cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
93861
Views
53
Helpful
18
Replies

5440 Endpoint abandoned EAP session and started new

getaway51
Level 2
Level 2

Hi,

I gt this error and checked authentication report. I attached logs here. 

May I knw wht could be causing the problem? is it a bug?

It seems the device nvr established session with the ISE. It just keeps authenticating.

 

 

 

18 Replies 18

Hello Laura,

 

do you mean with "the root cert was not selected on the supplicant side", that the proper root CA was not checked in the list of root CAs under the Network Authentication Method Properties ?

Is this also what you mean with the security settings?

 

Thank you

Rishi

vaguirre17
Level 1
Level 1

Its an endpoint issue if is for only for few users. if is for all the sessions in one NAD could be an issue with the switch. With one customer we opened a SR and could find the endpoint is not replying the eap packets. increase timers could be an option but we got fixed at all using nam instead the native supplicant.

when is a Certificate issue yu could see in the live logs a different error. something like 

 
12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate
 

not exactly. i had a situation where endpoints just silently have been starting new session. 

mightncube
Level 1
Level 1

Have been having this issue, did a lot of digging and searching,,

Among certificate issues that have already been mention.

There has been a drive by Microsoft to use Credential Guard.
Turns out credential guard doesn't work well with MSCHAPv2, regards it as unsecure and advices us to use certificates.

You might wanna dig deep on the user machines doing this first point is checking the WLAN-Autoconfig logs on Event Viewer.

Then check this article, might help someone.

https://www.neighborgeek.net/2016/08/windows-10-credential-guard-breaks-wifi.html