<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x timeout log in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787761#M580246</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;ISE 2.6, patch 12. I noticed that the same issue/log is for more than 1 endpoint and more than 1 switch. Yes, I checked the switch and it has connectivity to ISE, there is no log regarding RADIUS server down.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Mar 2023 10:42:02 GMT</pubDate>
    <dc:creator>peter.matuska1</dc:creator>
    <dc:date>2023-03-06T10:42:02Z</dc:date>
    <item>
      <title>802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787727#M580243</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The switch 9200L,&amp;nbsp;17.06.04 has 802.1x enabled. I noticed in the logs that sometimes the 802.1x doesn't finish correctly and the log on the ISE says:&amp;nbsp;5440 Endpoint abandoned EAP session and started new, the switch log is:&amp;nbsp;%DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (MAC address) with reason &lt;STRONG&gt;(Timeout)&lt;/STRONG&gt; on Interface Gi3/0/35 AuditSessionID 043410AC0000E5C0B633FC57 Username: host/hostname.domain.com&lt;/P&gt;
&lt;P&gt;The question is whether this is timeout is caused by the PC or by the switch. The PC has native windows supplicant using EAP-TLS.&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 10:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787727#M580243</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2023-03-06T10:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787740#M580245</link>
      <description>&lt;P&gt;is this for only 1 client or all of them having same issue ? and is this worked on any other switch ? all the switches having same issue ?&lt;/P&gt;
&lt;P&gt;what is the version of ISE ?&amp;nbsp; - does the switch has reachability to ISE and what Logs you see on ISE ?&lt;/P&gt;
&lt;P&gt;how is your configfuriaton on the switch AAA and port config ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;dot1x timeout tx-period XX ?what timeout config you have here ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 10:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787740#M580245</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-06T10:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787761#M580246</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;ISE 2.6, patch 12. I noticed that the same issue/log is for more than 1 endpoint and more than 1 switch. Yes, I checked the switch and it has connectivity to ISE, there is no log regarding RADIUS server down.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 10:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787761#M580246</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2023-03-06T10:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787771#M580248</link>
      <description>&lt;P&gt;if you connect same device or user other switch that works ?&lt;/P&gt;
&lt;P&gt;For testing any device you know having issue, try to increase the time ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dot1x timeout tx-period X&lt;BR /&gt;dot1x timeout supp-timeout X&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787771#M580248</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-06T11:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787776#M580249</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think it will be the same. I will try to modify the timeout on the intefaces.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787776#M580249</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2023-03-06T11:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787806#M580250</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Gi3/0/35 &amp;lt;&amp;lt;- the log for this Port is appear when PC connect AND active&amp;nbsp; or&amp;nbsp; connect not active&amp;nbsp;&lt;BR /&gt;I think this is normal when PC connect not active&lt;BR /&gt;the ISW/ISE will reauth the connect device, if the device not reply then SW/ISE will unauthz the port.&amp;nbsp;&lt;BR /&gt;that it no need to change the default timeout if the case is same of above&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787806#M580250</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-06T11:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787807#M580251</link>
      <description>&lt;P&gt;1. The log from ISE Indicates that the endpoint is not responding. If you check the steps in the detailed live log you will notice that ISE sends an Access-Challenge and that it gets no response for this access challenge.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. The log from the switch Indicates that the supplicant (PC) is timing out, the switch sends requests to the supplicant but the supplicant never responds during the time window.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has two possibilities:&amp;nbsp;&lt;BR /&gt;1. The supplicant is indeed not responding because of an issue with the supplicant or the protocol flow, you are using machine authentication&amp;nbsp;&lt;SPAN&gt;host/hostname.domain.com maybe the PC was put to sleep or something?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. The timers configured on the switch are misconfigured.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I believe it would be point#1 because if the timers are the issue then you would face this on a larger scale and more frequently.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787807#M580251</guid>
      <dc:creator>Tariq Mahmoud</dc:creator>
      <dc:date>2023-03-06T11:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787845#M580252</link>
      <description>&lt;P&gt;Hi, last time the customer reported the issue was when PC was turned on (not from sleep) and machine and user authentication failed during the boot up and login process. Once the customer unplugged and plug the cable back to the PC, the authentication finished correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787845#M580252</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2023-03-06T11:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787910#M580253</link>
      <description>&lt;P&gt;and this will happened each time the Sleep-&amp;gt;active time is less than auth timeout.&amp;nbsp;&lt;BR /&gt;the solution for me is use inactivity timeout &amp;lt;&amp;lt;- use this timeout only for this user port and monitor the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 12:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4787910#M580253</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-06T12:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4788105#M580263</link>
      <description>&lt;P&gt;That issue is most likely related to the endpoint, not the switch nor ISE. I came across similar issues and managed to fix them by updating the NIC drivers.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 16:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4788105#M580263</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-03-06T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4788188#M580268</link>
      <description>&lt;P&gt;Also you need to collect end device information which was failing - especially NIC cards used.&lt;/P&gt;
&lt;P&gt;Some Intel NIC cards having this issue,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 18:26:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4788188#M580268</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-06T18:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x timeout log</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4792034#M580395</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/58587"&gt;@peter.matuska1&lt;/a&gt; I agree with most of the responses here, especially Aref's. It might worth to troubleshoot further, e.g, by using one of these guides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/wireless-mobility-knowledge-base/802-1x-eap-troubleshooting/ta-p/3155512" target="_self"&gt;Cisco Community Technology and Support Wireless - Mobility Wireless - Mobility Knowledge Base 802.1X/EAP Troubleshooting&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/troubleshoot-dot1x-and-radius-in-ios-and-ios-xe/ta-p/4287439" target="_self"&gt;Cisco Community Technology and Support Security Security Knowledge Base Troubleshoot Dot1x and Radius in IOS and IOS-XE&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 12 Mar 2023 04:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-timeout-log/m-p/4792034#M580395</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-03-12T04:43:12Z</dc:date>
    </item>
  </channel>
</rss>

