<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610040#M75232</link>
    <description>&lt;P&gt;Currently I'm implementing 802.1x on a Catalyst 4500 L3 Switch and using ACS Version 5.5.0.46.5&lt;/P&gt;&lt;P&gt;I'm having random problems with using MAB. I say random because when ever I do a show authentication sessions maybe 6 will fail out of 214. The phones that I'm using are Cisco 7965 IP Phones. I've read that those phones are capable of using certificates for 802.1x but it was decided to use MAB on all the phones including VIPR phones. The problem that I'm having is that after an hour some phones become un authorized which bring down that port. I've noticed that some of these phones are stand alone phones with out a computer wired to them. The computers are successfully using 802.1x and the phones that are connected to them are working with MAB.&lt;/P&gt;&lt;P&gt;Here are my commands for an interface that's failing after an hour&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport access vlan 100&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 101&lt;BR /&gt;&amp;nbsp;no logging event link-status&lt;BR /&gt;&amp;nbsp;authentication control-direction in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When ever I do show authentication sessions this is the out put.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; Domain&amp;nbsp; Status Fg Session ID&lt;BR /&gt;----------------------------------------------------------------------&lt;BR /&gt;Gi1/1 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1111.1111.1111 mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOICE&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0A11111111111111111111&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;&amp;nbsp; A - Applying Policy (multi-line status for details)&lt;BR /&gt;&amp;nbsp; D - Awaiting Deletion&lt;BR /&gt;&amp;nbsp; F - Final Removal in progress&lt;BR /&gt;&amp;nbsp; I - Awaiting IIF ID allocation&lt;BR /&gt;&amp;nbsp; P - Pushed Session&lt;BR /&gt;&amp;nbsp; R - Removing User Profile (multi-line status for details)&lt;BR /&gt;&amp;nbsp; U - Applying User Profile (multi-line status for details)&lt;BR /&gt;&amp;nbsp; X - Unknown Blocker&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; Handle&amp;nbsp; Priority&amp;nbsp; Name&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 18&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; webauth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But after an hour or so it becomes unauthorized. Also should I have "authentication periodic , or authentication timer reauthenticate 3600"&lt;/P&gt;&lt;P&gt;if those particular ports just have a phone that's using mab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:19:25 GMT</pubDate>
    <dc:creator>lamarnale</dc:creator>
    <dc:date>2019-03-11T05:19:25Z</dc:date>
    <item>
      <title>802.1x issue</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610040#M75232</link>
      <description>&lt;P&gt;Currently I'm implementing 802.1x on a Catalyst 4500 L3 Switch and using ACS Version 5.5.0.46.5&lt;/P&gt;&lt;P&gt;I'm having random problems with using MAB. I say random because when ever I do a show authentication sessions maybe 6 will fail out of 214. The phones that I'm using are Cisco 7965 IP Phones. I've read that those phones are capable of using certificates for 802.1x but it was decided to use MAB on all the phones including VIPR phones. The problem that I'm having is that after an hour some phones become un authorized which bring down that port. I've noticed that some of these phones are stand alone phones with out a computer wired to them. The computers are successfully using 802.1x and the phones that are connected to them are working with MAB.&lt;/P&gt;&lt;P&gt;Here are my commands for an interface that's failing after an hour&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport access vlan 100&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 101&lt;BR /&gt;&amp;nbsp;no logging event link-status&lt;BR /&gt;&amp;nbsp;authentication control-direction in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;/P&gt;&lt;P&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When ever I do show authentication sessions this is the out put.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp; Domain&amp;nbsp; Status Fg Session ID&lt;BR /&gt;----------------------------------------------------------------------&lt;BR /&gt;Gi1/1 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1111.1111.1111 mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOICE&amp;nbsp;&amp;nbsp; Auth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0A11111111111111111111&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Key to Session Events Blocked Status Flags:&lt;/P&gt;&lt;P&gt;&amp;nbsp; A - Applying Policy (multi-line status for details)&lt;BR /&gt;&amp;nbsp; D - Awaiting Deletion&lt;BR /&gt;&amp;nbsp; F - Final Removal in progress&lt;BR /&gt;&amp;nbsp; I - Awaiting IIF ID allocation&lt;BR /&gt;&amp;nbsp; P - Pushed Session&lt;BR /&gt;&amp;nbsp; R - Removing User Profile (multi-line status for details)&lt;BR /&gt;&amp;nbsp; U - Applying User Profile (multi-line status for details)&lt;BR /&gt;&amp;nbsp; X - Unknown Blocker&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp; Handle&amp;nbsp; Priority&amp;nbsp; Name&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 18&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; webauth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But after an hour or so it becomes unauthorized. Also should I have "authentication periodic , or authentication timer reauthenticate 3600"&lt;/P&gt;&lt;P&gt;if those particular ports just have a phone that's using mab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610040#M75232</guid>
      <dc:creator>lamarnale</dc:creator>
      <dc:date>2019-03-11T05:19:25Z</dc:date>
    </item>
    <item>
      <title>I have had this issue happen</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610041#M75234</link>
      <description>&lt;P&gt;I have had this issue happen to me before but it was with deploying ISE and not ACS. To fix the issue, I had to return the following Radius attribute in my "Authorization Profile"&lt;/P&gt;

&lt;PRE&gt;
&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Verdana, Helvetica, sans-serif; line-height: normal;"&gt;AVPair attribute termination-action-modifier=1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;This attribute basically instructs the NAD to re-retry only the last authentication method which in your case is MAB. Otherwise, based on your config, the switch would first try &lt;STRONG&gt;dot1x&lt;/STRONG&gt; and then &lt;STRONG&gt;mab&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, I have not done this in ACS but ISE instead, however, they are both Radius servers and both Cisco products so my feeling is that this would fix your problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more info check out this doc:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html#wp9000052"&gt;http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-service/application_note_c27-573287.html#wp9000052&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 03:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610041#M75234</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-01-07T03:11:27Z</dc:date>
    </item>
    <item>
      <title>Thank you for the advice. I</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610042#M75236</link>
      <description>&lt;P&gt;Thank you for the advice. I will look into this.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 12:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610042#M75236</guid>
      <dc:creator>lamarnale</dc:creator>
      <dc:date>2015-01-07T12:46:18Z</dc:date>
    </item>
    <item>
      <title>Sounds good. Let me know what</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610043#M75239</link>
      <description>&lt;P&gt;Sounds good. Let me know what the results are!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 17:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-issue/m-p/2610043#M75239</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-01-07T17:54:06Z</dc:date>
    </item>
  </channel>
</rss>

