568905</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-08-07T02:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x failures</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4535355#M572323</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Maybe you find the solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 21:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-failures/m-p/4535355#M572323</guid>
      <dc:creator>Adrian Collantes</dc:creator>
      <dc:date>2022-01-20T21:24:34Z</dc:date>
    </item>
  </channel>
</rss>

