<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It seems like the PC is in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524417#M72690</link>
    <description>&lt;P&gt;It seems like the PC is operating in the VOICE-domain according to the cmd auth sess int you showed. Do you think that has something to do with your problem? I've experienced some PC's having problem with that.&lt;/P&gt;&lt;P&gt;If you could, try getting the PC to operate in the DATA-domain by not sending the voice-attribute from ISE after the authorization.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2014 09:44:14 GMT</pubDate>
    <dc:creator>Jimmy Johansson</dc:creator>
    <dc:date>2014-10-07T09:44:14Z</dc:date>
    <item>
      <title>ISE Authorization Policy Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524416#M72689</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m getting troubles during my implementation:&amp;nbsp;&lt;STRONG&gt;The User PC never gets IP Address from Access VLAN after AuthZ Policy succeded.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have two vlans in my implementation:&lt;/P&gt;&lt;P&gt;Vlan ID 802 for Authentication (Subnet 10.2.39.0)&lt;/P&gt;&lt;P&gt;Vlan ID 50 for Access Users (Subnet Y.Y.Y.Y)&lt;/P&gt;&lt;P&gt;When I start my User PC, I get IP for VLAN 802 (10.2.39.3) and After Posture process, ISE inform the switch to put the User PC port in VLAN 50.&lt;/P&gt;&lt;P&gt;Here I have my Switch Port Configuration:&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/38&lt;BR /&gt;&amp;nbsp;switchport access vlan 802&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;BR /&gt;&amp;nbsp;switchport voice vlan 120&lt;BR /&gt;&amp;nbsp;ip access-group ACL-DEFAULT in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action reinitialize vlan 50&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And Here, I have outputs AuthZ Policy in Action:&lt;/P&gt;&lt;P&gt;Oct &amp;nbsp;7 09:22:01.574 ANG: %DOT1X-5-SUCCESS: Authentication successful for client (0022.1910.4130) on Interface Gi0/38 AuditSessionID 0A022047000000F6126E9B17&lt;BR /&gt;&lt;STRONG&gt;Oct &amp;nbsp;7 09:22:01.582 ANG: %AUTHMGR-5-VLANASSIGN: VLAN 50 assigned to Interface Gi0/38 AuditSessionID 0A022047000000F6126E9B17&lt;/STRONG&gt;&lt;BR /&gt;Oct &amp;nbsp;7 09:22:01.591 ANG: %EPM-6-POLICY_REQ: IP 0.0.0.0| MAC 0022.1910.4130| AuditSessionID 0A022047000000F6126E9B17| AUTHTYPE DOT1X| EVENT APPLY&lt;BR /&gt;Oct &amp;nbsp;7 09:22:01.591 ANG: %EPM-6-AAA: POLICY xACSACLx-IP-PERMIT_ALL_TRAFFIC-537cb1d6| EVENT DOWNLOAD-REQUEST&lt;BR /&gt;Oct &amp;nbsp;7 09:22:01.633 ANG: %EPM-6-AAA: POLICY xACSACLx-IP-PERMIT_ALL_TRAFFIC-537cb1d6| EVENT DOWNLOAD-SUCCESS&lt;BR /&gt;Oct &amp;nbsp;7 09:22:01.633 ANG: %EPM-6-IPEVENT: IP 0.0.0.0| MAC 0022.1910.4130| AuditSessionID 0A022047000000F6126E9B17| AUTHTYPE DOT1X| EVENT IP-WAIT&lt;BR /&gt;SWISNGAC8FL02#&lt;BR /&gt;Oct &amp;nbsp;7 09:22:02.069 ANG: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (0022.1910.4130) on Interface Gi0/38 AuditSessionID 0A022047000000F6126E9B17&lt;BR /&gt;SWISNGAC8FL02#&lt;BR /&gt;Oct &amp;nbsp;7 09:22:02.731 ANG: %EPM-6-IPEVENT: IP 10.2.39.3| MAC 0022.1910.4130| AuditSessionID 0A022047000000F6126E9B17| AUTHTYPE DOT1X| EVENT IP-ASSIGNMENT&lt;BR /&gt;Oct &amp;nbsp;7 09:22:02.731 ANG: %EPM-6-POLICY_APP_SUCCESS: IP 10.2.39.3| MAC 0022.1910.4130| AuditSessionID 0A022047000000F6126E9B17| AUTHTYPE DOT1X| POLICY_TYPE Named ACL| POLICY_NAME xACSACLx-IP-PERMIT_ALL_TRAFFIC-537cb1d6| RESULT SUCCESS&lt;/P&gt;&lt;P&gt;After that, I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SWISNGAC8FL02#sh auth sess int g0/38&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface: &amp;nbsp;GigabitEthernet0/38&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MAC Address: &amp;nbsp;0022.1910.4130&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IP Address: &amp;nbsp;10.2.39.3&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; User-Name: &amp;nbsp;SNL\enzo.belo&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status: &amp;nbsp;Authz Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Domain: &amp;nbsp;VOICE&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Policy: &amp;nbsp;Should Secure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Security Status: &amp;nbsp;Unsecure&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Oper host mode: &amp;nbsp;multi-auth&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Oper control dir: &amp;nbsp;both&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Authorized By: &amp;nbsp;Authentication Server&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;Vlan Policy: &amp;nbsp;50&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ACS ACL: &amp;nbsp;xACSACLx-IP-PERMIT_ALL_TRAFFIC-537cb1d6&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Session timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Idle timeout: &amp;nbsp;N/A&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Common Session ID: &amp;nbsp;0A022047000000F6126E9B17&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Acct Session ID: &amp;nbsp;0x000001A7&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Handle: &amp;nbsp;0x710000F7&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Method &amp;nbsp; State&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dot1x &amp;nbsp; &amp;nbsp;Authc Success&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mab &amp;nbsp; &amp;nbsp; &amp;nbsp;Not run&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently, everything is OK, but NOT. &lt;STRONG&gt;The User PC never gets IP Address from Access VLAN 50.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do &amp;nbsp;SWISNGAC8FL02#sh mac address-table | inc 0022.1910.4130&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp; 50 &amp;nbsp; &amp;nbsp;0022.1910.4130 &amp;nbsp; &amp;nbsp;STATIC &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi0/38&amp;nbsp;&lt;BR /&gt;&amp;nbsp;802 &amp;nbsp; &amp;nbsp;0022.1910.4130 &amp;nbsp; &amp;nbsp;STATIC &amp;nbsp; &amp;nbsp; &amp;nbsp;Gi0/38&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SWISNGAC8FL02#sh epm session summary&amp;nbsp;&lt;BR /&gt;EPM Session Information&lt;BR /&gt;-----------------------&lt;BR /&gt;Total sessions seen so far : 17&lt;BR /&gt;Total active sessions &amp;nbsp; &amp;nbsp; &amp;nbsp;: 1&lt;/P&gt;&lt;P&gt;Interface &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; IP Address &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MAC Address &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;VLAN&lt;/STRONG&gt; &amp;nbsp; Audit Session Id:&lt;BR /&gt;----------------------------------------------------------------------------------&lt;BR /&gt;GigabitEthernet0/38 &amp;nbsp; &amp;nbsp; 10.2.39.3 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0022.1910.4130 &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;802&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; 0A022047000000F6126E9B17&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Switch is a&amp;nbsp;Cisco IOS Software, C3560E Software (C3560E-IPBASEK9-M), Version 15.0(2)SE6, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;I am using ISE Version 1.2.1.198 Patch Info 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me in this Case ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Daniel Stefani&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524416#M72689</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2019-03-11T05:05:24Z</dc:date>
    </item>
    <item>
      <title>It seems like the PC is</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524417#M72690</link>
      <description>&lt;P&gt;It seems like the PC is operating in the VOICE-domain according to the cmd auth sess int you showed. Do you think that has something to do with your problem? I've experienced some PC's having problem with that.&lt;/P&gt;&lt;P&gt;If you could, try getting the PC to operate in the DATA-domain by not sending the voice-attribute from ISE after the authorization.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 09:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524417#M72690</guid>
      <dc:creator>Jimmy Johansson</dc:creator>
      <dc:date>2014-10-07T09:44:14Z</dc:date>
    </item>
    <item>
      <title>Hi Jimmy, Great Tip !!!I</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524418#M72691</link>
      <description>&lt;P&gt;Hi Jimmy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great Tip !!!&lt;/P&gt;&lt;P&gt;I removed the Voice-Attribute from ISE AuthZ Policy and now works as I expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You so Much !!!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 10:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-authorization-policy-issues/m-p/2524418#M72691</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2014-10-07T10:24:18Z</dc:date>
    </item>
  </channel>
</rss>

