<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x Method Status List Empty in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5054821#M588530</link>
    <description>&lt;P&gt;We're seeing an issue on our 9200 series switches where we get the message "Method Status List Empty" when trying to authenticate devices either for the first time, or when a switch is restarted. To resolve, "clear authentication sessions" is required for the devices to then go through authentication again which works but is not a solution, before running this a device will sit as "UNKNOWN Unauth". I did see a bug for this but that is relating to an older IOS version well before ours, anyone have any ideas on how to resolve this?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2024 09:13:31 GMT</pubDate>
    <dc:creator>DM812</dc:creator>
    <dc:date>2024-04-02T09:13:31Z</dc:date>
    <item>
      <title>802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5054821#M588530</link>
      <description>&lt;P&gt;We're seeing an issue on our 9200 series switches where we get the message "Method Status List Empty" when trying to authenticate devices either for the first time, or when a switch is restarted. To resolve, "clear authentication sessions" is required for the devices to then go through authentication again which works but is not a solution, before running this a device will sit as "UNKNOWN Unauth". I did see a bug for this but that is relating to an older IOS version well before ours, anyone have any ideas on how to resolve this?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 09:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5054821#M588530</guid>
      <dc:creator>DM812</dc:creator>
      <dc:date>2024-04-02T09:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5054912#M588539</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Generally speaking , try latest advisory release for the platform ; if a bug remains persistent and not mentioned as such in bug search then you need to report back to&lt;U&gt;&lt;STRONG&gt; TAC,&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 11:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5054912#M588539</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-04-02T11:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5055214#M588555</link>
      <description>&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;said, when asking a question on these forums, it's also generally a good idea to tell us what version of software you're on, and some configurations that relate to the issue. e.g. you could send us the config output relating to the interface (show derived-config int x/y/z) and your IBNS 1.0/2.0 config.&amp;nbsp; NAC config does tend to sprawl all over the place.&lt;/P&gt;
&lt;P&gt;Have you followed the general advice given in &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;Wired Prescriptive Guide&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 20:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5055214#M588555</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-04-02T20:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5055224#M588556</link>
      <description>&lt;P&gt;Share the config of port&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2024 20:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5055224#M588556</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-02T20:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5056148#M588574</link>
      <description>&lt;P&gt;See example port config below, this only affects a chunk of ports at a time and affects both data and voice devices...&lt;/P&gt;&lt;P&gt;The below config is also set on a large number of switches and is working fine.&lt;/P&gt;&lt;P&gt;IOS:&amp;nbsp;17.6.3&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Port Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;switchport access vlan 5&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 10&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event server dead action authorize vlan 5&lt;BR /&gt;authentication event server dead action authorize voice&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 65535&lt;BR /&gt;authentication timer restart 10800&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;trust device cisco-phone&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout quiet-period 30&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;auto qos voip cisco-phone&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;service-policy input AutoQos-4.0-CiscoPhone-Input-Policy&lt;BR /&gt;service-policy output AutoQos-4.0-Output-Policy&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Global Config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius Servers&lt;BR /&gt;server name Server1&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group Servers&lt;BR /&gt;aaa authorization network default group Servers&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;radius server Server1&lt;BR /&gt;address ipv4 192.168.5.10 auth-port 1812 acct-port 1813&lt;BR /&gt;key [key]&lt;BR /&gt;timeout 2&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 192.168.5.10 server-key [key]&lt;BR /&gt;port 3799&lt;BR /&gt;!&lt;BR /&gt;aaa accounting dot1x default start-stop group Servers&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 09:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5056148#M588574</guid>
      <dc:creator>DM812</dc:creator>
      <dc:date>2024-04-04T09:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059451#M588603</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/780474"&gt;@DM812&lt;/a&gt;&amp;nbsp;- I think the config looks good. It appears you're using Aruba Clearpass as your RADIUS server? Do you see the Access-Request come to the server on the initial endpoint connection attempt (where the switch then puts the session in Method Status List Empty)?&amp;nbsp; Curious to know if any RADIUS traffic goes to the server, and what the server responds with.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 21:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059451#M588603</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-04-07T21:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059931#M588611</link>
      <description>&lt;P&gt;I can see the request on our RADIUS server and accepts the device and returns as accepted, authenticated, and sends the correct VLAN, but when looking on the switch it fails the auth.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 08:49:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059931#M588611</guid>
      <dc:creator>DM812</dc:creator>
      <dc:date>2024-04-08T08:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059943#M588612</link>
      <description>&lt;P&gt;show aaa server &amp;lt;&amp;lt;- share this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 09:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5059943#M588612</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-08T09:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5369711#M599787</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Team,&amp;nbsp; I am facing the issue.&amp;nbsp; &amp;nbsp; The switch is&amp;nbsp;WS-C3560CG-8PC-S .&amp;nbsp; &amp;nbsp; The version is&amp;nbsp;15.2(2)E10 C3560c405ex-.UNIVERSALK9-M.&amp;nbsp; &amp;nbsp; 802.1x is working on other 8-port but different models&amp;nbsp;WS-C3560CX.&amp;nbsp; The is not CX . It is&amp;nbsp; WS-C3560CG-8PC-S .&amp;nbsp; I want to know, if 802.1x&amp;nbsp; could be configured on this particular modelC3560CG-8PC&amp;nbsp; .&amp;nbsp; &amp;nbsp;Please advise.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;CivicCtrDCLEDLightSW#show access-session interface Gi0/1 details&lt;BR /&gt;Interface: GigabitEthernet0/1&lt;BR /&gt;MAC Address: 70b3.d5ab.d6c6&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 172.30.63.221&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: UNKNOWN&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: in&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 316s&lt;BR /&gt;Common Session ID: 0000000000000B42296454B4&lt;BR /&gt;Acct Session ID: Unknown&lt;BR /&gt;Handle: 0x00000001&lt;BR /&gt;Current Policy: DOT1X_MAB_POLICY&lt;/P&gt;&lt;P&gt;Method status list: empty&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 20:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5369711#M599787</guid>
      <dc:creator>Mukesh-Kumar</dc:creator>
      <dc:date>2026-02-12T20:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x Method Status List Empty</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5369720#M599789</link>
      <description>&lt;P&gt;I don't know this level of detail down to sub models of switches. What we need is to see your configuration and take it from there.&lt;/P&gt;
&lt;P&gt;Chances are, that it should work.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show run | section radius
show run | include aaa
show run interface gi 0/1
show run | in dot1x&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 20:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-method-status-list-empty/m-p/5369720#M599789</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-02-12T20:53:27Z</dc:date>
    </item>
  </channel>
</rss>

