09-17-2014 12:45 AM - edited 03-10-2019 10:01 PM
We have an ISE deployment for testing.
This is running v1.2.0.899.
We have an auth policy configured for domain-joined computers for 802.1x and domain credentials:
Condition: Wired_802.1X
Allow Protocols: PEAP_CHAPv2
Use: AD
This works, and authenticates both the machine (pre-login) and user (post-login).
However, I am seeing some errors int the Auth logs before the 5200 Authentication succeeded message.
These messages are not shown in the Cisco ISE Log Messages spreadsheet!
5441 Endpoint started new EAP session while the packet of previous EAP session is being processed. Dropping new session.
5405 RADIUS Request dropped
5440 Endpoint abandoned EAP session and started new
09-17-2014 02:35 AM
check the following link
https://supportforums.cisco.com/discussion/12303621/5440-endpoint-abandoned-eap-session-and-started-new#comment-form
09-17-2014 11:23 PM
I am seeing this error when a windows supplicant is booting up, we want them to use EAP-TLS. Before the GPOs has struck, they try to authenticate using EAP-PEAP on their own, which they aren't configured to do. Shortly after that, they send the EAP-TLS packets. After the supplicant has been authenticated, the 5440 error shows up but without affecting the authentication.
My guess is that this is the result of Windows behaviour. This generates a couple of "failed" authentications that in our case just confuse the costumer. I know this isn't an answer on your question, just my experience with the problem.
01-01-2018 05:52 PM
I had same problem with you, could you have solution to fix it?
09-18-2014 05:49 PM
Possibly a Bug CSCui21439
Known fixes on below release,
05-22-2015 10:59 AM
cciesec333,
Were you able to correct this problem? We are experiencing the same problems.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide