cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6433
Views
5
Helpful
2
Replies

authentication event fail action next-method, does not fail over to next method.

Jim Araujo
Level 1
Level 1

Hello, I am not sure why this is happening. We have a phone and windows PC on port fa0/11. Fa0/11 has dot1x enabled on it with the fail action to go to the next-method. The Windows PC fails MAB (first method) but the switch never moves on ot try dot1x (second method). Am I missing something?

Some debugs (this is the PC):

Jul 12 13:24:13.921 EDT: %AUTHMGR-5-START: Starting 'mab' for client (xxxx.yyyy.5572) on Interface Fa0/11 AuditSessionID 0A0A070B0000008F0E46E0DA
Jul 12 13:24:13.963 EDT: %MAB-5-FAIL: Authentication failed for client (xxxx.yyyy.5572) on Interface Fa0/11 AuditSessionID 0A0A070B0000008F0E46E0DA
Jul 12 13:24:13.963 EDT: %AUTHMGR-5-FAIL: Authorization failed for client (xxxx.yyyy.5572) on Interface Fa0/11 AuditSessionID 0A0A070B0000008F0E46E0DA
interface FastEthernet0/11
 switchport access vlan 221
 switchport mode access
 switchport voice vlan 121
 authentication event fail retry 1 action next-method
 authentication event server dead action authorize voice
 authentication event server alive action reinitialize
 authentication host-mode multi-domain
 authentication order mab dot1x
 authentication port-control auto
 authentication periodic
 authentication timer restart 0
 authentication timer reauthenticate server
 authentication violation protect
 mab
 dot1x pae authenticator
 dot1x timeout quiet-period 5
 dot1x timeout server-timeout 5
 dot1x timeout tx-period 5
 dot1x timeout supp-timeout 5
 spanning-tree portfast
1 Accepted Solution

Accepted Solutions

Jim Araujo
Level 1
Level 1

Knew it was something simple.

I was  missing the  global config command dot1x system-auth-control

View solution in original post

2 Replies 2

Jim Araujo
Level 1
Level 1

Knew it was something simple.

I was  missing the  global config command dot1x system-auth-control

Good job on resolving your own issue and also thank you for taking the time to come back and update the thread (+5 from me). 

Also, when I run into issues I always take advantage of ISE's Evaluate Configuration Validator located under Operations > Troubleshoot > General Tools. It is not 100% accurate but it definitely helps you complete a quick sanity check on a NAD. 

I hope this helps!

Thank you for rating helpful posts!