<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5440 Endpoint abandoned EAP session and started new in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4738834#M578830</link>
    <description>&lt;P class="lia-align-justify"&gt;Although this is an old post ... I would like to add some points for future reference:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. special attention to:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd35786" target="_blank" rel="noopener"&gt;CSCwd35786 ENH: ISE: 5440 Endpoint abandoned EAP session events need to have visibility in ISE reports&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: the best &lt;STRONG&gt;Workaround&lt;/STRONG&gt; is, at &lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Diagnostics &amp;gt; RADIUS Errors&lt;/STRONG&gt;, click the &lt;STRONG&gt;Advanced Filter&lt;/STRONG&gt; and &lt;EM&gt;Failure Reason CONTAINS 5440.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. check the &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc93451" target="_blank" rel="noopener"&gt;CSCwc93451 Profiler should ignore non-positive RADIUS syslog messages for forwarding from default RADIUS probe&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;EM&gt;" ...&lt;/EM&gt;&lt;EM&gt; &lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Normal operation with profiler default RADIUS probe enabled. You will see messages forwarded like: "&lt;U&gt;5440 NOTICE RADIUS: Endpoint abandoned EAP session and started new &lt;/U&gt;, 12934 WARN Failed-Attempt: Supplicant stopped responding, etc. We should only be sending successful authentications, accounting start/stop/interim, ie, 5200, 3000, 3001 &amp;amp; 3002. There are additional successful codes other than 5200. These need to be inculded as well. Everything else should be filtered out and not sent to VCS or DB. ... "&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Fixed on &lt;STRONG&gt;ISE3.1 P5&lt;/STRONG&gt; and &lt;STRONG&gt;ISE2.7 P8&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 14:01:32 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2022-12-14T14:01:32Z</dc:date>
    <item>
      <title>5440 Endpoint abandoned EAP session and started new</title>
      <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4598962#M574325</link>
      <description>&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;H3&gt;Overview&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5440 Endpoint abandoned EAP session and started new&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;zhenwei.zhang&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Id&lt;/TD&gt;&lt;TD&gt;B6:E3:3D:A9:F3:94&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Profile&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Policy&lt;/TD&gt;&lt;TD&gt;Ordos_802.1x_AD_auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authorization Policy&lt;/TD&gt;&lt;TD&gt;Ordos_802.1x_AD_auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authorization Result&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;H3&gt;Authentication Details&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Source Timestamp&lt;/TD&gt;&lt;TD&gt;2022-04-25 06:34:47.92&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Received Timestamp&lt;/TD&gt;&lt;TD&gt;2022-04-25 06:34:47.92&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Policy Server&lt;/TD&gt;&lt;TD&gt;ise&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5440 Endpoint abandoned EAP session and started new&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;5440 Endpoint abandoned EAP session and started new&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Resolution&lt;/TD&gt;&lt;TD&gt;Verify known NAD or supplicant issues and published bugs. Verify NAD and supplicant configuration.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Root cause&lt;/TD&gt;&lt;TD&gt;Endpoint started new authentication while previous is still in progress. Most probable that supplicant on that endpoint stopped conducting the previous authentication and started the new one. Closing the previous authentication.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;zhenwei.zhang&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Id&lt;/TD&gt;&lt;TD&gt;B6:E3:3D:A9:F3:94&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Protocol&lt;/TD&gt;&lt;TD&gt;PEAP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Network Device&lt;/TD&gt;&lt;TD&gt;Ordos_C9800&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS IPv4 Address&lt;/TD&gt;&lt;TD&gt;10.204.60.3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS Port Id&lt;/TD&gt;&lt;TD&gt;capwap_90000029&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS Port Type&lt;/TD&gt;&lt;TD&gt;Wireless - IEEE 802.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Response Time&lt;/TD&gt;&lt;TD&gt;41&amp;nbsp;milliseconds&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;H3&gt;Other Attributes&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;ConfigVersionId&lt;/TD&gt;&lt;TD&gt;217&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;AcsSessionID&lt;/TD&gt;&lt;TD&gt;ise/439644191/19875&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS-Port&lt;/TD&gt;&lt;TD&gt;91918&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CPMSessionID&lt;/TD&gt;&lt;TD&gt;033CCC0A00003896611F97C9&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;EndPointMACAddress&lt;/TD&gt;&lt;TD&gt;B6-E3-3D-A9-F3-94&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ISEPolicySetName&lt;/TD&gt;&lt;TD&gt;Ordos_802.1x_AD_auth&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;StepLatency&lt;/TD&gt;&lt;TD&gt;21=18618&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DTLSSupport&lt;/TD&gt;&lt;TD&gt;Unknown&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Network Device Profile&lt;/TD&gt;&lt;TD&gt;Cisco&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;Location#All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;Device Type#All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IPSEC&lt;/TD&gt;&lt;TD&gt;IPSEC#Is IPSEC Device#No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device IP Address&lt;/TD&gt;&lt;TD&gt;10.204.60.3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Called-Station-ID&lt;/TD&gt;&lt;TD&gt;9c-d5-7d-bc-d8-40:Envision-AESC&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;H3&gt;Result&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;RadiusPacketType&lt;/TD&gt;&lt;TD&gt;Drop&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Steps&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Radius.NAS-Port-Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11507&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12300&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request proposing PEAP with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12625&lt;/TD&gt;&lt;TD&gt;Valid EAP-Key-Name attribute received&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12302&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing PEAP challenge-response and accepting PEAP as negotiated&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12318&lt;/TD&gt;&lt;TD&gt;Successfully negotiated PEAP version 0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12800&lt;/TD&gt;&lt;TD&gt;Extracted first TLS record; TLS handshake started&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12805&lt;/TD&gt;&lt;TD&gt;Extracted TLS ClientHello message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12806&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerHello message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12807&lt;/TD&gt;&lt;TD&gt;Prepared TLS Certificate message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12808&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerKeyExchange message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12810&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerDone message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12305&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another PEAP challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;5440&lt;/TD&gt;&lt;TD&gt;Endpoint abandoned EAP session and started new (&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Step latency=18618 ms)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;问题：用户认证失败，提示5440错误&lt;/P&gt;&lt;P&gt;我的无线AC的version为&lt;/P&gt;&lt;P&gt;C9800#SHOW VERsion&lt;BR /&gt;Cisco IOS XE Software, Version 17.03.03&lt;BR /&gt;Cisco IOS Software [Amsterdam], C9800 Software (C9800_IOSXE-K9), Version 17.3.3, RELEASE SOFTWARE (fc7)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank" rel="noopener"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2021 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Thu 04-Mar-21 12:37 by mcpre&lt;/P&gt;&lt;P&gt;我的ISE版本为3.1&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 06:46:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4598962#M574325</guid>
      <dc:creator>lin.yang2</dc:creator>
      <dc:date>2022-04-25T06:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: 5440 Endpoint abandoned EAP session and started new</title>
      <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4599264#M574336</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1346103"&gt;@lin.yang2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at: &lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3383.pdf" target="_blank" rel="noopener"&gt;BRKSEC-3383 Troubleshooting ISE&lt;/A&gt;, special attention to &lt;STRONG&gt;pg. 10 - 802.1x Endpoint Abandoned EAP Session&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 13:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4599264#M574336</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-04-25T13:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: 5440 Endpoint abandoned EAP session and started new</title>
      <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4599298#M574339</link>
      <description>&lt;P&gt;&lt;SPAN&gt;5440 Endpoint abandoned EAP session and started new&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-This is usually an indication of a misconfigured supplicant and/or end user possibly being inpatient and initiating a new auth session before initial one completes.&amp;nbsp; This may help too:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;ISE Secure Wired Access Prescriptive Deployment Guide - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 13:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4599298#M574339</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-04-25T13:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: 5440 Endpoint abandoned EAP session and started new</title>
      <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4738834#M578830</link>
      <description>&lt;P class="lia-align-justify"&gt;Although this is an old post ... I would like to add some points for future reference:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. special attention to:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwd35786" target="_blank" rel="noopener"&gt;CSCwd35786 ENH: ISE: 5440 Endpoint abandoned EAP session events need to have visibility in ISE reports&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: the best &lt;STRONG&gt;Workaround&lt;/STRONG&gt; is, at &lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Diagnostics &amp;gt; RADIUS Errors&lt;/STRONG&gt;, click the &lt;STRONG&gt;Advanced Filter&lt;/STRONG&gt; and &lt;EM&gt;Failure Reason CONTAINS 5440.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. check the &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwc93451" target="_blank" rel="noopener"&gt;CSCwc93451 Profiler should ignore non-positive RADIUS syslog messages for forwarding from default RADIUS probe&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;EM&gt;" ...&lt;/EM&gt;&lt;EM&gt; &lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Normal operation with profiler default RADIUS probe enabled. You will see messages forwarded like: "&lt;U&gt;5440 NOTICE RADIUS: Endpoint abandoned EAP session and started new &lt;/U&gt;, 12934 WARN Failed-Attempt: Supplicant stopped responding, etc. We should only be sending successful authentications, accounting start/stop/interim, ie, 5200, 3000, 3001 &amp;amp; 3002. There are additional successful codes other than 5200. These need to be inculded as well. Everything else should be filtered out and not sent to VCS or DB. ... "&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Fixed on &lt;STRONG&gt;ISE3.1 P5&lt;/STRONG&gt; and &lt;STRONG&gt;ISE2.7 P8&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4738834#M578830</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-12-14T14:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: 5440 Endpoint abandoned EAP session and started new</title>
      <link>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4932832#M584356</link>
      <description>&lt;P&gt;That link doesn't work.It says page not found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 16:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5440-endpoint-abandoned-eap-session-and-started-new/m-p/4932832#M584356</guid>
      <dc:creator>maggie.26.1989</dc:creator>
      <dc:date>2023-10-02T16:55:23Z</dc:date>
    </item>
  </channel>
</rss>

