<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB Authentication with no response in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386784#M88839</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With "IP device tracking" configured, add the following command to the switch:&lt;/P&gt;&lt;P&gt; ip device tracking probe use-svi&lt;/P&gt;&lt;P&gt;bounce the port&amp;nbsp; and issue a 'show ip device track interface gi2/0/46'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Feb 2014 22:06:17 GMT</pubDate>
    <dc:creator>Robert Salazar</dc:creator>
    <dc:date>2014-02-17T22:06:17Z</dc:date>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386772#M88827</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring MAB authentication for IBMS devices(some buliding infra devices) but MAB was not getting triggered. &lt;/P&gt;&lt;P&gt;I tried using the following solution as well,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2015988" target="_blank"&gt;https://supportforums.cisco.com/thread/2015988&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it says &lt;SPAN style="font-size: 10pt;"&gt;I should changed control-direction to inbound "dot1x control-direction in", that let the MAB work. By applying this interface level command I can see that session is getting authorized but still I can not ping the devices. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can someone exactly confirm whats the issue over here and how to resolve?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;My config on port is as follows,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;int ten1/1/9&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt; authentication host-mode single-host&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication violation restrict&lt;/P&gt;&lt;P&gt; authentication &lt;SPAN style="font-size: 10pt;"&gt;control-direction in&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; mab&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:16:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386772#M88827</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2019-03-11T04:16:09Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386773#M88828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what does the show auth session interface int ten 1/1/9 look like when the port is authorized?&lt;/P&gt;&lt;P&gt;Does an IP address show up in the output?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 01:06:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386773#M88828</guid>
      <dc:creator>Robert Salazar</dc:creator>
      <dc:date>2014-01-14T01:06:36Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386774#M88829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, its not showing any IP , the status looks like as follows,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh authentication sessions interface gi2/0/46&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; GigabitEthernet2/0/46&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AC Address:&amp;nbsp; 0050.c2a8.0ffb&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-50-C2-A8-0F-FB&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; single-host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; in&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS ACL:&amp;nbsp; xACSACLx-IP-SSH-PERMIT-ALL-5270ce52&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0AA000390000002A12EFCB63&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000197&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xA600002B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Hammad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 03:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386774#M88829</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-01-14T03:30:48Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386775#M88830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you paste a show access-list xACSACLx-IP-SSH-PERMIT-ALL-5270ce52 or what ever the current dACL that is applied when you first get authenticated?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 03:51:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386775#M88830</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-01-14T03:51:58Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386776#M88831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Bruce,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My DAcl is like this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 04:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386776#M88831</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-01-14T04:07:37Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386777#M88832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So the switch will take the learned IP address and modify the dACL applied with the new IP address learned from the port.&amp;nbsp; If it doesn't learn an IP, then it can't modify the dACL.&amp;nbsp; I think if your dACL is truely "permit ip any any" then it should work.&amp;nbsp; You might try to add "permit icmp any any" to the dACL, if ping is what you are looking for.&amp;nbsp; Also, is the end device learning it's IP address from DHCP or is it static?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 04:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386777#M88832</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-01-14T04:17:32Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386778#M88833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DO you have "IP device tracking" enabled on the switch?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 04:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386778#M88833</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-01-14T04:22:55Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386779#M88834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Bruce,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its static, actually this is where from the orignal problem initiated. Coz of static IP the MAB was not getting initialized and so I have to use the command, &lt;/P&gt;&lt;P&gt;"authentication control-direction in&lt;STRONG&gt;".&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But still not able to ping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 05:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386779#M88834</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-01-14T05:23:11Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386780#M88835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; No we dont have this command on switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 05:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386780#M88835</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-01-14T05:23:38Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386781#M88836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would add it and try.&amp;nbsp; The reference below is for webauth but since cwa is really MAB, it still applies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="1" /&gt;By default, the IP device tracking feature is disabled on a switch. You must enable the IP device tracking feature to use web-based authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Layer 2 interfaces, web-based authentication detects IP hosts by using these mechanisms:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1103723"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;ARP based trigger—ARP redirect ACL allows web-based authentication to detect hosts with a static IP address or a dynamic IP address.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1103724"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Dynamic ARP inspection&lt;/P&gt;&lt;P&gt;&lt;A name="wp1103728"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;DHCP snooping—Web-based authentication is notified when the switch creates a DHCP-binding entry for the host.&lt;/P&gt;&lt;P&gt;&lt;A name="Session_Creation"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jan 2014 05:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386781#M88836</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-01-14T05:44:34Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386782#M88837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bruce, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried with adding in the command "&lt;SPAN style="font-size: 10pt;"&gt;IP device tracking", but still not getting authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Is there any other alternative for this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hammad Raza&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 04:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386782#M88837</guid>
      <dc:creator>netstar-sg-service</dc:creator>
      <dc:date>2014-02-13T04:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386783#M88838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried with adding in the command "IP device tracking", but still not getting MAB initiated when port comes up.&lt;/P&gt;&lt;P&gt;Is there any other alternative for this? or any technical docment specifically referring this kind of issues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 07:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386783#M88838</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-02-17T07:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386784#M88839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With "IP device tracking" configured, add the following command to the switch:&lt;/P&gt;&lt;P&gt; ip device tracking probe use-svi&lt;/P&gt;&lt;P&gt;bounce the port&amp;nbsp; and issue a 'show ip device track interface gi2/0/46'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 22:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386784#M88839</guid>
      <dc:creator>Robert Salazar</dc:creator>
      <dc:date>2014-02-17T22:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386785#M88840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was checking the use of this command and came across with this statement saying&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;" The caveat to this method is that an SVI must exist on every switch in every VLAN where&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Windows clients who run DHCP reside."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and In my setup, mostly edge switches are running on layer 2 purely. SVIs are created on core switches where routing is done. so wondering if this command will still supports and the purpose can be achieved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hammad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 03:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386785#M88840</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-02-18T03:11:42Z</dc:date>
    </item>
    <item>
      <title>Re:MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386786#M88841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hammad,&lt;BR /&gt;&lt;BR /&gt;The command still applies. I have used this command with "use svi" and built a local svi on the edge switch just for this reason. The ip device tracking uses arp to resolve the ip address. Some device dont respond like others. By using the use svi command you source it directly from the edge switch. I know it's a pain to build an svi for each vlan that is using static IPs but it may be the only way. Try it on one and let us know the outcome.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 03:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386786#M88841</guid>
      <dc:creator>cgambrel</dc:creator>
      <dc:date>2014-02-18T03:40:34Z</dc:date>
    </item>
    <item>
      <title>MAB Authentication with no response</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386787#M88844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The customer use case (detailed below) is essentially MAB for protected devices on specific ports to one server and all other ports would point to a separate server. Is this something that could be accomplished via SANet? This would of course require them to upgrade all affected access switches assuming what Hsing-Tsu mentioned below is true and we're limited to 3650/3850 today.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have different RADIUS servers for for dot1x and MAB when you use identity policy (SANet). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create two policies doing the same thing (eg MAB) but use different RADIUS servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would then have a different policy attached to the port groups in question. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 14:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386787#M88844</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2014-02-20T14:05:10Z</dc:date>
    </item>
    <item>
      <title>Hi Team, I have manage to put</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386788#M88846</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have manage to put the above mention commands "&amp;nbsp;ip device tracking probe use-svi" and it is working for some devices/ports. But on other occassions it is not working.&lt;/P&gt;&lt;P&gt;It works after I tried to remove it then re-add the MAB commands and shut /unshut port several times and then try to ping simultaneously.&lt;/P&gt;&lt;P&gt;The difference I can see is that when it correctly accept the device , in ACS monitoring I can see the entries for both Authentication and ACL while otherwise only Authentication entry is there. Kindly see the attached pic here.&lt;/P&gt;&lt;P&gt;I want to know what is causing ACS to stop the ACL entry on occasions?&lt;/P&gt;&lt;P&gt;Also in 2nd attachment (it is for successful auth) you can see the below output which should not be there by right? is it something to do with my MAB issue as well?&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: rgb(255, 0, 0); font-family: sans-serif; font-size: small; line-height: normal;"&gt;24423 &amp;nbsp;ACS has not been able to confirm previous successful machine authentication for user in Active Directory"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;hammad&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 04:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386788#M88846</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-03-12T04:42:22Z</dc:date>
    </item>
    <item>
      <title>Hi Team,Can anyone of the</title>
      <link>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386789#M88850</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can anyone of the Guru's help? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Hammad&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 08:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mab-authentication-with-no-response/m-p/2386789#M88850</guid>
      <dc:creator>shrazar85</dc:creator>
      <dc:date>2014-03-13T08:24:03Z</dc:date>
    </item>
  </channel>
</rss>

