<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lose connection between access switch and ISE servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277220#M595761</link>
    <description>&lt;P&gt;You can not do that&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Re-auth happened when timer end or interface is up/down&lt;/P&gt;
&lt;P&gt;When you disconnect device from SW-A and connect it to SW-B the SW-B will treat it as new auth even if timer is not end yet.&lt;/P&gt;
&lt;P&gt;What you want is open port for 802.1x and then close port for 802.1x one by one.&lt;/P&gt;
&lt;P&gt;It risky but there are no other options&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 01 Apr 2025 16:01:17 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-04-01T16:01:17Z</dc:date>
    <item>
      <title>Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277194#M595758</link>
      <description>&lt;P&gt;I'm migrating from an older WS-C3750X switch stack over to a C9300 switch stack. The C9300 switch stack is configured the same as the existing stack and will be racked up, stacking cabled up, and powered up alongside the existing switch. To minimize downtime in this medical environment, I'm going to shut down the management VLAN of the WS-C3750X switch stack and bring the C9300 switch stack onto the network. This will allow me to move the RJ-45 connections one at a time from the old to the new and the biggest impact to the end-users will be a momentary loss of connection or waiting for a VoIP device to reboot.&lt;/P&gt;
&lt;P&gt;My question is, when I shut down the management VLAN interface on the old switch stack it will lose connection to the ISE servers. I realize no new connections will be authenticated but I wanted to make sure existing connections will continue to be authorized until their timer runs out. In short, I want to make sure that loss of connection to the ISE servers won't cause existing connections to switch to unauthorized and stop passing traffic.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 14:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277194#M595758</guid>
      <dc:creator>dcasey</dc:creator>
      <dc:date>2025-04-01T14:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277212#M595759</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; &amp;nbsp;But in the end they will become unauthorized when the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;reauthentication timer interval expires &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;and the radius servers can no longer be reached.&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;On the switch the&lt;STRONG&gt; reauthentication timer interval&lt;/STRONG&gt; (session timer) can be downloaded to the switch &lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;from the RADIUS server using :&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Sw(config-if)#&lt;STRONG&gt;authentication timer reauthenticate server&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;For the settings on ISE (radius) checkout&amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315595/highlight/true#M96972" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-reauthentication-timer/m-p/2315595/highlight/true#M96972&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; But then one sufficient high timer value should have been provisioned on the previous authentication of the device.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; That there will be no troubles can not be guaranteed in my opinion. Consider a flow&amp;nbsp; for dedicated migrating of&lt;BR /&gt;&amp;nbsp; &amp;nbsp; equipment to the new stack taking into account the medical environment,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 15:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277212#M595759</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-04-01T15:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277220#M595761</link>
      <description>&lt;P&gt;You can not do that&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Re-auth happened when timer end or interface is up/down&lt;/P&gt;
&lt;P&gt;When you disconnect device from SW-A and connect it to SW-B the SW-B will treat it as new auth even if timer is not end yet.&lt;/P&gt;
&lt;P&gt;What you want is open port for 802.1x and then close port for 802.1x one by one.&lt;/P&gt;
&lt;P&gt;It risky but there are no other options&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 16:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277220#M595761</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-01T16:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277227#M595762</link>
      <description>&lt;P&gt;That is how I understood it I just needed a sanity check to make sure before I say one thing and something else happens. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 16:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277227#M595762</guid>
      <dc:creator>dcasey</dc:creator>
      <dc:date>2025-04-01T16:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277229#M595763</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;When you disconnect device from SW-A and connect it to SW-B the SW-B will treat it as new auth even if timer is not end yet."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;That's actually perfect and what I want. I just wanted to make sure if I shut down the management VLAN interface on the old switch stack (so I could bring the new switch stack online using the same management IP address) the connected devices on the old switch stack wouldn't all go unauthorized immediately. Once I move the RJ-45 cable from the old to the new stack I'm fine with them going through the authorization process again and being able to pass traffic.&lt;/P&gt;
&lt;P&gt;Thank you for your reply!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 16:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277229#M595763</guid>
      <dc:creator>dcasey</dc:creator>
      <dc:date>2025-04-01T16:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Lose connection between access switch and ISE servers</title>
      <link>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277236#M595764</link>
      <description>&lt;P&gt;Let me check log off message.&lt;/P&gt;
&lt;P&gt;I will update you if I get something useful.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 16:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lose-connection-between-access-switch-and-ise-servers/m-p/5277236#M595764</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-01T16:17:48Z</dc:date>
    </item>
  </channel>
</rss>

