<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with Device Authentication on ISE: Intermittent Disconnecti in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254825#M594656</link>
    <description>&lt;P&gt;Remove port secuirty&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then share&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show authentication session interface x/x detail&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 14:58:34 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-01-30T14:58:34Z</dc:date>
    <item>
      <title>Issues with Device Authentication on ISE: Intermittent Disconnections</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254562#M594631</link>
      <description>&lt;P&gt;We are experiencing unstable connectivity between endpoint devices and Cisco ISE. Random disconnections occur at unpredictable times, and standard troubleshooting methods (shut/no shut, removing port-security) do not resolve the issue. The only temporary solution is to remove the ISE configuration from the port, after which connectivity is restored. Additionally, authentication failures are observed, where devices (PCs or phones) fail to authenticate depending on the configured mode (multi-auth or multi-domain). Help me understand the problem&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 04:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254562#M594631</guid>
      <dc:creator>t-musin</dc:creator>
      <dc:date>2025-01-30T04:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Device Authentication on ISE: Intermittent Disconnecti</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254721#M594645</link>
      <description>&lt;P&gt;Is there a network problem?&amp;nbsp; Is the AAA server alive from the NAD prospective?&amp;nbsp; What is the NAD?&amp;nbsp; Wired or wireless?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 11:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254721#M594645</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-30T11:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Device Authentication on ISE: Intermittent Disconnecti</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254730#M594649</link>
      <description>&lt;P&gt;No network problems,&lt;/P&gt;&lt;P&gt;If I understand the meaning of the word NAD correctly, we are using Cat9300 for user connection&lt;BR /&gt;&lt;BR /&gt;Communication with the radius server is available. The problem is solved by removing the ISE configuration from the port&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 12:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254730#M594649</guid>
      <dc:creator>t-musin</dc:creator>
      <dc:date>2025-01-30T12:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Device Authentication on ISE: Intermittent Disconnecti</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254819#M594655</link>
      <description>&lt;P&gt;By your logs, port security is shutting the ports down. Not sure why as you have max3 and it only has 2 stored. On the other hand with 802.1x and MAB you probably don't need port security as it would be a nightmare to manage if PCs move around.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, there are many ways to do it, but this is what we do.&lt;/P&gt;&lt;P&gt;1, Set an ACL on the port that grants minimal access needed to authenticate. Block everything else.&lt;/P&gt;&lt;P&gt;2, If ISE authenticates, send down a dACL that will replace the restrictive one for more access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another note since you are doing MAB, on 3850 and 9300 if you reverse the commands it will do MAB and 802.1x at the same time instead of waiting for the 802.1x timer to run out before doing MAB.&lt;/P&gt;&lt;P&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority dot1x mab&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Nov  6 15:59:36: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/18, changed state to up
Nov  6 16:00:15: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (0025.8416.ee01) with reason (No Response from Client) on Interface Gi1/0/18 AuditSessionID 000000000001721B01218909
Nov  6 16:01:58: %PM-4-ERR_DISABLE: security-violation error detected on Gi1/0/18, putting Gi1/0/18 in err-disable state
Nov  6 16:01:58: %AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet1/0/18, new MAC address (80e8.2c27.63cb) is seen.AuditSessionID  lwiwiHH^D(^K&amp;lt;[S
Nov  6 16:01:58: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (80e8.2c27.63cb) with reason (No Response from Client) on Interface Gi1/0/18 AuditSessionID 000000000001721C01231D59
Nov  6 16:01:59: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/18, changed state to down&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 14:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254819#M594655</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2025-01-30T14:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Device Authentication on ISE: Intermittent Disconnecti</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254825#M594656</link>
      <description>&lt;P&gt;Remove port secuirty&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then share&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show authentication session interface x/x detail&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 14:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5254825#M594656</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-30T14:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Device Authentication on ISE: Intermittent Disconnecti</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5255106#M594686</link>
      <description>&lt;P&gt;802.1X and Port Security are &lt;EM&gt;&lt;STRONG&gt;incompatible &lt;/STRONG&gt;&lt;/EM&gt;and fight for control of the port. Remove Port Security.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 00:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-device-authentication-on-ise-intermittent/m-p/5255106#M594686</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2025-01-31T00:19:30Z</dc:date>
    </item>
  </channel>
</rss>

