<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hmm everything looks  good. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535119#M89779</link>
    <description>&lt;P&gt;Hmm everything looks &amp;nbsp;good. Can you also post a screen shot of the authorization result ?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jun 2014 17:04:37 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2014-06-24T17:04:37Z</dc:date>
    <item>
      <title>IP device tracking and idle timer problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535116#M89774</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are deploying 802.1X in our network and have encountered problem with a type of payment terminal.&lt;BR /&gt;The problem is that the terminal do not 'speak' to the network after the first initial DHCP request, the terminal waits for incoming packets from a counter to start the payment process. After the idle-time the MAC is flushed from the switch and the port is not authorized any more.&lt;/P&gt;&lt;P&gt;To solve this we set 'authentication control-direction in' on the port and use 'ip device tracking' to keep the client on the network, ip device tracking sends an arp request every 30 seconds to clients.&lt;/P&gt;&lt;P&gt;Our ISE is sending Radius:Idle-Timeout = 300 and the timer start to count down when the client is authenticated.&lt;/P&gt;&lt;P&gt;In Wireshark, I can see that the ARP request is going out and the ARP reply coming back in but this does not update the inactivity timer for the client. So after 5 minutes the port is gone, and there is no way to get the port up again from the network. Traffic from the client brings up the network.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This looks like a bug to me, anyone seen this, or a similar behaviour?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Running:&lt;/P&gt;&lt;P&gt;ISE 1.2p6&lt;BR /&gt;IOS 12.2(55)SE6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;STRONG&gt;From Trustsec 1.99 Wired 802.1X Deployment Guide:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;Tip Enable IP Device Tracking with inactivity timers to keep quiet endpoints connected. When IP Device Tracking is enabled, the switch periodically sends ARP probes to endpoints in the IP Device Tracking table (which is initially populated by DHCP requests or ARP from the end point). As long as the endpoint is connected and responds to these probes, the inactivity timer is not triggered and the endpoint is not inadvertently removed from the network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From CLI output&lt;/P&gt;&lt;P&gt;SW03#sh auth sessions int fa0/4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; xxxx.xxxx.5289&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; 10.10.10.64&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; XX-XX-XX-XX-52-89&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authz Success&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Group:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; 300s (server), Remaining: 2s&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A17BD07000000A925152A7B&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000458&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x090000A9&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Failed over&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authc Success&lt;/P&gt;&lt;P&gt;SW03#&lt;BR /&gt;SW03#&lt;BR /&gt;SW03#&lt;BR /&gt;SW03#sh auth sessions int fa0/4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface:&amp;nbsp; FastEthernet0/4&lt;BR /&gt;&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; Unknown&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; UNKNOWN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A17BD07000000AA251A0019&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00000462&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x800000AA&lt;/P&gt;&lt;P&gt;Runnable methods list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&amp;nbsp;&amp;nbsp; State&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dot1x&amp;nbsp;&amp;nbsp;&amp;nbsp; Running&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mab&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Not run&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535116#M89774</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2019-03-11T04:49:16Z</dc:date>
    </item>
    <item>
      <title>Can you share the port</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535117#M89775</link>
      <description>&lt;P&gt;Can you share the port-configurations?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 08:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535117#M89775</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-06-24T08:55:12Z</dc:date>
    </item>
    <item>
      <title>Here is the port config.Just</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535118#M89777</link>
      <description>&lt;P&gt;Here is the port config.&lt;/P&gt;&lt;P&gt;Just to clarify, everything is working except that the terminal is losing the authentication. The terminal works again if traffic is initiated from the terminals menu, like with ping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/4&lt;BR /&gt;&amp;nbsp;description Standard&lt;BR /&gt;&amp;nbsp;switchport access vlan xxx&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport block unicast&lt;BR /&gt;&amp;nbsp;switchport voice vlan xxx&lt;BR /&gt;&amp;nbsp;switchport port-security maximum 2&lt;BR /&gt;&amp;nbsp;switchport port-security&lt;BR /&gt;&amp;nbsp;switchport port-security aging time 5&lt;BR /&gt;&amp;nbsp;switchport port-security violation restrict&lt;BR /&gt;&amp;nbsp;priority-queue out&lt;BR /&gt;&amp;nbsp;authentication control-direction in&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action reinitialize vlan xxx&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize voice&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;authentication timer inactivity server&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;no snmp trap link-status&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 5&lt;BR /&gt;&amp;nbsp;storm-control broadcast level pps 100&lt;BR /&gt;&amp;nbsp;storm-control multicast level pps 100&lt;BR /&gt;&amp;nbsp;storm-control action trap&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;service-policy input users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 09:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535118#M89777</guid>
      <dc:creator>Mikael Gustafsson</dc:creator>
      <dc:date>2014-06-24T09:38:08Z</dc:date>
    </item>
    <item>
      <title>Hmm everything looks  good.</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535119#M89779</link>
      <description>&lt;P&gt;Hmm everything looks &amp;nbsp;good. Can you also post a screen shot of the authorization result ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 17:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535119#M89779</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-06-24T17:04:37Z</dc:date>
    </item>
    <item>
      <title> switchport port-security</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535120#M89780</link>
      <description>&lt;P&gt;&amp;nbsp;switchport port-security aging time 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically your port security is clashing with dot1x. I had this exact problem a while ago and removing the above command will fix it. Ultimately though you should review the need for port security configurations when using dot1x - kind of achieves the same purpose.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2014 22:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535120#M89780</guid>
      <dc:creator>Stephen McBride</dc:creator>
      <dc:date>2014-06-25T22:32:11Z</dc:date>
    </item>
    <item>
      <title>Possibly not related - but I</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535121#M89781</link>
      <description>&lt;P&gt;Possibly not related - but I don't think you should mix 802.1X with port-security. I would remove the port-security lines completely&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 01:58:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/2535121#M89781</guid>
      <dc:creator>franklinb</dc:creator>
      <dc:date>2015-10-02T01:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: IP device tracking and idle timer problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/4940449#M584613</link>
      <description>&lt;P&gt;I see you are using IBSN 1.0,&amp;nbsp;&lt;BR /&gt;I am using IBSN 2.0 and I prioritize the MAB over 802.1x and that fix my problem with sleepy printers&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 00:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-device-tracking-and-idle-timer-problem/m-p/4940449#M584613</guid>
      <dc:creator>acazarez</dc:creator>
      <dc:date>2023-10-15T00:14:14Z</dc:date>
    </item>
  </channel>
</rss>

