<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5568800#M600985</link>
    <description>&lt;P&gt;also on the 3750X switch port when i see the config as below, i dont see any command related to access-session host-mode multi-auth which was configured on it .&amp;nbsp; i have tried single mode as well but still the same issue&lt;/P&gt;&lt;P&gt;lab-switch#show run int gigabitEthernet 1/0/1&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 226 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication periodic&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;end&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2026 10:09:10 GMT</pubDate>
    <dc:creator>atifali.zaidi1</dc:creator>
    <dc:date>2026-08-11T10:09:10Z</dc:date>
    <item>
      <title>cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564936#M600797</link>
      <description>&lt;P&gt;Hello experts , i have just created my home lab for cisco ISE wired 802.1x , initially i am testing "open" mode ,&amp;nbsp; i have the following components&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ISE VM running 3.3 and patch 11&lt;/P&gt;&lt;P&gt;cisco 3750X running IOS 15.4&lt;/P&gt;&lt;P&gt;windows server 2025 configuring for ADDS and ADCS&amp;nbsp;&lt;/P&gt;&lt;P&gt;i followed the wired 802.1x prescriptive guide and using a windows machine ( with USB to ethernet adaptor ) as the physical ethernet port is damaged , have configured all the authentication settings on the machine , for example - PEAP with&amp;nbsp; mschapv2 etc . the machine is domain joined to the local AD server domain .&amp;nbsp; the ports on the switch are configured with 802.1x but when the machine is plugged in to the port , i get the below messages after i enabled - debug dot1x all&lt;/P&gt;&lt;P&gt;ISE is integrated with AD m joined as well , the test connection works&amp;nbsp;&lt;/P&gt;&lt;P&gt;test aaa command from the switch works with a dummy user , as i can see logs on ISE&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan 2 00:07:36.692: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down&lt;BR /&gt;*Jan 2 00:07:38.378: %SYS-5-CONFIG_I: Configured from console by lab on vty0 (192.168.1.3)&lt;BR /&gt;*Jan 2 00:07:50.189: dot1x-ev:[Gi1/0/1] Interface state changed to UP&lt;BR /&gt;*Jan 2 00:07:50.198: dot1x-ev:DOT1X Supplicant not enabled on GigabitEthernet1/0/1&lt;BR /&gt;*Jan 2 00:07:52.186: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to up&lt;BR /&gt;*Jan 2 00:07:53.192: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to up&lt;/P&gt;&lt;P&gt;i dont see any hits on ISE as well, i also tried another non-domain joined windows machine as well but still the same issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;lab-switch#show dot1x interface gigabitEthernet 1/0/1 details&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet1/0/1 -----------------------------------&lt;/P&gt;&lt;P&gt;PAE = AUTHENTICATOR QuietPeriod = 60&lt;/P&gt;&lt;P&gt;ServerTimeout = 0 SuppTimeout = 30 ReAuthMax = 3 MaxReq = 2 TxPeriod = 7 Dot1x Authenticator Client List Empty&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;lab-switch#show access-session interface gigabitEthernet 1/0/1 Interface MAC Address Method Domain Status Fg Session ID ---------------------------------------------------------------------- Gi1/0/1 xxxx.xxxx.xxxx N/A UNKNOWN Unauth C0A8011900000010000EDE3B Key to Session Events Blocked Status Flags: A - Applying Policy (multi-line status for details) D - Awaiting Deletion F - Final Removal in progress I - Awaiting IIF ID allocation N - Waiting for AAA to come up P - Pushed Session R - Removing User Profile (multi-line status for details) U - Applying User Profile (multi-line status for details) X - Unknown Blocker Runnable methods list: Handle Priority Name 6 5 dot1x 21 10 mab 19 15 webauth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 04:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564936#M600797</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-20T04:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564946#M600798</link>
      <description>&lt;P&gt;Have you tested the RADIUS comms to your ISE?&lt;/P&gt;
&lt;P&gt;Easiest test&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;test aaa group &amp;lt;radius_group_name&amp;gt; test test new-code&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;where &amp;lt;radius_group_name&amp;gt; is your aaa radius group name&lt;/P&gt;
&lt;P&gt;If RADIUS is working you will see a PAP request in ISE.&amp;nbsp; Username "test", password "test" - and be rejected. That is expected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does your Radius config look like? Please share:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show run | section radius
show run | in aaa&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 05:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564946#M600798</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-07-20T05:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564950#M600799</link>
      <description>&lt;P&gt;thanks for the reply , i did run the above commands on the switch , on the ISE side i could see user rejected , but it also mentioned -PAP is not enabled .&amp;nbsp; &amp;nbsp;i will post all the outputs as you requested soon.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 06:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5564950#M600799</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-20T06:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565142#M600813</link>
      <description>&lt;P&gt;I missed that part in your opening post that contained the "test" command. In that case we'd need to see your radius config, as well as the interface config please.&lt;/P&gt;
&lt;P&gt;Is the Windows client (supplicant) configured for machine auth, or user or both?&lt;/P&gt;
&lt;P&gt;There is another IOS command you can run on the switch to test if the supplicant can respond to EAPOL frames (a handy check to see if the supplicant is running)&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dot1x test eapol-capable interface gigabitEthernet 1/0/1&lt;/LI-CODE&gt;
&lt;P&gt;You won't get any response to that command. You must look in the logs&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show logging | include 1/0/1&lt;/LI-CODE&gt;
&lt;P&gt;If it worked, you'll see a message that client on gig 1/0/1 is 802.1X capable.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 21:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565142#M600813</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-07-20T21:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565463#M600827</link>
      <description>&lt;P&gt;i am attaching some results , please have a look, still no hits on ISE&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 06:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565463#M600827</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-22T06:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565465#M600828</link>
      <description>&lt;P&gt;ISE rules&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 06:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565465#M600828</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-22T06:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565474#M600829</link>
      <description>&lt;P&gt;I'm not a big fan of opening Word documents off the internet - perhaps in future just paste the images into these chats - you can copy paste them straight in.&lt;/P&gt;
&lt;P&gt;The switch config looks alright.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ISE AuthZ Rule below is wrong - because with PEAP you will never get User and Computer auth from any Windows client&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArneBier_0-1784705350106.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/284825i59DF0B23BD52BAE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="ArneBier_0-1784705350106.png" alt="ArneBier_0-1784705350106.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In your lab, change that to an OR instead.&lt;/P&gt;
&lt;P&gt;If you want EAP chaining, look at EAP-TEAP instead. But that's a more advanced topic. Focus on getting a computer auth working. Windows issues a Computer auth during Windows boot up, and user log off.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have not shared your Windows supplicant config. That might also reveal something,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 07:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565474#M600829</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-07-22T07:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565475#M600830</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;BLOCKQUOTE&gt;&lt;P class=""&gt;The key message is this:&lt;/P&gt;&lt;P&gt;dot1x-ev: DOT1X Supplicant not enabled on GigabitEthernet1/0/1&lt;/P&gt;&lt;P&gt;That usually means the switch isn't seeing any EAPOL (802.1X) frames from the connected device, which explains why nothing reaches ISE.&lt;/P&gt;&lt;P&gt;Since test aaa is working and ISE is successfully joined to AD, the RADIUS path looks fine. I'd focus on the endpoint and switch port instead.&lt;/P&gt;&lt;P&gt;A few things I'd check:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure the &lt;STRONG&gt;Wired AutoConfig&lt;/STRONG&gt; service is running on the Windows client. Without it, Windows won't start 802.1X.&lt;/LI&gt;&lt;LI&gt;Verify that &lt;STRONG&gt;IEEE 802.1X authentication&lt;/STRONG&gt; is enabled on the Ethernet adapter (including the USB-to-Ethernet adapter). Some USB NICs have limited or inconsistent 802.1X support depending on the driver.&lt;/LI&gt;&lt;LI&gt;Run a packet capture (Wireshark) on the client and check whether EAPOL packets are being sent when the cable is plugged in.&lt;/LI&gt;&lt;LI&gt;Double-check the switch interface configuration (authentication port-control auto, dot1x pae authenticator, etc.) to make sure 802.1X is actually enabled on that port.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you also post the output of:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;&lt;SPAN&gt;show run interface gi1/0/1
show authentication sessions interface gi1/0/1 details
show dot1x all&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;I suspect the issue is before the authentication even reaches ISE, so those outputs should help narrow it down.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jul 2026 07:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565475#M600830</guid>
      <dc:creator>hellencharless54</dc:creator>
      <dc:date>2026-07-22T07:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565519#M600831</link>
      <description>&lt;P&gt;thanks for the valuable feedback , the wired autoconfig is set to automatic on the windows 10 machine ,&amp;nbsp; under authentication settings , PEAP is there with validate server cert option checked .&amp;nbsp; the machine is AD joined and has the Root CA cert from AD which is gets once it joins the AD .&amp;nbsp; &amp;nbsp;mschapv2 option is checked with the option "automatically use my windows username and password&amp;nbsp; , also user or machine authentication is checked . i will paste some screenshots for the same.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 13:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565519#M600831</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-22T13:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565521#M600832</link>
      <description>&lt;P&gt;here are some outputs&amp;nbsp;&lt;/P&gt;&lt;P&gt;lab-switch#test aaa group ISE test-user password new-code&lt;/P&gt;&lt;P&gt;User rejected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;lab-switch#test aaa group ISE test-user password legacy&lt;/P&gt;&lt;P&gt;Attempting authentication test to server-group ISE using radius&lt;/P&gt;&lt;P&gt;User authentication request was rejected by server.&lt;/P&gt;&lt;P&gt;lab-switch#show running-config | i aaa&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server radius ISE&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group ISE&lt;/P&gt;&lt;P&gt;aaa authorization network default group ISE&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo periodic 2880&lt;/P&gt;&lt;P&gt;aaa accounting identity default start-stop group ISE&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;lab-switch#show running-config | sec radius&lt;/P&gt;&lt;P&gt;aaa group server radius ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;server name labise-01&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;&amp;nbsp;client 192.168.1.21 server-key Frostbite456@&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan1&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server attribute 31 mac format ietf upper-case&lt;/P&gt;&lt;P&gt;radius-server attribute 31 send nas-port-detail mac-only&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 10 tries 3&lt;/P&gt;&lt;P&gt;radius server labise-01&lt;/P&gt;&lt;P&gt;&amp;nbsp;address ipv4 192.168.1.21 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;lab-switch#show running-config | i source&lt;/P&gt;&lt;P&gt;ip ssh source-interface Vlan1&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;lab-switch#dot1x test eapol-capable interface gigabitEthernet 1/0/1&lt;/P&gt;&lt;P&gt;lab-switch#&lt;/P&gt;&lt;P&gt;logs from the port&lt;/P&gt;&lt;P&gt;lab-switch(config-if)#&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:56:49.906: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:02.581: dot1x-ev:[Gi1/0/1] Interface state changed to UP&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:02.581: dot1x-ev:DOT1X Supplicant not enabled on GigabitEthernet1/0/1&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-packet:[00e0.4c63.5bc8, Gi1/0/1] queuing an EAPOL pkt on Auth Q&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-packet:EAPOL pak rx - Ver: 0x1&amp;nbsp; type: 0x1&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-packet: length: 0x0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-ev:[Gi1/0/1] Dequeued pkt: Int Gi1/0/1 CODE= 0,TYPE= 0,LEN= 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-ev:[Gi1/0/1] Received pkt saddr =00e0.4c63.5bc8 , daddr = 0180.c200.0003, pae-ether-type = 888e.0101.0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-ev:[Gi1/0/1] Couldn't find the supplicant in the list&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:03.076: dot1x-ev:[00e0.4c63.5bc8, Gi1/0/1] New client detected, sending session start event for 00e0.4c63.5bc8&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:04.569: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to up&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:05.576: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to up&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-packet:[00e0.4c63.5bc8, Gi1/0/1] queuing an EAPOL pkt on Auth Q&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-packet:EAPOL pak rx - Ver: 0x1&amp;nbsp; type: 0x1&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-packet: length: 0x0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-ev:[Gi1/0/1] Dequeued pkt: Int Gi1/0/1 CODE= 0,TYPE= 0,LEN= 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-ev:[Gi1/0/1] Received pkt saddr =00e0.4c63.5bc8 , daddr = 0180.c200.0003, pae-ether-type = 888e.0101.0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-ev:[Gi1/0/1] Couldn't find the supplicant in the list&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:08.059: dot1x-ev:[00e0.4c63.5bc8, Gi1/0/1] New client detected, sending session start event for 00e0.4c63.5bc8&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-packet:[00e0.4c63.5bc8, Gi1/0/1] queuing an EAPOL pkt on Auth Q&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-packet:EAPOL pak rx - Ver: 0x1&amp;nbsp; type: 0x1&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-packet: length: 0x0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-ev:[Gi1/0/1] Dequeued pkt: Int Gi1/0/1 CODE= 0,TYPE= 0,LEN= 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-ev:[Gi1/0/1] Received pkt saddr =00e0.4c63.5bc8 , daddr = 0180.c200.0003, pae-ether-type = 888e.0101.0000&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-ev:[Gi1/0/1] Couldn't find the supplicant in the list&lt;/P&gt;&lt;P&gt;*Jan&amp;nbsp; 2 01:57:13.075: dot1x-ev:[00e0.4c63.5bc8, Gi1/0/1] New client detected, sending session start event for 00e0.4c63.5bc8&lt;/P&gt;&lt;P&gt;lab-switch#show dot1x interface gigabitEthernet 1/0/1&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet1/0/1&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;QuietPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 60&lt;/P&gt;&lt;P&gt;ServerTimeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 0&lt;/P&gt;&lt;P&gt;SuppTimeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 30&lt;/P&gt;&lt;P&gt;ReAuthMax&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 3&lt;/P&gt;&lt;P&gt;MaxReq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 2&lt;/P&gt;&lt;P&gt;TxPeriod&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = 7&lt;/P&gt;&lt;P&gt;lab-switch#show access-session interface gigabitEthernet 1/0/1 details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet1/0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 00e0.4c63.5bc8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv6 Address:&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv4 Address:&amp;nbsp; 192.168.1.11&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Unauthorized&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; UNKNOWN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Restart timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;Periodic Acct timeout:&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; C0A8011900000021006B4573&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xE3000014&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Policy:&amp;nbsp; (No Policy)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Method status list:&amp;nbsp; empty&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the wired autoconfig is set to automatic on the windows 10 machine ,&amp;nbsp; under authentication settings , PEAP is there with validate server cert option checked .&amp;nbsp; the machine is AD joined and has the Root CA cert from AD which is gets once it joins the AD .&amp;nbsp; &amp;nbsp;mschapv2 option is checked with the option "automatically use my windows username and password&amp;nbsp; , also user or machine authentication is checked . i will paste some screenshots for the same.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 13:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565521#M600832</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-07-22T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565623#M600836</link>
      <description>&lt;P&gt;If you're using PEAP(MSCHAPv2), this could be a Credential Guard issue. You need to confirm if Credential Guard is enabled and, if so, disable it.&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/considerations-known-issues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 21:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5565623#M600836</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2026-07-22T21:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5568799#M600984</link>
      <description>&lt;P&gt;hi Gregg,&amp;nbsp; &amp;nbsp;thanks a lot for commenting on this issue .&amp;nbsp; i managed to get a new lenovo laptop running windows 11 and getting the same issue . i verified the credential guard and i get to see the below on powershell, a value of 0 indicates that credential guard is not enabled .&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS C:\WINDOWS\system32&amp;gt; (Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning&lt;BR /&gt;0&lt;BR /&gt;PS C:\WINDOWS\system32&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 10:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5568799#M600984</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-08-11T10:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: cannot see EAPOL frames on the switch for wired 802.1x - open mode</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5568800#M600985</link>
      <description>&lt;P&gt;also on the 3750X switch port when i see the config as below, i dont see any command related to access-session host-mode multi-auth which was configured on it .&amp;nbsp; i have tried single mode as well but still the same issue&lt;/P&gt;&lt;P&gt;lab-switch#show run int gigabitEthernet 1/0/1&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 226 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication periodic&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 10:09:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-see-eapol-frames-on-the-switch-for-wired-802-1x-open-mode/m-p/5568800#M600985</guid>
      <dc:creator>atifali.zaidi1</dc:creator>
      <dc:date>2026-08-11T10:09:10Z</dc:date>
    </item>
  </channel>
</rss>

