<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication session freeze 802.1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5008467#M586863</link>
    <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/ta-p/3704356" target="_self"&gt;Check this out first&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We're not clairvoyant. Garbage in, garbage out.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 21:48:40 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-01-29T21:48:40Z</dc:date>
    <item>
      <title>Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007536#M586818</link>
      <description>&lt;P&gt;Dear All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue with my 802.1x wired implementation. The authentication settings on endpoint is computers or users because ise allows domain users and domain computers network access. The issue is that when the user logs out of their pc, after a while when no user is logged in, the pc will not get network access and also in ise I can not see any live session for that pc. When I do show mac address, I can only see the mac address of the IP Phone and not the mac address of the PC, and when I do show authentication session I can see the mac address of the endpoint there but and the status is unauth.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch keeps logging dot1x failed for client with mac address (endpoint mac address), which is weird because I do not see the mac address of the endpoint on the interface and also I do not see any log of the mac address in ise live logs.&lt;/P&gt;&lt;P&gt;To solve this issue, I have to manually clear auth session etc, but I do not understand what exactly is happening here. I read the documentation of 802.1x implementation but did not find anything related.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 05:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007536#M586818</guid>
      <dc:creator>muhammadtalha</dc:creator>
      <dc:date>2024-01-29T05:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007647#M586820</link>
      <description>&lt;P&gt;This might be an issue with session management on the switch - if the MAC address is gone, then it could be that the switch has cleared the session because the PC has not sent an Ethernet frame within the Inactivity-Timer period.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you share your switch interface config:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show derived-config interface &amp;lt;interface&amp;gt;
show run | section device-tracking policy
&lt;/LI-CODE&gt;
&lt;P&gt;Are you using IBNS 2.0? If so, can you share your policy map? If so, please show us these - and also your Service Template that sets the Inactivity-Timer&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show policy-map type control subscriber &amp;lt;name of policy map&amp;gt;
show run | section service-template IA-TIMER&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007647#M586820</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-01-29T06:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007648#M586821</link>
      <description>&lt;P&gt;Thanks for your response, I am not using device-tracking policy and also I am using IBNS 2.0.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007648#M586821</guid>
      <dc:creator>muhammadtalha</dc:creator>
      <dc:date>2024-01-29T06:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007650#M586822</link>
      <description>&lt;P&gt;Device-Tracking is required for NAC to work as expected. It's not something you want to avoid or not configure correctly.&lt;/P&gt;
&lt;P&gt;Have a &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;good look at this Guide from Cisco&lt;/A&gt; - it's the best starting point for checking that you have all your ducks in a row.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007650#M586822</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-01-29T06:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007653#M586823</link>
      <description>&lt;P&gt;I tried configuring device tracking on 2960X 15.2(2) E3 but the switch does not support this command. However, when I do IP device tracking interface, I can see the mac address of the IP Phone and vlan of the IP Phone and nothing related to the endpoint vlan or mac address and also the show auth session still has the mac address of the endpoint and is still unauth.&lt;/P&gt;&lt;P&gt;Gi3/0/16 (MAC ADDRESS) N/A UNKNOWN Unauth C0A837170000037F3E7076DD&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:43:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5007653#M586823</guid>
      <dc:creator>muhammadtalha</dc:creator>
      <dc:date>2024-01-29T06:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication session freeze 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5008467#M586863</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/ta-p/3704356" target="_self"&gt;Check this out first&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We're not clairvoyant. Garbage in, garbage out.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 21:48:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-session-freeze-802-1x/m-p/5008467#M586863</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-01-29T21:48:40Z</dc:date>
    </item>
  </channel>
</rss>

