<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Switch authentication issue on window computer in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5197501#M591927</link>
    <description>&lt;P&gt;This issue solved?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 10:16:27 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-09-23T10:16:27Z</dc:date>
    <item>
      <title>Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195219#M591845</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I have a question would like to ask the different from the 2 commands ? and the command at Site A has enabled the authentication, whereas in Site B didn't, and in Site A all computer can access to network whereas in Site B its not obtaining any IP addresses at all, as the authentication has not been active in site B switch ports, i do not understand why laptop can not obtain IP addresses, as in both switches has self certificates and AAA configured on it, just wonder anything else need to configure in the computer itself ? the previously colleagues has left to company, and i do not have enough information on what it has been done by him, any help would be appreicated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;From Site A&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/9&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description User&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;switchport access vlan 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;switchport mode access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;device-tracking attach-policy IPDT_POLICY&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication periodic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;access-session closed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;access-session port-control auto&lt;/P&gt;
&lt;P&gt;&amp;nbsp;mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x pae authenticator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;service-policy type control subscriber ISE_POLICY&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;from site B&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description User data port&lt;/P&gt;
&lt;P&gt;&amp;nbsp;switchport mode access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication event fail action next-method&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication host-mode multi-auth&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication order mab dot1x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication priority dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication periodic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication timer reauthenticate server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication timer inactivity 180&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication violation restrict&lt;/P&gt;
&lt;P&gt;&amp;nbsp;mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x pae authenticator&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Piaa&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 09:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195219#M591845</guid>
      <dc:creator>keith-mk-li</dc:creator>
      <dc:date>2024-09-17T09:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195296#M591846</link>
      <description>&lt;P&gt;Depends what model of switches here, how your Layer 3 VLAN SVI have helper address or not ?&lt;/P&gt;
&lt;P&gt;Try adding on Site B. Access VLAN XXX (switchport access vlan 100) config and check.&lt;/P&gt;
&lt;P&gt;below guide help you for more information :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 11:33:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195296#M591846</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-09-17T11:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195299#M591847</link>
      <description>&lt;P&gt;authentication order mab dot1x &amp;lt;&amp;lt;- change the order make it dot1x mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authentication priority dot1x mab&lt;/P&gt;
&lt;P&gt;Then check&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 11:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195299#M591847</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-17T11:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195431#M591849</link>
      <description>&lt;P&gt;Did they successfully authenticate? You have not provided any information about the authentications from the respective switch.&lt;/P&gt;
&lt;P&gt;Without any other details, it sounds like a DHCP problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 14:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195431#M591849</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-09-17T14:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195707#M591866</link>
      <description>&lt;P&gt;The DHCP is leasing IP from the site itself, please find below running config and aaa loggings, i found there is no authentication sessions in the switch at all, kindly check any if the setting is correct ? in ISE i don't see any logging from this ip segment in this site&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2024.09.18 14:29:01 =~=~=~=~=~=~=~=~=~=~=~=&lt;BR /&gt;login as: cisco&lt;BR /&gt;Keyboard-interactive authentication prompts from server:&lt;BR /&gt;| Password:&lt;BR /&gt;End of keyboard-interactive prompts from server&lt;/P&gt;&lt;P&gt;Switch&amp;gt;en&lt;BR /&gt;Password:&lt;BR /&gt;Switch#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 58518 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 15:34:19 HKG Tue Sep 17 2024 by adm_kli&lt;BR /&gt;! NVRAM config last updated at 12:01:52 HKG Mon Sep 16 2024 by adm_klam&lt;BR /&gt;!&lt;BR /&gt;version 15.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec localtime&lt;BR /&gt;service timestamps log datetime msec localtime&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Switch&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;logging buffered 51200&lt;BR /&gt;enable secret 5&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;aaa group server radius ISE&lt;BR /&gt;server name ISE1&lt;BR /&gt;server name ISE2&lt;BR /&gt;deadtime 300&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login NO_AUTH none&lt;BR /&gt;aaa authentication login SSH-LOGIN local&lt;BR /&gt;aaa authentication dot1x default group ISE&lt;BR /&gt;aaa authorization network default group ISE&lt;BR /&gt;aaa accounting delay-start all&lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting auth-proxy default start-stop group ISE&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE&lt;BR /&gt;aaa accounting network default start-stop group ISE&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 10.12.101.10 server-key 7 01360xxxxxxxxxxxxxxx&lt;BR /&gt;client 10.12.101.11 server-key 7 14321xxxxxxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;aaa session-id common&lt;BR /&gt;clock timezone HKG 8 0&lt;BR /&gt;switch 1 provision ws-c2960x-48lps-l&lt;BR /&gt;switch 2 provision ws-c2960x-48lps-l&lt;BR /&gt;switch 3 provision ws-c2960x-48lps-l&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;login on-success log&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-2xxxxxxxxx&lt;BR /&gt;enrollment selfsigned&lt;BR /&gt;subject-name cn=IOS-Self-Signed-Certificate-2xxxxxxxxx&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair TP-self-signed-2xxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;crypto pki certificate chain TP-self-signed-2xxxxxxxx&lt;BR /&gt;certificate self-signed 01&lt;BR /&gt;quit&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode rapid-pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;vlan 3&lt;BR /&gt;name Devices&lt;BR /&gt;!&lt;BR /&gt;vlan 100&lt;BR /&gt;name WiFi&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel1&lt;BR /&gt;description uplink to C9200 Switch&lt;BR /&gt;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel2&lt;BR /&gt;description uplink to Server&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport nonegotiate&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; description User data port&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity 180&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/2&lt;BR /&gt;description User data port&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; authentication priority dot1x mab&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity 180&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/3&lt;BR /&gt;description User data port&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity 180&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==========================================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2024.09.18 16:33:36 =~=~=~=~=~=~=~=~=~=~=~=&lt;BR /&gt;login as: cisco&lt;BR /&gt;Keyboard-interactive authentication prompts from server:&lt;BR /&gt;| Password:&lt;BR /&gt;End of keyboard-interactive prompts from server&lt;/P&gt;&lt;P&gt;Switch&amp;gt;en&lt;BR /&gt;Password:&lt;BR /&gt;Switch#sh aaa server&lt;/P&gt;&lt;P&gt;RADIUS: id 1, priority 1, host 10.12.101.10, auth-port 1812, acct-port 1813&lt;BR /&gt;State: current UP, duration 4294967s, previous duration 18000s&lt;BR /&gt;Dead: total time 18000s, count 1&lt;BR /&gt;Quarantined: No&lt;BR /&gt;Authen: request 0, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Response: accept 0, reject 0, challenge 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 0&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;Author: request 0, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Response: accept 0, reject 0, challenge 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 0&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;Account: request 19, timeouts 19, failover 1, retransmission 14&lt;BR /&gt;Request: start 0, interim 0, stop 5&lt;BR /&gt;Response: start 0, interim 0, stop 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 5&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;Elapsed time since counters last cleared: 12w4h38m&lt;BR /&gt;Estimated Outstanding Access Transactions: 0&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; Estimated Outstanding Accounting Transactions: 0&lt;BR /&gt;Estimated Throttled Access Transactions: 0&lt;BR /&gt;Estimated Throttled Accounting Transactions: 0&lt;BR /&gt;Maximum Throttled Transactions: access 0, accounting 0&lt;BR /&gt;Requests per minute past 24 hours:&lt;BR /&gt;high - 3 hours, 45 minutes ago: 0&lt;BR /&gt;low - 3 hours, 45 minutes ago: 0&lt;BR /&gt;average: 0&lt;/P&gt;&lt;P&gt;RADIUS: id 2, priority 2, host 10.12.101.11, auth-port 1812, acct-port 1813&lt;BR /&gt;State: current UP, duration 4294967s, previous duration 18000s&lt;BR /&gt;Dead: total time 18000s, count 1&lt;BR /&gt;Quarantined: No&lt;BR /&gt;Authen: request 0, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Response: accept 0, reject 0, challenge 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 0&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;Author: request 0, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Response: accept 0, reject 0, challenge 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 0&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; Account: request 19, timeouts 19, failover 5, retransmission 14&lt;BR /&gt;Request: start 0, interim 0, stop 5&lt;BR /&gt;Response: start 0, interim 0, stop 0&lt;BR /&gt;Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt;Transaction: success 0, failure 5&lt;BR /&gt;Throttled: transaction 0, timeout 0, failure 0&lt;BR /&gt;Elapsed time since counters last cleared: 12w4h37m&lt;BR /&gt;Estimated Outstanding Access Transactions: 0&lt;BR /&gt;Estimated Outstanding Accounting Transactions: 0&lt;BR /&gt;Estimated Throttled Access Transactions: 0&lt;BR /&gt;Estimated Throttled Accounting Transactions: 0&lt;BR /&gt;Maximum Throttled Transactions: access 0, accounting 0&lt;BR /&gt;Requests per minute past 24 hours:&lt;BR /&gt;high - 3 hours, 44 minutes ago: 0&lt;BR /&gt;low - 3 hours, 44 minutes ago: 0&lt;BR /&gt;average: 0&lt;BR /&gt;Switch#sh aaa sessions&lt;BR /&gt;Total sessions since last reload: 108&lt;BR /&gt;Session Id: 176&lt;BR /&gt;Unique Id: 186&lt;BR /&gt;User Name: cisco&lt;BR /&gt;IP Address: 192.168.1.132&lt;BR /&gt;Idle Time: 0&lt;BR /&gt;CT Call Handle: 0&lt;BR /&gt;Switch# &amp;#8; &amp;#8;sh radius statistics&lt;BR /&gt;Auth. Acct. Both&lt;BR /&gt;Maximum inQ length: NA NA 2&lt;BR /&gt;Maximum waitQ length: NA NA 4&lt;BR /&gt;Maximum doneQ length: NA NA 1&lt;BR /&gt;Total responses seen: 68 134 202&lt;BR /&gt;Packets with responses: 68 134 202&lt;BR /&gt;Packets without responses: 0 4 4&lt;BR /&gt;Access Rejects : 0&lt;BR /&gt;Average response delay(ms): 1496 218 649&lt;BR /&gt;Maximum response delay(ms): 35379 5240 35379&lt;BR /&gt;Number of Radius timeouts: 8 40 48&lt;BR /&gt;Duplicate ID detects: 0 0 0&lt;BR /&gt;Buffer Allocation Failures: 0 0 0&lt;BR /&gt;Maximum Buffer Size (bytes): 279 335 335&lt;BR /&gt;Malformed Responses : 0 0 0&lt;BR /&gt;Bad Authenticators : 0 0 0&lt;BR /&gt;Unknown Responses : 0 0 0&lt;BR /&gt;Source Port Range: (2 ports only)&lt;BR /&gt;1645 - 1646&lt;BR /&gt;Last used Source Port/Identifier:&lt;BR /&gt;1645/68&lt;BR /&gt;1646/178&lt;/P&gt;&lt;P&gt;Elapsed time since counters last cleared: 39w3d12h30m&lt;BR /&gt;Radius Latency Distribution:&lt;BR /&gt;&amp;lt;= 2ms : 0 0&lt;BR /&gt;3-5ms : 0 0&lt;BR /&gt;5-10ms : 0 0&lt;BR /&gt;10-20ms: 0 0&lt;BR /&gt;20-50ms: 0 0&lt;BR /&gt;50-100m: 0 0&lt;BR /&gt;&amp;gt;100ms : 68 134&lt;/P&gt;&lt;P&gt;Current inQ length : 0&lt;BR /&gt;Current doneQ length: 0&lt;/P&gt;&lt;P&gt;Switch#sh aaa l&amp;#8; &amp;#8;clients&lt;/P&gt;&lt;P&gt;Dynamic Author Client 10.12.101.10&lt;BR /&gt;CoA: requests: 0, transactions: 0&lt;BR /&gt;retransmissions: 0, active transactions: 0&lt;BR /&gt;Ack responses: 0, Nak reponses: 0&lt;BR /&gt;invalid requests: 0, errors: 0&lt;BR /&gt;PoD: requests: 0, transactions: 0&lt;BR /&gt;retransmissions: 0, active transactions: 0&lt;BR /&gt;Ack responses: 0, Nak reponses: 0&lt;BR /&gt;invalid requests: 0, errors: 0&lt;BR /&gt;Average Ack response time: 0 msec&lt;BR /&gt;Requests per minute past 24 hours:&lt;BR /&gt;high - 3 hours, 45 minutes ago: 0&lt;BR /&gt;low - 3 hours, 45 minutes ago: 0&lt;BR /&gt;average: 0&lt;/P&gt;&lt;P&gt;Dynamic Author Client 10.12.101.11&lt;BR /&gt;CoA: requests: 0, transactions: 0&lt;BR /&gt;retransmissions: 0, active transactions: 0&lt;BR /&gt;Ack responses: 0, Nak reponses: 0&lt;BR /&gt;invalid requests: 0, errors: 0&lt;BR /&gt;PoD: requests: 0, transactions: 0&lt;BR /&gt;retransmissions: 0, active transactions: 0&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; Ack responses: 0, Nak reponses: 0&lt;BR /&gt;invalid requests: 0, errors: 0&lt;BR /&gt;Average Ack response time: 0 msec&lt;BR /&gt;Requests per minute past 24 hours:&lt;BR /&gt;high - 3 hours, 45 minutes ago: 0&lt;BR /&gt;low - 3 hours, 45 minutes ago: 0&lt;BR /&gt;average: 0&lt;/P&gt;&lt;P&gt;Dropped request packets: 0&lt;BR /&gt;Switch#sh aaa ss&amp;#8; &amp;#8;essions&lt;BR /&gt;Total sessions since last reload: 108&lt;BR /&gt;Session Id: 176&lt;BR /&gt;Unique Id: 186&lt;BR /&gt;&lt;BR /&gt;Switch# sh aaa user all&lt;BR /&gt;--------------------------------------------------&lt;BR /&gt;Unique id 186 is currently in use.&lt;BR /&gt;No data for type 0&lt;BR /&gt;No data for type EXEC&lt;BR /&gt;No data for type CONN&lt;BR /&gt;NET: Username=(n/a)&lt;BR /&gt;Session Id=000000B0 Unique Id=000000BA&lt;BR /&gt;Start Sent=0 Stop Only=N&lt;BR /&gt;stop_has_been_sent=N&lt;BR /&gt;Method List=0&lt;BR /&gt;Attribute list:&lt;BR /&gt;090CA57C 0 00000001 session-id(408) 4 176(B0)&lt;BR /&gt;090CA5B0 0 00000001 start_time(418) 4 Sep 18 2024 16:33:38&lt;BR /&gt;--------&lt;BR /&gt;No data for type CMD&lt;BR /&gt;No data for type SYSTEM&lt;BR /&gt;No data for type VRRS&lt;BR /&gt;No data for type RM CALL&lt;BR /&gt;No data for type RM VPDN&lt;BR /&gt;No data for type AUTH PROXY&lt;BR /&gt;No data for type DOT1X&lt;BR /&gt;No data for type CALL&lt;BR /&gt;No data for type VPDN-TUNNEL&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; No data for type VPDN-TUNNEL-LINK&lt;BR /&gt;No data for type IPSEC-TUNNEL&lt;BR /&gt;No data for type MCAST&lt;BR /&gt;No data for type RESOURCE&lt;BR /&gt;No data for type SSG&lt;BR /&gt;No data for type IDENTITY&lt;BR /&gt;No data for type ConnectedApps&lt;BR /&gt;Accounting:&lt;BR /&gt;log=0x18001&lt;BR /&gt;Events recorded :&lt;BR /&gt;CALL START&lt;BR /&gt;INTERIM START&lt;BR /&gt;INTERIM STOP&lt;BR /&gt;update method(s) :&lt;BR /&gt;NEWINFO&lt;BR /&gt;update interval = 0&lt;BR /&gt;Outstanding Stop Records : 0&lt;BR /&gt;Dynamic attribute list:&lt;BR /&gt;090CA57C 0 00000001 connect-progress(75) 4 No Progress&lt;BR /&gt;090CA5B0 0 00000001 pre-session-time(334) 4 65(41)&lt;BR /&gt;090CA5E4 0 00000001 elapsed_time(414) 4 0(0)&lt;BR /&gt;090CA618 0 00000001 pre-bytes-in(330) 4 0(0)&lt;BR /&gt;090CA64C 0 00000001 pre-bytes-out(331) 4 0(0)&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; 090CA680 0 00000001 pre-paks-in(332) 4 0(0)&lt;BR /&gt;090CA6B4 0 00000001 pre-paks-out(333) 4 0(0)&lt;BR /&gt;Debg: No data available&lt;BR /&gt;Radi: No data available&lt;BR /&gt;Interface:&lt;BR /&gt;TTY Num = 1&lt;BR /&gt;Stop Received = 0&lt;BR /&gt;Byte/Packet Counts till Call Start:&lt;BR /&gt;Start Bytes In = 0 Start Bytes Out = 0&lt;BR /&gt;Start Paks In = 0 Start Paks Out = 0&lt;BR /&gt;Byte/Packet Counts till Service Up:&lt;BR /&gt;Pre Bytes In = 0 Pre Bytes Out = 0&lt;BR /&gt;Pre Paks In = 0 Pre Paks Out = 0&lt;BR /&gt;Cumulative Byte/Packet Counts :&lt;BR /&gt;Bytes In = 0 Bytes Out = 0&lt;BR /&gt;Paks In = 0 Paks Out = 0&lt;BR /&gt;StartTime = 16:33:38 HKG Sep 18 2024&lt;BR /&gt;Component = Exec&lt;BR /&gt;Authen: service=LOGIN type=ASCII method=LOCAL&lt;BR /&gt;Kerb: No data available&lt;BR /&gt;Meth: No data available&lt;BR /&gt;Preauth: No Preauth data.&lt;BR /&gt;General:&lt;BR /&gt;--More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; Unique Id = 000000BA&lt;BR /&gt;Session Id = 000000B0&lt;BR /&gt;Attribute List:&lt;BR /&gt;090CA57C 0 00000081 interface(221) 4 tty1&lt;BR /&gt;090CA5B0 0 00000001 port-type(225) 4 Virtual Terminal&lt;BR /&gt;090CA5E4 0 00000081 clid(36) 14 192.168.81.161&lt;BR /&gt;PerU: No data available&lt;BR /&gt;Service Profile: No Service Profile data.&lt;BR /&gt;Unkn: No data available&lt;BR /&gt;Unkn: No data available&lt;/P&gt;&lt;P&gt;Switch#sh auth&lt;BR /&gt;Switch#sh authentication his&lt;/P&gt;&lt;P&gt;Switch#sh authentication his&amp;#8; &amp;#8;&amp;#8; &amp;#8;&amp;#8; &amp;#8;sessions&lt;BR /&gt;No sessions currently exist&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Piaa&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 08:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195707#M591866</guid>
      <dc:creator>keith-mk-li</dc:creator>
      <dc:date>2024-09-18T08:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195727#M591867</link>
      <description>&lt;P&gt;i found there is a GPO to changing the user computer network adapter EAP (PEAP) 802.1x, and i see in the switch &lt;STRONG&gt;"&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;aaa authentication login NO_AUTH none"&lt;/STRONG&gt;, does it mean the authentication has been been active in the switch and the NIC adapter has forced to use&amp;nbsp;EAP (PEAP) 802.1x, and its can not successfully authenticate that why can not reaching the LAN ? but its weird that for below, this devices need to be auth via the ISE by whitelisting the device mac address, as in the switch authenticate has not been active, how can this device to be able to reaching the LAN, any help would be appreicated&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet2/0/5&lt;BR /&gt;description Devices&amp;nbsp;&lt;BR /&gt;switchport access vlan 3&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication host-mode multi-host&lt;BR /&gt;authentication order mab&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch#sh authentication sessions int gi2/0/5&lt;BR /&gt;No sessions match supplied criteria.&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;Handle Priority Name&lt;BR /&gt;9 5 dot1x&lt;BR /&gt;16 10 mab&lt;BR /&gt;14 15 webauth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Piaa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 09:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5195727#M591867</guid>
      <dc:creator>keith-mk-li</dc:creator>
      <dc:date>2024-09-18T09:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5197501#M591927</link>
      <description>&lt;P&gt;This issue solved?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 10:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5197501#M591927</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-23T10:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Switch authentication issue on window computer</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5203028#M592160</link>
      <description>&lt;P&gt;not resolve&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 15:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-switch-authentication-issue-on-window-computer/m-p/5203028#M592160</guid>
      <dc:creator>keith-mk-li</dc:creator>
      <dc:date>2024-10-03T15:57:42Z</dc:date>
    </item>
  </channel>
</rss>

