<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4809211#M580968</link>
    <description>&lt;P&gt;sorry late update:&lt;/P&gt;&lt;P&gt;We have fixed the issue, nothing wrong with switch config or ISE. It was the IP Phone hard code 802.1x issue, after we disable, it was working perfectly. Thanks for your time guys&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2023 04:08:31 GMT</pubDate>
    <dc:creator>Ruelb2214</dc:creator>
    <dc:date>2023-04-06T04:08:31Z</dc:date>
    <item>
      <title>Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4770919#M579714</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;we have encounter issue with MAB devices, the authorization doesn't apply on the switch port, below the capture logs&lt;/P&gt;&lt;P&gt;Feb 8 08:10:07.059: %AUTHMGR-5-START: Starting 'mab' for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002CB17651032500&lt;BR /&gt;Feb 8 08:10:08.370: %MAB-5-SUCCESS: Authentication successful for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002CB17651032500&lt;BR /&gt;Feb 8 08:10:08.370: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002CB17651032500&lt;BR /&gt;Feb 8 08:10:08.373: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002CB17651032500&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The other Dot1x windows machine are working only MAB keeps failing to apply the Auth.&lt;/P&gt;&lt;P&gt;I read some post here, to put Access Type=ACCESS ACCPET, I did that and still has issue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/10&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority mab dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;snmp trap mac-notification change added&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;/P&gt;&lt;P&gt;Switch Ports Model SW Version SW Image&lt;BR /&gt;------ ----- ----- ---------- ----------&lt;BR /&gt;* 1 52 WS-C2960X-48FPS-L 15.0(2)EX5 C2960X-UNIVERSALK9-M&lt;BR /&gt;2 52 WS-C2960X-48FPS-L 15.0(2)EX5 C2960X-UNIVERSALK9-M&lt;/P&gt;&lt;P&gt;Did anyone encounter the same issue? How did you resolve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 08:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4770919#M579714</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-02-08T08:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4770922#M579715</link>
      <description>&lt;P&gt;Just to add in, we are using static profiling ISE and base on the logs it hits the correct policy and given a correct auth profile, but on switch it did not reflect.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ruelb2214_0-1675845427360.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/176082iA89429D1754AFB67/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ruelb2214_0-1675845427360.png" alt="Ruelb2214_0-1675845427360.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 08:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4770922#M579715</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-02-08T08:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771404#M579720</link>
      <description>&lt;P&gt;Hi, Can you paste snap of Policy Elements&amp;gt; Authorization &amp;gt;Authorization profiles and Attributes configuration. Have you verified the vlan you sending are configured on switch ?&lt;/P&gt;&lt;P&gt;This issue seems either attributes configuration is incorrect in ISE authorization profile or attributes being assigned like vlan id doen't exists on switch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 14:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771404#M579720</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2023-02-08T14:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771424#M579721</link>
      <description>&lt;P&gt;Since the tunnel-group vlan is set to "2", which matches the port details of "&lt;SPAN&gt;switchport access vlan 2", then I'm inclined to think the vlan 2 was created on the switch. I would also recommend you also do a syntax check on the DACL.&amp;nbsp; I've had DACLs which could not be applied because of syntax errors which were not obvious to my eyes, but were found by the ipv4 syntax checker in ISE v2.2/v2.7.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 15:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771424#M579721</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2023-02-08T15:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771533#M579728</link>
      <description>&lt;P&gt;After the DACL syntax is confirmed, check if DACL download is happening on the switch. You can confirm this by taking captures or enabling RADIUS debugs on the switch.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 17:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771533#M579728</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-02-08T17:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771665#M579735</link>
      <description>&lt;P&gt;If you have not done so already, you should also confirm that you have DHCP Snooping (global and VLAN) and IP Device Tracking (global and switchport) configured correctly. The switch uses requires IPDT to learn the source IP address of the endpoint so that it can insert that into the DACL when applied.&lt;/P&gt;
&lt;P&gt;You can confirm if the switch has the endpoint IP address in the device tracking table using the &lt;STRONG&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;show ip device tracking all&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt; command.&lt;/P&gt;
&lt;P&gt;If that is not the culprit, much more information would be needed to provide any meaningful assistance (ISE version, ISE policy configurations, switch global config, details on the differences between working and non-working switchports, etc).&lt;/P&gt;
&lt;P&gt;If this is an urgent issue, please contact TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 21:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771665#M579735</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-02-08T21:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771739#M579737</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;VLAN on switch has no issue, when we remove the NAC config the Phone works perfectly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While for authorization profile or attributes it's configure "ACCESS ACCEPT" and its working on another&amp;nbsp;switch model as well. We have 9200 switches same Policy and Auth profile used, no issue at all. Only in 2960 switches model we are facing&amp;nbsp;the issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 02:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771739#M579737</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-02-09T02:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771742#M579738</link>
      <description>&lt;P&gt;I have tried enable DHPC snooping on global and VLAN and IPDT also, but still the same issue.&lt;/P&gt;&lt;P&gt;I'm not sure if we are hitting bug on the firmware and planning upgrade to version&amp;nbsp;15.2-7.E7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Switch Ports Model SW Version SW Image&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;------ ----- ----- ---------- ----------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;* 1 52 WS-C2960X-48FPS-L 15.0(2)EX5 C2960X-UNIVERSALK9-M&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2 52 WS-C2960X-48FPS-L 15.0(2)EX5 C2960X-UNIVERSALK9-M&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 03:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771742#M579738</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-02-09T03:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771750#M579740</link>
      <description>&lt;P&gt;found out interested debug aaa attr logs which could be related to firmware bug:&lt;/P&gt;&lt;P&gt;Feb 9 03:59:58.604: %MAB-5-SUCCESS: Authentication successful for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;BR /&gt;Feb 9 03:59:58.604: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;BR /&gt;Feb 9 03:59:58.607: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;BR /&gt;Feb 9 03:59:58.702: AAA/ATTR(00000000): add tag 1 to attribute inacl(144)&lt;/P&gt;&lt;P&gt;Feb 9 04:00:59.173: AAA/ATTR(00000000): add tag 1 to attribute tunnel-type(448)&lt;BR /&gt;Feb 9 04:00:59.173: AAA/ATTR(00000000): add tag 1 to attribute tunnel-medium-type(440)&lt;BR /&gt;Feb 9 04:00:59.173: AAA/ATTR(00000000): add tag 1 to attribute tunnel-private-group-id(381)&lt;BR /&gt;Feb 9 04:00:59.173: AAA/ATTR:&lt;STRONG&gt; invalid attribute prefix: "ACS"&lt;/STRONG&gt;&lt;BR /&gt;Feb 9 04:00:59.173: %MAB-5-SUCCESS: Authentication successful for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;BR /&gt;Feb 9 04:00:59.173: %AUTHMGR-7-RESULT: Authentication result 'success' from 'mab' for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;BR /&gt;Feb 9 04:00:59.173: %AUTHMGR-5-FAIL: Authorization failed or unapplied for client (487a.5507.31ac) on Interface Gi2/0/10 AuditSessionID 0A71075B002D28CF554C390B&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 05:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4771750#M579740</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-02-09T05:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WS-C2960X-48FPS-L MAB Authorization keeps failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4809211#M580968</link>
      <description>&lt;P&gt;sorry late update:&lt;/P&gt;&lt;P&gt;We have fixed the issue, nothing wrong with switch config or ISE. It was the IP Phone hard code 802.1x issue, after we disable, it was working perfectly. Thanks for your time guys&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 04:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ws-c2960x-48fps-l-mab-authorization-keeps-failing/m-p/4809211#M580968</guid>
      <dc:creator>Ruelb2214</dc:creator>
      <dc:date>2023-04-06T04:08:31Z</dc:date>
    </item>
  </channel>
</rss>

