<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dot1x NAC reauthentication issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852791#M821960</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jafrazie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i didn't saw EAPOL-Start or EAPOL-Logoff Request from the debug dot1x packet&lt;/P&gt;&lt;P&gt;in debug dot1x all it show&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-ev:dot1x_exec_reauth_client: Reauthenticating Authenticator instance on GigabitEthernet0/41&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting REAUTHENTICATE on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_authenticated, got event 18(reAuthenticate)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_authenticated -&amp;gt; auth_restart&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticated_exit called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:dot1x_auth_stop_reauth_timer called for 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_restart_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-ev:Sending create new context event to EAP for 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticated_restart_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting !EAP_RESTART on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_restart, got event 6(no_eapRestart)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_restart -&amp;gt; auth_connecting&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_connecting_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_restart_connecting_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-packet:Received an EAP request packet from EAP for mac 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting RX_REQ on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_connecting, got event 11(eapReq_no_reAuthMax)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_connecting -&amp;gt; auth_authenticating&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticating_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_connecting_authenticating_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting AUTH_START on Client=31CC01C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;iz switch itself genarate the re-auth itself&lt;/P&gt;&lt;P&gt;what could cos this?&lt;/P&gt;&lt;P&gt;could it be something wrong with my config, i do try without NAC, just purely dot1x authentication with original winXP SP2 is still the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx,&lt;/P&gt;&lt;P&gt;LIMCS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Sep 2007 09:16:16 GMT</pubDate>
    <dc:creator>cheaseung</dc:creator>
    <dc:date>2007-09-15T09:16:16Z</dc:date>
    <item>
      <title>Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852789#M821946</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i setup a test LAB with NAC Dot1x Framework, and i facing an issue where by the port keep on repeating triger reauthntication, althought the next reauthentication is not yet reach, i try configure re-authperiod to using local rather than radious server or event disable the reauthentication but the result is still the same&lt;/P&gt;&lt;P&gt; my lab is using a Cat3560 event upgrade with latest IOS ver c3560-advipservicesk9-mz.122-40.SE but is still the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when show dot1x interface detail i notise the next re-auth is still alot of sec, but out of sudden the port juz reauthenticed, whereby the CAT detail show status reauthenticating, &lt;/P&gt;&lt;P&gt;CAT version 2.1.103.o with supplicant bundle.&lt;/P&gt;&lt;P&gt;i event try to modify the ctad.ini &lt;/P&gt;&lt;P&gt;SQTimer and all this make no difference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852789#M821946</guid>
      <dc:creator>cheaseung</dc:creator>
      <dc:date>2020-02-21T09:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852790#M821952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you verify the source of your unexpected re-auth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's the supplicant, you'll see an EAPOL-Start on the wire to initiate it (or maybe an EAPOL-Logoff, but unlikely).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's the switch, you'll see an EAPOL-Id-Request frame on the wire from the switch to the supplicant to initiate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2007 04:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852790#M821952</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2007-09-14T04:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852791#M821960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jafrazie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i didn't saw EAPOL-Start or EAPOL-Logoff Request from the debug dot1x packet&lt;/P&gt;&lt;P&gt;in debug dot1x all it show&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-ev:dot1x_exec_reauth_client: Reauthenticating Authenticator instance on GigabitEthernet0/41&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting REAUTHENTICATE on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_authenticated, got event 18(reAuthenticate)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_authenticated -&amp;gt; auth_restart&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticated_exit called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:dot1x_auth_stop_reauth_timer called for 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_restart_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-ev:Sending create new context event to EAP for 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticated_restart_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting !EAP_RESTART on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_restart, got event 6(no_eapRestart)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_restart -&amp;gt; auth_connecting&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_connecting_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_restart_connecting_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-packet:Received an EAP request packet from EAP for mac 000b.db1b.9eac&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting RX_REQ on Client=31CC01C&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43:     dot1x_auth Gi0/41: during state auth_connecting, got event 11(eapReq_no_reAuthMax)&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: @@@ dot1x_auth Gi0/41: auth_connecting -&amp;gt; auth_authenticating&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_authenticating_enter called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Gi0/41:000b.db1b.9eac:auth_connecting_authenticating_action called&lt;/P&gt;&lt;P&gt;.Sep 15 12:16:43: dot1x-sm:Posting AUTH_START on Client=31CC01C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;iz switch itself genarate the re-auth itself&lt;/P&gt;&lt;P&gt;what could cos this?&lt;/P&gt;&lt;P&gt;could it be something wrong with my config, i do try without NAC, just purely dot1x authentication with original winXP SP2 is still the same&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx,&lt;/P&gt;&lt;P&gt;LIMCS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2007 09:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852791#M821960</guid>
      <dc:creator>cheaseung</dc:creator>
      <dc:date>2007-09-15T09:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852792#M821978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your psec configuration is most likely tripping a re-auth on you every minute. OUY could set the aging criteria to inactivity, or ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would humbly recommend disabling psec in this scenario. 1X itself will limit the port to only a single MAC anway, and there's no such thing as aging for it really .. after all, that's why you might want re-auth for to begin with. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2007 22:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852792#M821978</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2007-09-17T22:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852793#M821994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey jaffrazie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx alot, u r so great&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2007 23:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852793#M821994</guid>
      <dc:creator>cheaseung</dc:creator>
      <dc:date>2007-09-17T23:45:15Z</dc:date>
    </item>
    <item>
      <title>Dot1x NAC reauthentication issue</title>
      <link>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852794#M822000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, man. I solved my issue ))) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 13:08:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dot1x-nac-reauthentication-issue/m-p/852794#M822000</guid>
      <dc:creator>cirimpei costel</dc:creator>
      <dc:date>2013-05-17T13:08:12Z</dc:date>
    </item>
  </channel>
</rss>

