<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 802.1x Authentication Failure - 12535 The EAP-TLS session tick in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5364994#M599632</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/112193"&gt;@matthew.goli1&lt;/a&gt;&amp;nbsp;Try disabling Credential Guard on client side:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=reg" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=reg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
    <pubDate>Sat, 24 Jan 2026 19:17:48 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2026-01-24T19:17:48Z</dc:date>
    <item>
      <title>ISE 802.1x Authentication Failure - 12535 The EAP-TLS session ticket</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5361273#M599546</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have been experiencing a number of Windows endpoints failing 802.1x authentication with the failure reason of "&lt;SPAN&gt;12535 The EAP-TLS session ticket received from supplicant is expired".&amp;nbsp; When this occurs the endpoint's Wired Event log shows this event message:&lt;BR /&gt;============================================&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;Wired 802.1X Authentication failed.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Network Adapter: Intel(R) Ethernet Connection (11) I219-LM&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Interface GUID: {caad02e9-f125-4451-bed6-b19c17cfd2b1}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Peer Address: 5067AECA6791&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Local Address: D8BBC181B75E&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Connection ID: 0x2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Identity: host/S23IA15.wfn.int&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;User: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Domain: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Reason: 0x50005&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Reason Text: The message received was unexpected or badly formatted.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Error Code: 0x80090326&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;============================================&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Googling this isn't turning up many answers for me yet.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;When the client fails 802.1x authentication, it then authenticates via MAB successfully, but our MAB policy places a Block all ACL on that endpoint causing a disruption.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;After a few minutes the client re-authenticates successfully with 802.1x.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;This is on an ISE deployment with ISE version 3.2 patch 9.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I did have a TAC open and we disabled "EAP TLS Session Resume" based on their recommendations but still seeing this issue occur randomly across different clients on our network.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Wondering if anyone here has some more insight on this issue and what can be done about it.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Matt.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 17:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5361273#M599546</guid>
      <dc:creator>matthew.goli1</dc:creator>
      <dc:date>2026-01-14T17:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x Authentication Failure - 12535 The EAP-TLS session tick</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5362978#M599586</link>
      <description>&lt;P&gt;I was under the impression that this relates to the Stateless Session Resume (which is separate to the EAP-TLS Session Resume feature - this feature is where the Server (ISE) keeps track of the session lifetime) - have you got this enabled still?&amp;nbsp; Try disabling that. I don't know how many vendor products support this (Windows native supplicant probably does).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1768871126077.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/258104i478642B84C414735/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1768871126077.png" alt="ArneBier_0-1768871126077.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 01:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5362978#M599586</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-01-20T01:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 802.1x Authentication Failure - 12535 The EAP-TLS session tick</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5364994#M599632</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/112193"&gt;@matthew.goli1&lt;/a&gt;&amp;nbsp;Try disabling Credential Guard on client side:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=reg" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure?tabs=reg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 19:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-802-1x-authentication-failure-12535-the-eap-tls-session/m-p/5364994#M599632</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-24T19:17:48Z</dc:date>
    </item>
  </channel>
</rss>

