<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x authorization failing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568311#M573393</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47096"&gt;@lmqtechnology&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to the ISE wired guide, ensure you enable accounting, device tracking and anything else you are missing.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ensure you remove port-security, I am not sure private VLAN would be supported either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2022 20:01:31 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-03-10T20:01:31Z</dc:date>
    <item>
      <title>dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568278#M573382</link>
      <description>&lt;P&gt;I have configured dot1x with Cisco ISE and a 3850 switch, however I am unable to get the port to authorize.&amp;nbsp; I check the ISE radius logs and it shows it authenticate successfully, but yet the switch fails to authorize the port..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (&amp;lt;mac_removed&amp;gt;) on Interface GigabitEthernet1/0/43 AuditSessionID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/43&lt;BR /&gt;switchport private-vlan mapping 911 5,11,15,22-23,27,34,42,55,65,71,78,80,100&lt;BR /&gt;switchport mode private-vlan host&lt;BR /&gt;switchport port-security maximum 20&lt;BR /&gt;switchport port-security&lt;BR /&gt;ip arp inspection trust&lt;BR /&gt;authentication host-mode multi-host&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;ip verify source&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568278#M573382</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-03-10T19:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568280#M573383</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47096"&gt;@lmqtechnology&lt;/a&gt; dot1x and port-security on the same interface is not supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you provide the output of "show authentication session interface gigX/X"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568280#M573383</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-10T19:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568286#M573384</link>
      <description>&lt;P&gt;Hi Rob,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards to port-security I believe that used to be the case, but not any more with "multi-host"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/port-security-and-802-1x-ise/td-p/2532438" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/port-security-and-802-1x-ise/td-p/2532438&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;output below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;BR /&gt;Gi1/0/43 &amp;lt;mac_address&amp;gt; dot1x DATA Unauth 0A6434FA000001E1753E5A59&lt;/P&gt;&lt;P&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;A - Applying Policy (multi-line status for details)&lt;BR /&gt;D - Awaiting Deletion&lt;BR /&gt;F - Final Removal in progress&lt;BR /&gt;I - Awaiting IIF ID allocation&lt;BR /&gt;P - Pushed Session&lt;BR /&gt;R - Removing User Profile (multi-line status for details)&lt;BR /&gt;U - Applying User Profile (multi-line status for details)&lt;BR /&gt;X - Unknown Blocker&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;Handle Priority Name&lt;BR /&gt;12 5 dot1xSup&lt;BR /&gt;8 5 dot1x&lt;BR /&gt;13 10 webauth&lt;BR /&gt;11 15 mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568286#M573384</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-03-10T19:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568287#M573385</link>
      <description>&lt;P&gt;can I see&amp;nbsp;&lt;BR /&gt;show auth session &amp;nbsp;of this interface&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568287#M573385</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-03-10T19:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568289#M573386</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47096"&gt;@lmqtechnology&lt;/a&gt; can you append "detail" to see the full output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"show authentication session interface gig1/0/43 &lt;STRONG&gt;detail&lt;/STRONG&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's an 8 year old post, last recommendation is not to use dot1x and port security on the same interface.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:19:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568289#M573386</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-10T19:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568290#M573387</link>
      <description>&lt;P&gt;okay, I havent seen that.. can you provide a reference and link?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;output below:&lt;/P&gt;&lt;P&gt;Interface: GigabitEthernet1/0/43&lt;BR /&gt;IIF-ID: 0x1EAD5FD0&lt;BR /&gt;MAC Address: &amp;lt;removed&amp;gt;&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: Unknown&lt;BR /&gt;User-Name: host/&amp;lt;removed&amp;gt;&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-host&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Common Session ID: 0A6434FA000001E1753E5A59&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x72000040&lt;BR /&gt;Current Policy: POLICY_Gi1/0/43&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;BR /&gt;Security Policy: Should Secure&lt;BR /&gt;Security Status: Link Unsecured&lt;/P&gt;&lt;P&gt;Server Policies:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Method status list:&lt;BR /&gt;Method State&lt;BR /&gt;dot1x Authc Success&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568290#M573387</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-03-10T19:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568291#M573388</link>
      <description>&lt;P&gt;*posted above&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568291#M573388</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-03-10T19:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568295#M573389</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47096"&gt;@lmqtechnology&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Confirmed by Cisco employee, I've also seen other posts on this forum in the last few years by other Cisco employees who confirm the same.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-switch-setup-with-port-security/td-p/3513432" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-switch-setup-with-port-security/td-p/3513432&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of the ISE Live Log for this authenticated session and "show run aaa" from the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568295#M573389</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-10T19:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568296#M573390</link>
      <description>&lt;P&gt;&lt;SPAN&gt;DEFAULT_LINKSEC_POLICY_SHOULD_SECURE &amp;lt;- service template config or not ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:34:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568296#M573390</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-03-10T19:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568299#M573391</link>
      <description>&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ group ISE enable&lt;BR /&gt;aaa authentication dot1x default group radius&lt;BR /&gt;aaa authorization network default group ISE&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;radius server ISE-RADIUS&lt;BR /&gt;address ipv4 10.10.52.13 auth-port 1812 acct-port 1813&lt;BR /&gt;key 7 &amp;lt;removed&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;tacacs server 10.10.52.13&lt;BR /&gt;address ipv4 10.10.52.13&lt;BR /&gt;tacacs-server key 7 &amp;lt;removed&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ISE-RADIUS&lt;BR /&gt;server name ISE-RADIUS&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ISE&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;11017&lt;BR /&gt;RADIUS created a new session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15049&lt;BR /&gt;Evaluating Policy Group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15008&lt;BR /&gt;Evaluating Service Selection Policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11507&lt;BR /&gt;Extracted EAP-Response/Identity&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12500&lt;BR /&gt;Prepared EAP-Request proposing EAP-TLS with challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12625&lt;BR /&gt;Valid EAP-Key-Name attribute received&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12301&lt;BR /&gt;Extracted EAP-Response/NAK requesting to use PEAP instead&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12300&lt;BR /&gt;Prepared EAP-Request proposing PEAP with challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12625&lt;BR /&gt;Valid EAP-Key-Name attribute received&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12302&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response and accepting PEAP as negotiated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12318&lt;BR /&gt;Successfully negotiated PEAP version 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12800&lt;BR /&gt;Extracted first TLS record; TLS handshake started&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12805&lt;BR /&gt;Extracted TLS ClientHello message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12806&lt;BR /&gt;Prepared TLS ServerHello message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12807&lt;BR /&gt;Prepared TLS Certificate message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12808&lt;BR /&gt;Prepared TLS ServerKeyExchange message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12810&lt;BR /&gt;Prepared TLS ServerDone message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12811&lt;BR /&gt;Extracted TLS Certificate message containing client certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12318&lt;BR /&gt;Successfully negotiated PEAP version 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12812&lt;BR /&gt;Extracted TLS ClientKeyExchange message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12813&lt;BR /&gt;Extracted TLS CertificateVerify message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12804&lt;BR /&gt;Extracted TLS Finished message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12801&lt;BR /&gt;Prepared TLS ChangeCipherSpec message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12802&lt;BR /&gt;Prepared TLS Finished message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12816&lt;BR /&gt;TLS handshake succeeded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12310&lt;BR /&gt;PEAP full handshake finished successfully&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12313&lt;BR /&gt;PEAP inner method started&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11521&lt;BR /&gt;Prepared EAP-Request/Identity for inner EAP method&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11522&lt;BR /&gt;Extracted EAP-Response/Identity for inner EAP method&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11806&lt;BR /&gt;Prepared EAP-Request for inner method proposing EAP-MSCHAP with challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11808&lt;BR /&gt;Extracted EAP-Response containing EAP-MSCHAP challenge-response for inner method and accepting EAP-MSCHAP as negotiated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15041&lt;BR /&gt;Evaluating Identity Policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15048&lt;BR /&gt;Queried PIP - Normalised Radius.RadiusFlowType&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15013&lt;BR /&gt;Selected Identity Source - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24431&lt;BR /&gt;Authenticating machine against Active Directory - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24325&lt;BR /&gt;Resolving identity - host/&amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24313&lt;BR /&gt;Search for matching accounts at join point - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24319&lt;BR /&gt;Single matching account found in forest - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24323&lt;BR /&gt;Identity resolution detected single matching account&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24343&lt;BR /&gt;RPC Logon request succeeded - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24470&lt;BR /&gt;Machine authentication against Active Directory is successful - &amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;22037&lt;BR /&gt;Authentication Passed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11824&lt;BR /&gt;EAP-MSCHAP authentication attempt passed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11810&lt;BR /&gt;Extracted EAP-Response for inner method containing MSCHAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11814&lt;BR /&gt;Inner EAP-MSCHAP authentication succeeded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11519&lt;BR /&gt;Prepared EAP-Success for inner EAP method&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12314&lt;BR /&gt;PEAP inner method finished successfully&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12305&lt;BR /&gt;Prepared EAP-Request with another PEAP challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11006&lt;BR /&gt;Returned RADIUS Access-Challenge&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11001&lt;BR /&gt;Received RADIUS Access-Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11018&lt;BR /&gt;RADIUS is re-using an existing session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12304&lt;BR /&gt;Extracted EAP-Response containing PEAP challenge-response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15036&lt;BR /&gt;Evaluating Authorization Policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24209&lt;BR /&gt;Looking up Endpoint in Internal Endpoints IDStore - host/&amp;amp;lt;remove&amp;amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24211&lt;BR /&gt;Found Endpoint in Internal Endpoints IDStore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15048&lt;BR /&gt;Queried PIP - Radius.NAS-Port-Type&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15048&lt;BR /&gt;Queried PIP - EndPoints.LogicalProfile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15048&lt;BR /&gt;Queried PIP - Network Access.AuthenticationStatus&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15016&lt;BR /&gt;Selected Authorization Profile - PermitAccess&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;22081&lt;BR /&gt;Max sessions policy passed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;22080&lt;BR /&gt;New accounting session created in Session cache&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;12306&lt;BR /&gt;PEAP authentication succeeded&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11503&lt;BR /&gt;Prepared EAP-Success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11002&lt;BR /&gt;Returned RADIUS Access-Accept&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 19:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568299#M573391</guid>
      <dc:creator>lmqtechnology</dc:creator>
      <dc:date>2022-03-10T19:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568311#M573393</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47096"&gt;@lmqtechnology&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to the ISE wired guide, ensure you enable accounting, device tracking and anything else you are missing.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ensure you remove port-security, I am not sure private VLAN would be supported either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 20:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568311#M573393</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-10T20:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x authorization failing</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568313#M573394</link>
      <description>&lt;P&gt;Auth is success no issue,&amp;nbsp;&lt;BR /&gt;ISE authz network which mean&amp;nbsp;&lt;BR /&gt;ISE assign VLAN&amp;nbsp;&lt;BR /&gt;or&amp;nbsp;&lt;BR /&gt;ISE send ACL&amp;nbsp;&lt;BR /&gt;or&amp;nbsp;&lt;BR /&gt;ISE send service-template &amp;lt;-here you can either VLAN or ACL&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;can you confirm which one you config in ISE Authz&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 20:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-authorization-failing/m-p/4568313#M573394</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-03-10T20:03:37Z</dc:date>
    </item>
  </channel>
</rss>

