<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC not working on 1 Desk, works everywhere else. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620583#M575077</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think we may have hit this bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of the issues so have have been on member switches of a switch stack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv93417" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv93417&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you think?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
    <pubDate>Mon, 30 May 2022 14:18:41 GMT</pubDate>
    <dc:creator>Anthony O'Reilly</dc:creator>
    <dc:date>2022-05-30T14:18:41Z</dc:date>
    <item>
      <title>NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4617393#M574952</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a strange one for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have deployed a two-node ISE 2.7 Patch 6 cluster. We have deployed NAC successfully about 7 months ago. We have a few issues now and again but all is working well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recently there are a number of desks where NAC has stopped working regardless of who uses that desk. NAC works for the users on other desks without any problems. When the go back to the "Desk X", they don't get any connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the ISE logs, I can see the user when user logged in at Desk 1&amp;nbsp;@ 09:25 (see screen shot "NAC1.jpg") successfully and got network access. When the user went to "Desk X", I can see entries in ISE at 09:52, 09:59, 10:05, these three entries&amp;nbsp;shows a successful authentication with a session, however on the users laptop it states that there is no internet. The three entries is where we tried to eliminate the docking station, network cables and the switchport as a root cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Troubleshooting steps at Desk X:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;User logged in at this desk at 09:52 using the docking station, no internet. ISE reports successful authentication with a session. User is patched into switchport Gi3/0/4.&lt;/LI&gt;
&lt;LI&gt;User logged in at this desk at 09:59 using no docking station, no internet.&amp;nbsp;ISE reports successful authentication with a session.&amp;nbsp;User is patched into switchport Gi3/0/4.&lt;/LI&gt;
&lt;LI&gt;Moved patch cable from switchport Gi3/0/4 on STACK3 to Gi3/0/9&amp;nbsp;(same config) on same switch. The switch thinks that there is nothing connected&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;GigabitEthernet3/0/4 is up, &lt;STRONG&gt;line protocol is down (notconnect)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; Hardware is Gigabit Ethernet, address is 00bc.6094.2404 (bia 00bc.6094.2404)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; Description: ### User Access Port ###&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Move cable from Gi3/0/4 to Gi3/0/9, same issue&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;GigabitEthernet3/0/9 is up, &lt;STRONG&gt;line protocol is down (notconnect)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; Hardware is Gigabit Ethernet, address is 00bc.6094.2409 (bia 00bc.6094.2409)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp; Description: ### User Access Port ###&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Removed NAC config, port came up and User logged in successfully, no issues with switchport or cabling.&lt;/LI&gt;
&lt;LI&gt;Added NAC config, port came up and User logged in and successfully authenticated and logged into the network.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Switch config:&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;template PORT-AUTH-TEMPLATE&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;mab&lt;BR /&gt;access-session host-mode multi-domain&lt;BR /&gt;access-session control-direction in&lt;BR /&gt;access-session closed&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;service-policy type control subscriber INT-AUTH-POLICY&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/0/9&lt;BR /&gt;description ### User Access Port ###&lt;BR /&gt;switchport access vlan XX&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan YY&lt;BR /&gt;srr-queue bandwidth share 10 10 60 20&lt;BR /&gt;srr-queue bandwidth shape 10 0 0 0&lt;BR /&gt;queue-set 2&lt;BR /&gt;priority-queue out&lt;BR /&gt;mls qos trust device cisco-phone&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;dot1x timeout tx-period 60&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;storm-control broadcast level 30.00 25.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;storm-control action trap&lt;BR /&gt;source template PORT-AUTH-TEMPLATE&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input AutoQoS-Police-CiscoPhone&lt;BR /&gt;end&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regardless of what user uses that desk, it will not work. A fix for this is to remove NAC and re add it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switch is a 2960X-48FPD-L and is a member of a stack which has 3 switches in it. The software version is: 15.2(4)E6.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is occurring randomly across desks across numerous sites for the customer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorAnthonyOReilly_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorAnthonyOReilly_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 10:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4617393#M574952</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-25T10:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4618937#M575001</link>
      <description>&lt;P class="lia-align-justify"&gt;HI&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;&amp;nbsp;1st&lt;/STRONG&gt; ... about the &lt;STRONG&gt;aaa accounting update newinfo periodic 5&lt;/STRONG&gt; command, consider the use of &lt;STRONG&gt;1440&lt;/STRONG&gt; or &lt;STRONG&gt;2880&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;2nd&lt;/STRONG&gt; ... during the issue what is the result of the following command:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;#show mac address-table interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;BR /&gt;#show ip device tracking interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;BR /&gt;#show authentication sessions interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 04:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4618937#M575001</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-27T04:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4618990#M575007</link>
      <description>&lt;P&gt;I think device-tracking may be missing from the config. As Marcelo mentioned, let's see the output of those commands.&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 05:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4618990#M575007</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-05-27T05:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619095#M575015</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;#show mac address-table interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;There was nothing showing in the mac address-table for this interface. If I moved the device to another interface, it was in the mac address-table.&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;#show ip device tracking interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;I didn't run this at the time, I will the next time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;#show authentication sessions interface &lt;EM&gt;&lt;U&gt;G3/0/4&lt;/U&gt;&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;There was nothing in the output for this command, it was as if there was nothing patched into the switch port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I plugged a phone into the port, the phone would get power. There was no entry for the phone in the #sh cdp nei command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ran a shut and no shut on the ports that were having issues. I will wait for the next interface that has this issues and report back. I will test this command&amp;nbsp;&lt;STRONG&gt;aaa accounting update newinfo periodic 1440&amp;nbsp;&lt;/STRONG&gt;on three 2960 switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;Device tracking is on this, it is configured globally using this command&amp;nbsp;&lt;STRONG&gt;ip device tracking probe delay 10&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This is the result from the tracking on the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;STACK01#sh ip device tracking all&lt;BR /&gt;Global IP Device Tracking for clients = Enabled&lt;BR /&gt;Global IP Device Tracking Probe Count = 3&lt;BR /&gt;Global IP Device Tracking Probe Interval = 30&lt;BR /&gt;Global IP Device Tracking Probe Delay Interval = 10&lt;BR /&gt;-----------------------------------------------------------------------------------------------&lt;BR /&gt;IP Address MAC Address Vlan Interface Probe-Timeout State Source&lt;BR /&gt;-----------------------------------------------------------------------------------------------&lt;BR /&gt;1.1.1.2 xxxx.xxxx.xxx 10 GigabitEthernet2/0/3 30 ACTIVE ARP&lt;BR /&gt;1.1.1.4&amp;nbsp;xxxx.xxxx.xxx 10 GigabitEthernet2/0/33 30 ACTIVE ARP&lt;BR /&gt;1.1.2.2&amp;nbsp;xxxx.xxxx.xxx 24 GigabitEthernet2/0/14 30 ACTIVE ARP&lt;BR /&gt;1.1.1.8 xxxx.xxxx.xxx 10 GigabitEthernet1/0/1 30 ACTIVE ARP&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 08:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619095#M575015</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-27T08:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619259#M575029</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st:&lt;/STRONG&gt; the "&lt;STRONG&gt;periodic&lt;/STRONG&gt;" of the &lt;STRONG&gt;aaa accouting update newinfo &lt;U&gt;periodic [1440 or 2880]&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;ensure that the &lt;STRONG&gt;RADIUS Accounting&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;Interim Accounting Update&lt;/STRONG&gt;) is sent to the &lt;STRONG&gt;ISE Node&lt;/STRONG&gt;&amp;nbsp;(regardless if the &lt;STRONG&gt;SW&lt;/STRONG&gt; observes a change for the &lt;STRONG&gt;Active Session&lt;/STRONG&gt; or not) every &lt;STRONG&gt;1 or 2 days&lt;/STRONG&gt;, If &lt;STRONG&gt;ISE&lt;/STRONG&gt; fails to receive &lt;STRONG&gt;Interim Accounting Message&lt;/STRONG&gt;&amp;nbsp;for an &lt;STRONG&gt;Endpoint Session&lt;/STRONG&gt; beyond &lt;STRONG&gt;5 days&lt;/STRONG&gt;, &lt;STRONG&gt;ISE&lt;/STRONG&gt; will &lt;U&gt;stop&lt;/U&gt; maintaining the &lt;STRONG&gt;Session&lt;/STRONG&gt; for that &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;. A "&lt;STRONG&gt;periodic = 5&lt;/STRONG&gt;" (&lt;STRONG&gt;5 sec&lt;/STRONG&gt;) generates a lot of &lt;STRONG&gt;Interim Accounting Update&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd:&lt;/STRONG&gt; the "&lt;STRONG&gt;device tracking&lt;/STRONG&gt;" is enabled via the &lt;STRONG&gt;(config)# ip device tracking&lt;/STRONG&gt; (although it is &lt;U&gt;enable by default&lt;/U&gt; in &lt;STRONG&gt;15.x+&lt;/STRONG&gt;), the &lt;STRONG&gt;(config)# ip device tracking probe delay &lt;U&gt;10&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;does not allow a &lt;STRONG&gt;SW&lt;/STRONG&gt; to send a &lt;STRONG&gt;Probe&lt;/STRONG&gt; for &lt;U&gt;10sec&lt;/U&gt; when it detects a &lt;STRONG&gt;Link UP/Flap&lt;/STRONG&gt; (a good practice).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3rd:&lt;/STRONG&gt; when you said "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;There was &lt;U&gt;nothing showing in the mac address-table&lt;/U&gt; for this interface ...&lt;/EM&gt; ", in other words, if you check the &lt;STRONG&gt;#show logging&lt;/STRONG&gt; info, then something like this appears? I mean the "&lt;EM&gt;&lt;U&gt;Unknown MAC&lt;/U&gt;&lt;/EM&gt;":&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;EM&gt;May 27 XX:XX:XX.XXX: %AUTHMGR-5-START: Starting 'dot1x' for client ("&lt;U&gt;Unknown Mac&lt;/U&gt;") on Interface &lt;U&gt;G3/0/4&lt;/U&gt; AuditSessionID XXXXXXXXXXXXXXXXXXXXXXXX&lt;/EM&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 13:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619259#M575029</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-27T13:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619281#M575034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your quick response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The switches in one site are now configured as&amp;nbsp;&lt;STRONG&gt;aaa accouting update newinfo&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;periodic 2880&amp;nbsp;&lt;/U&gt;&lt;/STRONG&gt;I am currently monitoring them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. The ip device tracking command has not changed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. There is definitely nothing in the logs for Unknown for our testing on Gi3/0/4.&amp;nbsp;I've searched logs for Unknown and unknown across all our switches looking for other examples and I don't have any entries for it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there anything else I can check?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 13:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619281#M575034</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-27T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619411#M575038</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;in other words:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; the&amp;nbsp;&lt;STRONG&gt;MAC Addr&amp;nbsp;Table&lt;/STRONG&gt; is empty for &lt;STRONG&gt;G3/0/4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; the &lt;STRONG&gt;Starting 'dot1x' for client&lt;/STRONG&gt; on &lt;STRONG&gt;G3/0/4&lt;/STRONG&gt; is not appearing on the &lt;STRONG&gt;show logging&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3.&amp;nbsp;&lt;/STRONG&gt;you are having problems with &lt;STRONG&gt;DeskX&lt;/STRONG&gt;, even if you change the &lt;STRONG&gt;SW Port&lt;/STRONG&gt; (&lt;STRONG&gt;G3/0/4&lt;/STRONG&gt;&amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;G3/0/9&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;My question:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At &lt;STRONG&gt;NAC1.JPG&lt;/STRONG&gt; (your &lt;STRONG&gt;1st&lt;/STRONG&gt; image), &lt;STRONG&gt;ISE&lt;/STRONG&gt; received an &lt;STRONG&gt;EAP-TLS&lt;/STRONG&gt; packet from &lt;STRONG&gt;DeskX&lt;/STRONG&gt;, but there is no&amp;nbsp;&lt;STRONG&gt;Starting 'dot1x' for client on G3/0/4&lt;/STRONG&gt; on &lt;STRONG&gt;show logging&lt;/STRONG&gt;&amp;nbsp;&lt;U&gt;and&lt;/U&gt;&amp;nbsp;no &lt;STRONG&gt;MAC&lt;/STRONG&gt; on the &lt;STRONG&gt;MAC Addr Table&lt;/STRONG&gt; on &lt;STRONG&gt;G3/0/4&lt;/STRONG&gt; ... did you check if the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; sent the packet to the&amp;nbsp;&lt;STRONG&gt;SW&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;debug dot1x all&lt;/STRONG&gt;) and the &lt;STRONG&gt;SW&lt;/STRONG&gt; sent the the packet to &lt;STRONG&gt;ISE&lt;/STRONG&gt; (&lt;STRONG&gt;debug radius&lt;/STRONG&gt;)?&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 17:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619411#M575038</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-27T17:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619458#M575040</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the&amp;nbsp;&lt;STRONG&gt;MAC Addr&amp;nbsp;Table&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is empty for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;G3/0/4 &lt;FONT color="#FF0000"&gt;This is correct&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Starting 'dot1x' for client&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;G3/0/4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is not appearing on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;show logging &lt;FONT color="#FF0000"&gt;I am not sure on this at the time the log buffer was full and I cleared it to save me strolling down. There were four ports in total on this switch, I checked the logs for Gi3/0/4, Gi3/0/9, Gi2/0/6 and Gi2/0/16&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3.&amp;nbsp;&lt;/STRONG&gt;you are having problems with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DeskX&lt;/STRONG&gt;, even if you change the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SW Port&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;G3/0/4&lt;/STRONG&gt;&amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;G3/0/9&lt;/STRONG&gt;). &lt;FONT color="#FF0000"&gt;This desk has two ports that had the same symptoms.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;My question:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NAC1.JPG&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(your&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;image),&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;received an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;EAP-TLS&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;packet from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;DeskX&lt;/STRONG&gt;, but there is no&amp;nbsp;&lt;STRONG&gt;Starting 'dot1x' for client on G3/0/4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;show logging&lt;/STRONG&gt;&amp;nbsp;&lt;U&gt;and&lt;/U&gt;&amp;nbsp;no&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;MAC&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;MAC Addr Table&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;G3/0/4&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;... did you check if the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Endpoint&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;sent the packet to the&amp;nbsp;&lt;STRONG&gt;SW&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;debug dot1x all&lt;/STRONG&gt;) and the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SW&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;sent the the packet to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(&lt;STRONG&gt;debug radius&lt;/STRONG&gt;)?&amp;nbsp;&lt;FONT color="#FF0000"&gt;Unfortunately, I didn't do any debugs, I will for the next one. There are alot of people due on site on Monday and I will be ready to collect logs and debugs. There was no&amp;nbsp;&lt;STRONG&gt;Starting 'dot1x' for client&amp;nbsp;&lt;/STRONG&gt;in the logs. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;FONT color="#000000"&gt;I will hopefully have a live example for you on Monday, fingers crossed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Thanks for all your help, much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 20:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4619458#M575040</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-27T20:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620436#M575062</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a good example this morning. I was able to replicate the issue whether the laptop was on a docking station or plugged directly into the laptop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Laptop is in port Gi1/0/18, there two commands were run after the device was in the port after about 50 seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;SW2#sh access-session int gi1/0/18&lt;BR /&gt;No sessions match supplied criteria.&lt;BR /&gt;&lt;BR /&gt;Runnable methods list:&lt;BR /&gt;Handle Priority Name&lt;BR /&gt;6 5 dot1x&lt;BR /&gt;17 10 mab&lt;BR /&gt;15 15 webauth&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;SW#sh mac address-table int gi1/0/18&lt;BR /&gt;Mac Address Table&lt;BR /&gt;-------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Vlan Mac Address Type Ports&lt;BR /&gt;---- ----------- -------- -----&lt;/PRE&gt;
&lt;PRE&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/18&lt;BR /&gt;description ### User Access Port ###&lt;BR /&gt;switchport access vlan XX&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan YY&lt;BR /&gt;srr-queue bandwidth share 10 10 60 20&lt;BR /&gt;srr-queue bandwidth shape 10 0 0 0&lt;BR /&gt;queue-set 2&lt;BR /&gt;priority-queue out&lt;BR /&gt;mls qos trust device cisco-phone&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;dot1x timeout tx-period 60&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;storm-control broadcast level 30.00 25.00&lt;BR /&gt;storm-control action shutdown&lt;BR /&gt;storm-control action trap&lt;BR /&gt;source template PORT-AUTH-TEMPLATE&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input AutoQoS-Police-CiscoPhone&lt;BR /&gt;end&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Debug dot1x all and debug radius are attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can do another test again if you wish.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 10:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620436#M575062</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-30T10:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620559#M575071</link>
      <description>&lt;P&gt;This is a good one for TAC since it sounds like you are under a time pressure to get it fixed.&lt;/P&gt;
&lt;P&gt;It sounds like it could be a switch bug... consider upgrading the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 13:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620559#M575071</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-05-30T13:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620583#M575077</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think we may have hit this bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of the issues so have have been on member switches of a switch stack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv93417" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv93417&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you think?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 14:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620583#M575077</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-30T14:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620748#M575083</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;interesting and &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv93417" target="_blank" rel="noopener"&gt;CSCvv93417&amp;nbsp;2960x stack Member Switch fails wired dot1x; MasterSwitch passes dot1x using the same configs&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;could be the cause, are you able to test your &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; in a &lt;STRONG&gt;SW&lt;/STRONG&gt; without a stack configuration?&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;As you said: "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;The Switch is a 2960X-48FPD-L and is a &lt;STRONG&gt;Member&lt;/STRONG&gt; of a stack which has 3 Switches in it. The software version is: 15.2(4)E6...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp; I checked the &lt;STRONG&gt;EAP&lt;/STRONG&gt; and &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; debug:&lt;/P&gt;
&lt;PRE&gt;ISE IP       "10.10.10.100"&lt;BR /&gt;NAS IP       "10.10.1.1"&lt;BR /&gt;Framed-MTU   "1500"&lt;BR /&gt;Endpoint IP  "10.10.10.10"&lt;BR /&gt;EndPoint MAC "48-2A-E3-3E-72-04"&lt;/PRE&gt;
&lt;P&gt;I'm able to verify the &lt;STRONG&gt;Access-Request&lt;/STRONG&gt; and &lt;STRONG&gt;Access-Challenge&lt;/STRONG&gt; from/to &lt;STRONG&gt;NAD&lt;/STRONG&gt; to/from &lt;STRONG&gt;ISE&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Attention to:&lt;/P&gt;
&lt;PRE&gt;May 30 10:40:03.385: RADIUS/ENCODE(00000000):Orig. &lt;U&gt;component type = Invalid&lt;/U&gt;&lt;/PRE&gt;
&lt;P&gt;please take a look at&amp;nbsp;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCuu75107" target="_blank" rel="noopener"&gt;CSCuu75107&amp;nbsp;2960 - traceback with EAP Authentication timeout&lt;/A&gt;., although there is no &lt;STRONG&gt;RESULT_OVERRIDE&lt;/STRONG&gt; in your logs.&lt;BR /&gt;Attention to:&lt;/P&gt;
&lt;PRE&gt;May 30 10:40:02.839: RADIUS/DECODE: EAP-Message fragments, 253+253+253+249, total 1008 bytes&lt;/PRE&gt;
&lt;P&gt;always good to double check &lt;STRONG&gt;Fragmentation/MTU&lt;/STRONG&gt; end-to-end (specially if you have a &lt;STRONG&gt;FW&lt;/STRONG&gt; between) ... just in case : )&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 18:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620748#M575083</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-05-30T18:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620790#M575089</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is excellent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The next steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Upgrade the switch stack to &lt;STRONG&gt;15.2(7)E5&lt;/STRONG&gt; and monitor for two weeks with periodic timer of &lt;STRONG&gt;2880&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Check the FW MTU setting for all user subnets,&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;In the mean-time the temporary fix for current issue is to remove NAC from the port and add it back in again&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Remove NAC&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;PRE&gt;&lt;EM&gt;no dot1x timeout tx-period 60&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;no dot1x max-reauth-req 3&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;no source template PORT-AUTH-TEMPLATE&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;shut&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;no shut&lt;/EM&gt;&lt;/PRE&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI&gt;Add NAC&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;PRE&gt;&lt;EM&gt;dot1x timeout tx-period 60&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;dot1x max-reauth-req 3&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;source template PORT-AUTH-TEMPLATE&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;shut&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;no shut&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;Just to point out that if a switchport starts behaving like this, it doesn't matter who logs into the network on these ports, they will not get network access. This includes printers and phones (MAB).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully an IOS upgrade will resolve this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 20:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4620790#M575089</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-05-30T20:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4622747#M575144</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;excellent Action Plan !!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 17:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4622747#M575144</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-01T17:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4657548#M576355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to let you know that the IOS upgrade&amp;nbsp;from 15.2(7)E3 to 15.2(7)E5 on the Cisco 2960X switches work. We haven't encountered this issue since.&lt;/P&gt;
&lt;P&gt;Thanks for all your help. Much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4657548#M576355</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2022-07-26T12:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAC not working on 1 Desk, works everywhere else.</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4657566#M576356</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;excellent news !!! Thanks for sharing the final result !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 13:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-not-working-on-1-desk-works-everywhere-else/m-p/4657566#M576356</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-26T13:11:58Z</dc:date>
    </item>
  </channel>
</rss>

