5400 Authentication failed - ISE - Happening Randomly to users
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2021 10:53 AM - edited 08-24-2021 11:12 AM
Hi,
Would appreciate if I can get some tips or ideas on what the issue might be. Seems that users do get an IP address as they cannot be authenticated. Looks like it might be between ISE and Active directory, however so far have not found the exact problem. Below are some of the outputs received, on ISE side:
EVENT: 5400 Authentication failed |
Failure Reason | 15039 Rejected per authorization profile |
Resolution | Authorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results. |
Root cause | Selected Authorization Profile contains ACCESS_REJECT attribute |
Any little help will be greatly appreciated
- Labels:
-
Integrated Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2021 01:07 PM
Missing some valuable information here, but this seems to be an issue with the authz policy the client is hitting during authz. I would start with double checking the authz profile that is assigned as the result. Also, this could be possible if the client/s are hitting the default catch all policy which is resulting in the reject. Additional info that would aide the community includes:
-Detailed radius live log steps
-Type of auth (dot1x/mab?)
-AAA/interface config
