<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event 5400 Authentication failed with 22056 Failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4720513#M578204</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306399"&gt;@latenaite2011&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;verifying ISE working with other use cases&lt;/LI&gt;
&lt;LI&gt;trying another switch port, in case the switch port gone bad&lt;/LI&gt;
&lt;LI&gt;trying another docking station, in case the existing docking station is bad or has a bad network interface&lt;/LI&gt;
&lt;LI&gt;trying rebooting the PC and trying another PC, in case something wrong with the client O/S&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 13 Nov 2022 18:32:29 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2022-11-13T18:32:29Z</dc:date>
    <item>
      <title>Event 5400 Authentication failed with 22056 Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718090#M578126</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;Just wondering if anyone knows why a user would get a Event 5400 Authentication failed (Failure Reason is 22056 Subnet not found in the applicable identity store(s).&amp;nbsp; The laptop has just gone through a successful authentication and switched to a docking station (to test how a normal user would do) and we're testing this new configuration now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the live logs, we can see it switched from 802.1x to MAB and not sure why if it just worked with 802.1x about several minutes ago.&lt;/P&gt;
&lt;P&gt;See attached snapshots.&amp;nbsp; This is a new setup.&amp;nbsp; &amp;nbsp;Not sure if the mac address is still in the cache so it is not prompting to re-authenticate.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 17:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718090#M578126</guid>
      <dc:creator>latenaite2011</dc:creator>
      <dc:date>2022-11-08T17:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Event 5400 Authentication failed with 22056 Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718145#M578127</link>
      <description>&lt;P&gt;I didn't read your trace, but just from idea - after successful dot1x authentication an endpoint with the MC of the endpoint was created on the ISE, but docking station has another MAC address, so you got disconnected.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 18:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718145#M578127</guid>
      <dc:creator>Thomas Schmitt</dc:creator>
      <dc:date>2022-11-08T18:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Event 5400 Authentication failed with 22056 Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718189#M578130</link>
      <description>&lt;P&gt;Thanks for the reply Thomas.&lt;/P&gt;
&lt;P&gt;I did ask if the docking station has a different network adapter but it doesn't. Customer connects the laptop docking station that connects to the laptop using a USB C. The connection worked with the docking station at first then when he connected it, it wouldn't work anymore.&amp;nbsp; Since the laptop doesn't have any physical network, he uses the docking station to connect.&amp;nbsp; You can see the Live logs that the mac address is the same for the successful and the failed attempt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 19:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4718189#M578130</guid>
      <dc:creator>latenaite2011</dc:creator>
      <dc:date>2022-11-08T19:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Event 5400 Authentication failed with 22056 Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4719987#M578189</link>
      <description>&lt;P&gt;You redacted the user/host information so I don't know if you are doing the same user/host for all of these.&lt;/P&gt;
&lt;P&gt;Capture 1 is doing EAP-TLS which is certificate based authentication.&lt;/P&gt;
&lt;P&gt;Capture 2 is doing PEAP+EAP-MSCHAPv2 which is username+password authentication.&lt;/P&gt;
&lt;P&gt;Capture 3 is doing &lt;EM&gt;&lt;STRONG&gt;MAB&lt;/STRONG&gt;&lt;/EM&gt; and failing because the MAC Address &lt;STRONG&gt;&lt;EM&gt;was not found&lt;/EM&gt;&lt;/STRONG&gt; in ISE (it has never been seen before).&lt;/P&gt;
&lt;P&gt;If you want to allow new (never-before-seen) MAC addresses onto your network, you should change the authentication policy of your respective Policy Set to simply Continue if User Not Found:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/167719i3701784D365F4DCB/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 21:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4719987#M578189</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-11-11T21:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Event 5400 Authentication failed with 22056 Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4720513#M578204</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306399"&gt;@latenaite2011&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;verifying ISE working with other use cases&lt;/LI&gt;
&lt;LI&gt;trying another switch port, in case the switch port gone bad&lt;/LI&gt;
&lt;LI&gt;trying another docking station, in case the existing docking station is bad or has a bad network interface&lt;/LI&gt;
&lt;LI&gt;trying rebooting the PC and trying another PC, in case something wrong with the client O/S&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Nov 2022 18:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/event-5400-authentication-failed-with-22056-failure/m-p/4720513#M578204</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-13T18:32:29Z</dc:date>
    </item>
  </channel>
</rss>

