<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows computers authentication failure after a restart or shutdo in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587322#M573918</link>
    <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Apr 2022 14:00:20 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-04-06T14:00:20Z</dc:date>
    <item>
      <title>Windows computers authentication failure after a restart or shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587240#M573905</link>
      <description>&lt;P&gt;The native supplicant is configured for &lt;STRONG&gt;PEAP&lt;/STRONG&gt; and &lt;STRONG&gt;MSCHAPV2&lt;/STRONG&gt;. the authentication method is &lt;STRONG&gt;user or computer authentication&lt;/STRONG&gt;. verify server identity is also checked and we use ISE self signed certificate. it authentication successfully at first but after a restart it fails. to make it successfull we must unplug and plug the cable or disable and enable network adapter. The RADIUS log in ISE shows&amp;nbsp;&lt;STRONG&gt;15039 Rejected per authorization profile&lt;/STRONG&gt;. here below is the configuration on the switch. what did i miss?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The configuration on the switch&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Global Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa group server radius RADIUS_GROUP&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa authentication dot1x default group RADIUS_GROUP&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa authorization network default group RADIUS_GROUP&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa authorization auth-proxy default group RADIUS_GROUP&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa accounting update periodic 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa accounting dot1x default start-stop group RADIUS_GROUP&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa server radius dynamic-author&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa session-id common&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;interface config&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server dead action reinitialize vlan 650&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I have run the test command&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;test aaa group RADIUS_GROUP testuser test password new-model&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;and it returns User successfully authenticated.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 12:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587240#M573905</guid>
      <dc:creator>mikeyasg</dc:creator>
      <dc:date>2022-04-06T12:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers authentication failure after a restart or shutdo</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587251#M573906</link>
      <description>&lt;P&gt;I think the issue that the Client not send EAP-Logoff are this client is Win10?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 12:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587251#M573906</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-06T12:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers authentication failure after a restart or shutdo</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587275#M573909</link>
      <description>&lt;P&gt;Yes. Windows 10 version 21H2&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 13:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587275#M573909</guid>
      <dc:creator>mikeyasg</dc:creator>
      <dc:date>2022-04-06T13:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers authentication failure after a restart or shutdo</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587307#M573913</link>
      <description>&lt;P&gt;"Users who fail authentication remain in the restricted VLAN until the next re-authentication attempt. A port in the restricted VLAN tries to re-authenticate at configured intervals (the default is 60 seconds). If re-authentication fails, the port remains in the restricted VLAN. If re-authentication is successful, the port moves either to the configured VLAN or to a VLAN sent by the RADIUS server. You can disable re-authentication. &lt;STRONG&gt;If you do this, the only way to restart the authentication process is for the port to receive a &lt;U&gt;link down&lt;/U&gt; or &lt;U&gt;EAP logoff&lt;/U&gt; event.&lt;/STRONG&gt; We recommend that you keep re-authentication enabled if a client might connect through a hub. When a client disconnects from the hub, the port might not receive the link down or EAP logoff event."&lt;BR /&gt;&lt;BR /&gt;Solution is re-auth command,&amp;nbsp;&lt;BR /&gt;try add it in one interface monitor interface&amp;amp;client and then apply to all other interface.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 13:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587307#M573913</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-06T13:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers authentication failure after a restart or shutdo</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587313#M573915</link>
      <description>&lt;P&gt;can you share the command?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 13:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587313#M573915</guid>
      <dc:creator>mikeyasg</dc:creator>
      <dc:date>2022-04-06T13:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers authentication failure after a restart or shutdo</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587322#M573918</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/Dot1X_Deployment/Dot1x_Dep_Guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 14:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-computers-authentication-failure-after-a-restart-or/m-p/4587322#M573918</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-06T14:00:20Z</dc:date>
    </item>
  </channel>
</rss>

