<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE - Periodic Dynamic Auth Failures in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391754#M88986</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this for wireless or wired or both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jan 2014 18:33:35 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2014-01-03T18:33:35Z</dc:date>
    <item>
      <title>ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391753#M88985</link>
      <description>&lt;P&gt;I am running into an issue where I get a handful of Dynamic Auth Failure errors in ISE. In the results it's showing a CoANAK and the error cause is 200. In the steps it's showing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;11204 Received reauthenticate request &lt;/P&gt;&lt;P&gt;11220 Prepared the reauthenticate request &lt;/P&gt;&lt;P&gt;11100 RADIUS-Client about to send request &lt;/P&gt;&lt;P&gt;11101 RADIUS-Client received response &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which shows successful communications between ISE and the NAD. When I look at the logs for Radius Authentication for one of the hosts I see it pass MAB with one session ID then Dynamic Auth CoA Fail then pass dot1x with a different session ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I was reading up on the Dynamic Auth RFC (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tools.ietf.org/html/rfc5176" target="_blank"&gt;http://tools.ietf.org/html/rfc5176&lt;/A&gt;&lt;SPAN&gt;) and in Section 3.5 it states:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Values 200-299 represent successful completion, so that these values may only be sent within CoA-ACK or Disconnect-ACK packets and MUST NOT be sent within a CoA-NAK or Disconnect-NAK packet."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something here? Is anyone else having this issue? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391753#M88985</guid>
      <dc:creator>xxkozxx</dc:creator>
      <dc:date>2019-03-11T04:14:13Z</dc:date>
    </item>
    <item>
      <title>ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391754#M88986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this for wireless or wired or both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 18:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391754#M88986</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-03T18:33:35Z</dc:date>
    </item>
    <item>
      <title>ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391755#M88987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wired.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 19:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391755#M88987</guid>
      <dc:creator>xxkozxx</dc:creator>
      <dc:date>2014-01-03T19:31:28Z</dc:date>
    </item>
    <item>
      <title>ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391756#M88988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have non Cisco phones that the clients connect to? Also what version and platform is the wired switch? Also can you post the running config of the port that you traced this back to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you issue a "show authentication session interface xxx" do you see multiple aaa-session-id for the same user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to run a few debugs around the COA process and please make sure that the radius shared secret is the same as the server-key under the client settings for the "aaa server radius dynamic-author" configuration section. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 20:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391756#M88988</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-03T20:44:50Z</dc:date>
    </item>
    <item>
      <title>ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391757#M88989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All Cisco Phones. Switches are 4510's running 03.02.03&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a sample port config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernetX/X/X&lt;/P&gt;&lt;P&gt; switchport access vlan XX&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan XX&lt;/P&gt;&lt;P&gt; srr-queue bandwidth share 10 10 60 20&lt;/P&gt;&lt;P&gt; queue-set 2&lt;/P&gt;&lt;P&gt; priority-queue out&lt;/P&gt;&lt;P&gt; authentication event fail action next-method&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication order mab dot1x&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; mls qos trust device cisco-phone&lt;/P&gt;&lt;P&gt; mls qos trust cos&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt; spanning-tree guard root&lt;/P&gt;&lt;P&gt; service-policy input AutoQoS-Police-CiscoPhone&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No I don't see multiple session id's for the same user. We are using EAP-TLS and cert auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server keys are good. I've debugged a couple of these. Only thing I could find was the session ID is different between mab and dot1x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/2391757#M88989</guid>
      <dc:creator>xxkozxx</dc:creator>
      <dc:date>2014-01-03T21:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - Periodic Dynamic Auth Failures</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/3830723#M88990</link>
      <description>&lt;P&gt;Hello, i'm having the same problem. Did you find a solution for this?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 14:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-periodic-dynamic-auth-failures/m-p/3830723#M88990</guid>
      <dc:creator>steve sousa</dc:creator>
      <dc:date>2019-04-02T14:59:30Z</dc:date>
    </item>
  </channel>
</rss>

