<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5436 RADIUS packet already in the process in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244802#M594080</link>
    <description>&lt;P&gt;I've now upgraded to 3.0.4.608 Patch 1 but I'm still seeing the same errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alliasneo1_0-1736348412922.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237201iC9B382E6BF9FB49F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alliasneo1_0-1736348412922.png" alt="alliasneo1_0-1736348412922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alliasneo1_1-1736348450406.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237202i88426693EC97AC09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alliasneo1_1-1736348450406.png" alt="alliasneo1_1-1736348450406.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2025 15:00:56 GMT</pubDate>
    <dc:creator>alliasneo1</dc:creator>
    <dc:date>2025-01-08T15:00:56Z</dc:date>
    <item>
      <title>5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244293#M594044</link>
      <description>&lt;P&gt;Hi, has anyone seen this before or offer any advice?&lt;/P&gt;&lt;P&gt;Running ISE 3.4.068 with no patches installed.&lt;/P&gt;&lt;P&gt;Lots of devices are no longer matching against my polcies. Occassionaly they will match like in the example below but they will then continue in the logs as a fail. when I click on the details icon I get the following message:&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5436 RADIUS packet already in the process&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;5436 RADIUS packet already in the process&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Resolution&lt;/TD&gt;&lt;TD&gt;Check whether the Average RADIUS Request Latency statistic is close to or exceeds the client's RADIUS request timeout. If so, determine whether the latency is caused by a slow external Identity Store or because this instance of ISE is being overloaded. To resolve this, increase the client's RADIUS request timeout, using a faster or additional, external Identity Stores, or reduce the load on this instance of ISE.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Root cause&lt;/TD&gt;&lt;TD&gt;Ignoring this request because it is a duplicate of another packet that is currently being processed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alliasneo1_0-1736246882698.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237118i018795E4491BC630/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alliasneo1_0-1736246882698.png" alt="alliasneo1_0-1736246882698.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 10:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244293#M594044</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-07T10:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244301#M594045</link>
      <description>&lt;P&gt;....&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244301#M594045</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-09T08:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244309#M594046</link>
      <description>&lt;P&gt;We have 2 deployment nodes with Admin, Monitoring and Policy Service on both and pxGrid on one.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 11:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244309#M594046</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-07T11:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244316#M594047</link>
      <description>&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244316#M594047</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-09T08:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244324#M594048</link>
      <description>&lt;P&gt;And what is load balance you use ? - &lt;STRONG&gt;I'm not sure if I've set load balancing up, I've registered both nodes, one as a primary and one as a secondary. What else would I need to do?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;How you config NAD to send request to both PSN?&lt;STRONG&gt; The commands on the Switch have both ISE nodes configured under the radius and aaa config&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 11:36:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244324#M594048</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-07T11:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244325#M594049</link>
      <description>&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244325#M594049</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-09T08:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244346#M594050</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286969"&gt;@alliasneo1&lt;/a&gt; install ISE 3.4 patch 1, you could be hitting this bug &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwm38826" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwm38826&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="qtr-margin-top"&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt; RADIUS Packets are incorrectly being dropped with failure reason "&lt;U&gt;RADIUS: RADIUS packet already in the process&lt;/U&gt;" after upgrading to or installing ISE 3.4. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="qtr-margin-top"&gt;&lt;STRONG&gt;Conditions:&lt;/STRONG&gt; ISE is running 3.4.0.608 with the "Reject RADIUS requests from clients with repeated failures" RADIUS suppression feature enabled. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="qtr-margin-top"&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt; Disable RADIUS suppression for "Reject RADIUS requests from clients with repeated failures" in Administration &amp;gt; System &amp;gt; Settings &amp;gt; Protocols &amp;gt; RADIUS and restart services in the PSN using "app stop ise" and "app start ise" to clear the sessions stuck in the duplicate manager. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="qtr-margin-top"&gt;This is resolved in ISE 3.4 patch 1, so install the latest patch.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="qtr-margin-top"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/b_ise_34_RN.html#c-resolved_caveats_34p1" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/release_notes/b_ise_34_RN.html#c-resolved_caveats_34p1&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 12:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244346#M594050</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-07T12:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244549#M594067</link>
      <description>&lt;P&gt;Regarding RADIUS load balancing in IOS-XE devices, it's really simple and very effective. One command under the aaa group statement - e.g. in my example, the aaa group is called "dnac-client-radius-group" :&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;conf t
aaa group server radius dnac-client-radius-group
  load-balance method least-outstanding
  end
wr mem
&lt;/LI-CODE&gt;
&lt;P&gt;You can check the effectiveness of the load balancing with the "show aaa servers" command:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;CSR#show aaa servers | in request
     Authen: request 22, timeouts 20, failover 0, retransmission 15
     Author: request 3, timeouts 0, failover 0, retransmission 0
     Account: request 0, timeouts 0, failover 0, retransmission 0
     Authen: request 22, timeouts 20, failover 0, retransmission 15
     Author: request 0, timeouts 0, failover 0, retransmission 0
     Account: request 0, timeouts 0, failover 0, retransmission 0
&lt;/LI-CODE&gt;
&lt;P&gt;The first three rows are RADIUS server 1, and the last three rows are RADIUS server 2.&lt;/P&gt;
&lt;P&gt;You should also reset the counters after enabling load balancing to see an accurate result&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;clear aaa counters servers radius all&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 20:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244549#M594067</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-07T20:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244793#M594078</link>
      <description>&lt;P&gt;Hi, thanks for this, it looks like it's working now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch#sh aaa servers | in req&lt;BR /&gt;Authen: request 63, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Author: request 1, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Account: request 31, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Authen: request 61, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Author: request 0, timeouts 0, failover 0, retransmission 0&lt;BR /&gt;Account: request 19, timeouts 0, failover 0, retransmission 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't have this configured on any switches so I think that's good now&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 14:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244793#M594078</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-08T14:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244794#M594079</link>
      <description>&lt;P&gt;Hey, thanks for this.&lt;/P&gt;&lt;P&gt;I've spent today updating the nodes and I'm now running 3.0.4.608 Patch 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I'm still seeing the Misconfigured supplicants and the same error message.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 14:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244794#M594079</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-08T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244802#M594080</link>
      <description>&lt;P&gt;I've now upgraded to 3.0.4.608 Patch 1 but I'm still seeing the same errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alliasneo1_0-1736348412922.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237201iC9B382E6BF9FB49F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alliasneo1_0-1736348412922.png" alt="alliasneo1_0-1736348412922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alliasneo1_1-1736348450406.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237202i88426693EC97AC09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alliasneo1_1-1736348450406.png" alt="alliasneo1_1-1736348450406.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 15:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244802#M594080</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-08T15:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244828#M594082</link>
      <description>&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244828#M594082</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-09T08:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244934#M594088</link>
      <description>&lt;P&gt;Is this happening on switches or wireless?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does your IOS config look like?&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show run | section radius
show derived int x/y/z (example switch interface with NAC enabled)
show access-session int x/y/z detail&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What endpoint is this (Windows PC, etc.?) - does the endpoint have a 802.1X supplicant configured?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco best practice: RADIUS Accounting is normally set to send Interim-Updates only if there has been an update from the Device Sensor (if configured) and latest, every 2880 minutes (48 hours) if there have been no updates.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 21:23:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5244934#M594088</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-08T21:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245071#M594098</link>
      <description>&lt;P&gt;#&lt;STRONG&gt;sh run | section radius&lt;/STRONG&gt;&lt;BR /&gt;aaa group server radius &lt;STRONG&gt;XXX&lt;/STRONG&gt;&lt;BR /&gt;server name &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;server name &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;ip radius source-interface &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;load-balance method least-outstanding&lt;BR /&gt;aaa authorization auth-proxy default group radius&lt;BR /&gt;aaa accounting system default start-stop group radius&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client &lt;STRONG&gt;XXXX&lt;/STRONG&gt; server-key &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;client &lt;STRONG&gt;XXXX&lt;/STRONG&gt; server-key &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;auth-type any&lt;BR /&gt;radius-server attribute 44 include-in-access-req default-vrf&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf upper-case&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server deadtime 10&lt;BR /&gt;radius server &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;address ipv4 &lt;STRONG&gt;XXXX&lt;/STRONG&gt; auth-port 1812 acct-port 1813&lt;BR /&gt;timeout 5&lt;BR /&gt;retransmit 3&lt;BR /&gt;key &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;radius server &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;BR /&gt;address ipv4 &lt;STRONG&gt;XXXX&lt;/STRONG&gt; auth-port 1812 acct-port 1813&lt;BR /&gt;timeout 5&lt;BR /&gt;retransmit 3&lt;BR /&gt;key &lt;STRONG&gt;XXXX&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are all 9200 switches.&lt;/P&gt;&lt;P&gt;This is happening with devices that are not configured with dot1x. so for example a windows laptop with no dot1x so it doesn't authenticate but then even when it is unplugged its still showing up under &lt;STRONG&gt;#sh authentication sessions&lt;/STRONG&gt; and it repeates the authentication every 60 seconds on the port. If I manually go in and clear the sessions then it clears it out.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 08:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245071#M594098</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-09T08:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245370#M594108</link>
      <description>&lt;P&gt;You need to share your interface config. I want to see if this is IBNS 1.0 or 2.0 and if it's 2.0, then we also need to see the policy-map logic.&amp;nbsp; It sounds to me like the MAB is not successful (status = 'UNAUTHORIZED'), and that causes the NAC logic in the switch to clear the session and start over again.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show derived int x/y/z
show access-session int x/y/z detail&lt;/LI-CODE&gt;
&lt;P&gt;If IBNS 2.0 then also the policy-map (the policy referred to in the interface config)&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show policy-map type control subscriber&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 21:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245370#M594108</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-09T21:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245607#M594125</link>
      <description>&lt;P&gt;Hi, This is my Interface config on all my switches:&lt;/P&gt;&lt;P&gt;int g1/0/1&lt;/P&gt;&lt;P&gt;switchport access vlan X&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan X&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;no logging event link-status&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication host-mode multi-auth&lt;BR /&gt;authentication open&lt;BR /&gt;authentication order dot1x mab&lt;BR /&gt;authentication priority dot1x mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate 65535&lt;BR /&gt;authentication violation restrict&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;auto qos trust&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the policy-map command:&lt;/P&gt;&lt;P&gt;GHC-ISETEST-EJC-SW01#show policy-map type control subscriber&lt;BR /&gt;BUILTIN_AUTOCONF_POLICY&lt;BR /&gt;event identity-update match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 map attribute-to-service table BUILTIN_DEVICE_TO_TEMPLATE&lt;BR /&gt;POLICY_Gi1/0/10&lt;BR /&gt;event session-started match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 authenticate using dot1x retries 2 retry-time 0 priority 10&lt;BR /&gt;event authentication-failure match-first&lt;BR /&gt;5 class DOT1X_FAILED do-until-failure&lt;BR /&gt;10 terminate dot1x&lt;BR /&gt;20 authenticate using mab priority 20&lt;BR /&gt;10 class DOT1X_NO_RESP do-until-failure&lt;BR /&gt;10 terminate dot1x&lt;BR /&gt;20 authenticate using mab priority 20&lt;BR /&gt;20 class MAB_FAILED do-until-failure&lt;BR /&gt;10 terminate mab&lt;BR /&gt;20 authentication-restart 60&lt;BR /&gt;40 class DOT1X_TIMEOUT do-until-failure&lt;BR /&gt;10 terminate dot1x&lt;BR /&gt;20 authenticate using mab priority 20&lt;BR /&gt;50 class always do-until-failure&lt;BR /&gt;10 terminate dot1x&lt;BR /&gt;20 terminate mab&lt;BR /&gt;30 authentication-restart 60&lt;BR /&gt;event agent-found match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 terminate mab&lt;BR /&gt;20 authenticate using dot1x retries 2 retry-time 0 priority 10&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template DEFAULT_LINKSEC_POLICY_SHOULD_SECURE&lt;BR /&gt;event violation match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 restrict&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 10:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245607#M594125</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-01-10T10:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245638#M594126</link>
      <description>&lt;P&gt;Sorry I am busy now' maybe other VIP can help you.&lt;/P&gt;
&lt;P&gt;Goodluck&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 12:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5245638#M594126</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-10T12:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5249325#M594302</link>
      <description>&lt;P&gt;I don't have an IBNS 1.0 switch to check the command syntax, but you should never have sessions showing AFTER a physical interface is disconnected.&amp;nbsp; Unless ... is that device that is disconnected connected to the back of a desk-phone (and phone is physically attached to the switch)?&amp;nbsp; If the phone is not configured correctly, it won't send the disconnect on behalf of the connected device.&lt;/P&gt;
&lt;P&gt;In IBNS 2.0 there is a very clear Policy that ensures that disconnected endpoints are cleared&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;policy-map type control subscriber PORT-AUTH-POLICY-I
...
...
  event inactivity-timeout match-all
    10 class always do-until-failure
     10 clear-session
...
...&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 00:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5249325#M594302</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-20T00:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5271413#M595488</link>
      <description>&lt;P&gt;You are hitting a known bug:&amp;nbsp;&amp;nbsp;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwh80062" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCwh80062&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 16:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5271413#M595488</guid>
      <dc:creator>cklam</dc:creator>
      <dc:date>2025-03-14T16:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5274528#M595603</link>
      <description>&lt;P&gt;Thanks for the reply. Yes everything in that bug matches up with what I'm seeing. Doesn't look like there is a fix at this time?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 11:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5436-radius-packet-already-in-the-process/m-p/5274528#M595603</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2025-03-24T11:00:58Z</dc:date>
    </item>
  </channel>
</rss>

