09-30-2017 02:59 AM - edited 02-21-2020 10:35 AM
Hello Guys,
i faced this error "5440 Endpoint abandoned EAP session and started new"when users try to authoticate to network ( wired 802.1X) with ISE 2.3 .
FYI: before rebooting client machine users can authenticate normaly to the network.
In event manager on windows 10 i have this error: "Unable to identify a user for 802.1X authentication"
any idea please ???
Regards,
Solved! Go to Solution.
11-15-2018 02:51 PM
@raam, the "authentication mac-move permit" is on the switch side, and disabling the "EAP-TLS L-bit" is on the ISE side. What is the problem you're having?
09-30-2017 10:14 AM
Hi,
When the users stop responding to EAP reauthentication or start authentication while the NAD already have existing session, this message gets generated. Exmaple, when the endpoint hibernate and comes back online.
On the switch try the command 'authentication mac-move permit'. This will enable the NAD to terminate the existing 802.1x session and starts new one when a request is received while there is an existing session for the endpoint.
Also, there are couple of bugs related to windows 7 which can generate this message on ISE. Worth checking if they are applicable to windows 10. Here you go.
Please remeber to rate useful posts.
10-01-2017 05:08 AM
thank you for your response !
i will see tomorrow this command can resolve the problem or not.
10-01-2017 05:12 AM
10-02-2017 03:08 AM
hi,
the problem persist with this command.
Regards,
10-02-2017 03:58 AM
hello,
it works fine with NAM cisco Annyconnect.
Regards,
10-02-2017 08:13 AM
10-06-2017 02:20 AM
06-28-2018 01:26 PM
And news in this issue? Did it solve the problem of disconnections?
07-03-2018 12:15 AM
08-15-2019 04:01 PM
It also worked for me
11-15-2018 02:16 PM
Hi Can you please tell me which place are you telling this settings on PC or on ISE side?
Thanks
11-15-2018 02:51 PM
@raam, the "authentication mac-move permit" is on the switch side, and disabling the "EAP-TLS L-bit" is on the ISE side. What is the problem you're having?
03-10-2020 05:32 AM
Hey ,
I have the same issue as mentioned before but its between ISE and Xerox printer and between them there is a meraki SW .so on meraki SW the printer cannot get an dynamic IP address with the same error 5440 .
please let me know what can i do
02-03-2021 01:02 AM
I ✔ "EAP-TLS L-bit" on the ISE side, it worked. I dont know why. I just update the agent resources from cisco site. And then appeared this same case.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide