<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Self Provisioning - Supplicant then NAC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293884#M98697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am trying to see--based on my experience---is the native supplciant provisioning phase. Can you post a screenshot of the Client_unknown authorization policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Aug 2013 02:49:27 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-08-18T02:49:27Z</dc:date>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293876#M98689</link>
      <description>&lt;P&gt;I'm trying to setup a scenario such as -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laptop brought on network - joins open wireless network - through open wireless network it registers with ISE using the supplicant wizard - once the supplicant wizard completes it joins a secure SSID - after navigating to another webpage NAC is delivered and client is postured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've gotten all the way to the last part.&amp;nbsp; It runs through the supplicant wizard, successfully registers, and joins the 802.1x network without a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I go to any other webpage it redirects me to "Unable to verify credentials required to access the network." page.&amp;nbsp; The only way to stop it is to remove it from the clients page on the WLC - once it's removed and rejoins the 802.1x network the NAC agent install comes up, installs, and postures according to the posture policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems like everything is where it should be but it doesn't install at the proper time without being removed from the network.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293876#M98689</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2019-03-11T03:46:16Z</dc:date>
    </item>
    <item>
      <title>Re:Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293877#M98690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this for wireless? What version of contoller code are you on?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 13:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293877#M98690</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-14T13:17:11Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293878#M98691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Cisco 5508 running &lt;SPAN style="font-size: 10pt;"&gt;7.5.102.0 - I was on 7.4 and had the same issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 13:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293878#M98691</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-14T13:36:09Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293879#M98692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am testing this same scenario also. When the client connects to the SSID after the onboarding provisioning is completed what do you see as far as the client entry? Is it in a RUN state. Also does the state change when you remove the user from the client database?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry i didnt read through your first post, I see now that you are on wireless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 04:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293879#M98692</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-16T04:04:15Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293880#M98693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem.&amp;nbsp; I've attached screenshots from the WLC.&amp;nbsp; These are the only differences between when the client is on the controller after the supplicant has been installed and after I have removed the client from the controller and it has authenticated.&amp;nbsp; It seems the only difference is the session ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the authentication logs you can see where the session changes and I've forced the client to reconnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st redirect URL&lt;/P&gt;&lt;P&gt;/guestportal/gateway?sessionId=ac1e104500000c73520da9cc&amp;amp;action=cpp&lt;/P&gt;&lt;P&gt;2nd redirect URL&lt;/P&gt;&lt;P&gt;/guestportal/gateway?sessionId=ac1e104500000c74520daa40&amp;amp;action=cpp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached authentication logs as well.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/2/1/151123-WLC-Before.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;After&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/5/1/151157-WLC-Before.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;ISE Authentication log screenshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/5/1/151158-Authentication.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 04:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293880#M98693</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-16T04:34:23Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293881#M98694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are my provisioning policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/2/2/151223-Client%20Provisioning.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 01:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293881#M98694</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-18T01:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293882#M98695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to follow the authorization logs, however in my scenario on version 1.1.4 patch 3 the below is sequence of my use case, it looks like you are on 1.2...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client authenticates with CWA&lt;/P&gt;&lt;P&gt;Client is redirected to the native supplication provisioning portal&lt;/P&gt;&lt;P&gt;clients connects with 802.1x&lt;/P&gt;&lt;P&gt;Client is redirected to posture&lt;/P&gt;&lt;P&gt;Finally posture status determines fate of connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the logs you provided I see the following in your sequence...&lt;/P&gt;&lt;P&gt;Client authenticates with CWA&lt;/P&gt;&lt;P&gt;----I do not see the client redirected to the NSP phase---&lt;/P&gt;&lt;P&gt;Client authenticates with eap-tls&lt;/P&gt;&lt;P&gt;Then after the delay you are hitting it connects and is compliant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you delete the endpoint entry, and the wireless network profile and run through the entire process. From what I can tell your policies look fine&amp;nbsp; and you are using the nac agent. Also when you get redirected to the page not available message, can you verify that the sessionid in the url matches the session id in the ise logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using the default ip value or are you customizing the hostname that is sent in the authorization profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 02:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293882#M98695</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-18T02:28:01Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293883#M98696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct, sorry I didn't mention it - I'm on ISE 1.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No customization and the supplicant hits right after the login which is how it arrives at the EAP-TLS phase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs I've posted are of a client that has not been registered and has been removed from the WLC before the attempt (it's my test Win7 client). I've tried clients that have never been registered to ISE with the same result just to be sure it's not a problem with the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The URLs passed by ISE do match the session ID.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 02:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293883#M98696</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-18T02:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293884#M98697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am trying to see--based on my experience---is the native supplciant provisioning phase. Can you post a screenshot of the Client_unknown authorization policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 02:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293884#M98697</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-18T02:49:27Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293885#M98698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've attached screenshots of the policy below.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/4/2/151241-ClientUnknown1.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/4/2/151242-ClientUnknown2.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 02:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293885#M98698</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-18T02:53:59Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293886#M98699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide the ACL contents of the ACL_Client_Unknown? Are you running multiple PSNs? Also send me the screenshot of the graybox that shows all the attributes for the attributes you sent above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 03:09:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293886#M98699</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-18T03:09:25Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293887#M98700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have two ISE nodes, one is primary on all services the other is secondary on all services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two WLC's one with the high availability SKU - it is in hot standby mode during these tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL for Client Unknown - 172.30.16.70 and .71 are the ISE nodes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/4/2/151243-ACL_Client_Unknown.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attribute information - &lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/4/2/151244-Client%20Unknown%20Attributes.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 03:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293887#M98700</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-18T03:14:21Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293888#M98701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you add an entry to deny all traffic to port 80, this will help in failover scenarios if the discovery host is pointing to an ise node that isnt servicing the redirect request. I do not think this will fix your scenario but everything else looks solid. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;typically the discovery agent updates at the time the ise is redirected for posturing, so when the nac agent connects it sends a http discovery probe for the discovery host, if ise1 is the discovery host and ise2 is the active psn for the session, then the discovery probe will see the session is redirected to a different psn to prevent this scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also allowing dhcp traffic in the ACL which I recommend disabling so the client is forced to re-ip during the CWA to 802.1x transition. When you reproduce the issue where the client is unable to view the page, check the ip address and make sure that the client still doesnt have the old ip address, if so then the dhcp entries in the ACL may be the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be best to run a packet capture on the test client to see if dns resolution is failing or if ISE sending back the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Aug 2013 06:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293888#M98701</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-18T06:38:09Z</dc:date>
    </item>
    <item>
      <title>Re:Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293889#M98702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Disabling fast ssid switching in the wireless lan controller fixed the issue.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 02:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293889#M98702</guid>
      <dc:creator>David Boos</dc:creator>
      <dc:date>2013-08-30T02:16:39Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293890#M98703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had this problem too and as David did, disabling fast ssid solved the issue.&lt;/P&gt;&lt;P&gt;Is there any drawback for this? I read somewhere this setting help Apple IOS to move between SSID.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 06:23:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293890#M98703</guid>
      <dc:creator>andikamulya</dc:creator>
      <dc:date>2013-10-22T06:23:14Z</dc:date>
    </item>
    <item>
      <title>Self Provisioning - Supplicant then NAC</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293891#M98704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Symptoms or Issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Client machine browser displays a "no policy matched" error message after user authentication and authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Conditions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; This issue applies to user sessions during the client provisioning phase of authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Possible Causes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The client provisioning resource policy could be missing required settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Resolution&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; •Ensure that a client provisioning policy exists in Cisco ISE. If yes,&amp;nbsp; verify the policy identity group, conditions, and type of agent(s)&amp;nbsp; defined in the policy. (Also ensure whether or not there is any agent&amp;nbsp; profile configured under Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt;&amp;nbsp; Client Provisioning &amp;gt; Resources &amp;gt; Add &amp;gt; ISE Posture Agent&amp;nbsp; Profile, even a profile with all default values.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; •Try reauthenticating the client machine by bouncing the port on the access switch. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293891#M98704</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-25T23:36:33Z</dc:date>
    </item>
    <item>
      <title>I had the same issue but with</title>
      <link>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293892#M98705</link>
      <description>&lt;P&gt;I had the same issue but with &lt;STRONG&gt;wired &lt;/STRONG&gt;802.1x authentication/PEAP, but the resolution was extremely similar. Simply disabling Fast Reconnect under the PEAP settings fixed my problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 17:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-provisioning-supplicant-then-nac/m-p/2293892#M98705</guid>
      <dc:creator>Ramon Thomas</dc:creator>
      <dc:date>2014-05-13T17:56:41Z</dc:date>
    </item>
  </channel>
</rss>

