cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
382
Views
0
Helpful
3
Replies

AuthIZ profiles

dear all i have problem with Authiz policy  what i say the user must authica first and be in any groups of the list and need to be android 

 

if i remove the last condation that contant andorid the Authiz work 

saeedabdelhalimhamada_0-1744013613911.png

 

 

 

 

Overview

Event5400 Authentication failed
Usernametest
Endpoint Id48:9B:E0:E8:B3:AB 
 
Endpoint ProfileAndroid
Authentication PolicyWireless-802.1x-NIB-WIFI SSID >> Wireless-802.1X
Authorization PolicyWireless-802.1x-NIB-WIFI SSID >> Default
Authorization ResultDenyAccess

Authentication Details

Source Timestamp2025-04-07 10:09:42.769
Received Timestamp2025-04-07 10:09:42.769
Policy ServerISE-01
Event5400 Authentication failed
Failure Reason15039 Rejected per authorization profile
ResolutionAuthorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results.
Root causeSelected Authorization Profile contains ACCESS_REJECT attribute
Usernametest
Endpoint Id48:9B:E0:E8:B3:AB
Calling Station Id48-9b-e0-e8-b3-ab
Endpoint ProfileAndroid
Authentication Identity StoreNibHQ-AD
Identity Groupallow-list-testing
Audit Session Id1510640A00021E800F4C53B6
Authentication Methoddot1x
Authentication ProtocolPEAP (EAP-MSCHAPv2)
Service TypeFramed
Network DeviceWLC-01
Device TypeAll Device Types
LocationAll Locations
NAS IPv4 Address10.100.16.21
NAS Port Idcapwap_900000b8
NAS Port TypeWireless - IEEE 802.11
Authorization ProfileDenyAccess
Response Time33 milliseconds

Other Attributes

ConfigVersionId173
Device Port63398
DestinationPort1812
RadiusPacketTypeAccessRequest
ProtocolRadius
NAS-Port21617
Framed-MTU1485
State37CPMSessionID=1510640A00021E800F4C53B6;34SessionID=ISE-01/531755997/1489426;
undefined-18600:0f:ac:04
undefined-18700:0f:ac:04
undefined-18800:0f:ac:01
NetworkDeviceProfileIdb0699505-3150-4215-a80e-6753d45bf56c
IsThirdPartyDeviceFlowfalse
AcsSessionIDISE-01/531755997/1489426
DetailedInfoAuthentication succeed
SelectedAuthenticationIdentityStoresNibHQ-AD
IdentityPolicyMatchedRuleWireless-802.1X
AuthorizationPolicyMatchedRuleDefault
EndPointMACAddress48-9B-E0-E8-B3-AB
ISEPolicySetNameWireless-802.1x-NIB-WIFI SSID
IdentitySelectionMatchedRuleWireless-802.1X
AD-User-Resolved-Identitiestest@nibhq.local
AD-User-Candidate-Identitiestest@nibhq.local
TotalAuthenLatency99
ClientLatency66
AD-User-Resolved-DNsCN=TEST,OU=Users,OU=57_Central Affairs Sector,OU=NIB-Sectors,DC=nibhq,DC=local
AD-User-DNS-Domainnibhq.local
AD-Groups-Namesnibhq.local/Builtin/Users
AD-Groups-Namesnibhq.local/NIB-Sectors/57_Central Affairs Sector/57_Central Affairs Sector
AD-Groups-Namesnibhq.local/Users/Domain Users
AD-User-NetBios-NameNIBHQ
IsMachineIdentityfalse
UserAccountControl66048
AD-User-SamAccount-Nametest
AD-User-Qualified-Nametest@nibhq.local
TLSCipherECDHE-RSA-AES256-GCM-SHA384
TLSVersionTLSv1.2
DTLSSupportUnknown
HostIdentityGroupEndpoint Identity Groups:allow-list-testing
Network Device ProfileCisco
LocationLocation#All Locations
Device TypeDevice Type#All Device Types
IPSECIPSEC#Is IPSEC Device#No
ExternalGroupsnibhq.local/S-1-5-32-545
ExternalGroupsS-1-5-21-4129499605-3250610629-1857627236-18513
ExternalGroupsS-1-5-21-4129499605-3250610629-1857627236-513
IdentityAccessRestrictedfalse
RADIUS Usernametest
NAS-IdentifierWLC-01
Device IP Address10.100.16.21
CPMSessionID1510640A00021E800F4C53B6
Called-Station-IDcc-7f-75-58-37-40:NIB_WIFI
CiscoAVPairservice-type=Framed,audit-session-id=1510640A00021E800F4C53B6,method=dot1x,client-iif-id=1711278343,vlan-id=1,cisco-wlan-ssid=NIB_WIFI,wlan-profile-name=NIB_WIFI_Global_F_a7fb7e41,AuthenticationIdentityStore=NibHQ-AD,FQSubjectName=e0d4af20-de9d-11ed-ab69-7e7af6e903ec#test@nibhq.local,UniqueSubjectID=4fced747fcb06203d7961e0773857192d1963517

Result

RadiusPacketTypeAccessReject

Session Events

2025-04-07 10:09:42.769Authentication failed
 

Steps

 Step IDDescriptionLatency (ms)
 11001Received RADIUS Access-Request - NibHQ-AD
 11017RADIUS created a new session - nibhq.local0
 15049Evaluating Policy Group - NibHQ-AD1
 15008Evaluating Service Selection Policy0
 15048Queried PIP - DEVICE.Device Type0
 15048Queried PIP - Radius.NAS-Port-Id1
 15048Queried PIP - DEVICE.Network Device Profile0
 15048Queried PIP - Normalised Radius.RadiusFlowType0
 15048Queried PIP - Radius.Called-Station-ID0
 11507Extracted EAP-Response/Identity1
 12500Prepared EAP-Request proposing EAP-TLS with challenge0
 12625Valid EAP-Key-Name attribute received0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request5
 11018RADIUS is re-using an existing session0
 12301Extracted EAP-Response/NAK requesting to use PEAP instead0
 12300Prepared EAP-Request proposing PEAP with challenge0
 12625Valid EAP-Key-Name attribute received0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request4
 11018RADIUS is re-using an existing session0
 12302Extracted EAP-Response containing PEAP challenge-response and accepting PEAP as negotiated0
 61025Open secure connection with TLS peer1
 12319Successfully negotiated PEAP version 10
 12800Extracted first TLS record; TLS handshake started0
 12805Extracted TLS ClientHello message0
 12806Prepared TLS ServerHello message0
 12807Prepared TLS Certificate message0
 12808Prepared TLS ServerKeyExchange message8
 12810Prepared TLS ServerDone message0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request7
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request6
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request25
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 12319Successfully negotiated PEAP version 10
 12810Prepared TLS ServerDone message0
 12812Extracted TLS ClientKeyExchange message2
 12803Extracted TLS ChangeCipherSpec message0
 12804Extracted TLS Finished message0
 12801Prepared TLS ChangeCipherSpec message0
 12802Prepared TLS Finished message0
 12816TLS handshake succeeded0
 12310PEAP full handshake finished successfully0
 12305Prepared EAP-Request with another PEAP challenge1
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request4
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 12313PEAP inner method started0
 11521Prepared EAP-Request/Identity for inner EAP method0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request6
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 11522Extracted EAP-Response/Identity for inner EAP method0
 11806Prepared EAP-Request for inner method proposing EAP-MSCHAP with challenge0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request6
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 11808Extracted EAP-Response containing EAP-MSCHAP challenge-response for inner method and accepting EAP-MSCHAP as negotiated0
 15041Evaluating Identity Policy1
 15013Selected Identity Source - NibHQ-AD1
 24430Authenticating user against Active Directory - NibHQ-AD0
 24325Resolving identity - test2
 24313Search for matching accounts at join point - nibhq.local0
 24319Single matching account found in forest - nibhq.local0
 24323Identity resolution detected single matching account0
 24343RPC Logon request succeeded - test@nibhq.local2
 24402User authentication against Active Directory succeeded - NibHQ-AD0
 22037Authentication Passed0
 11824EAP-MSCHAP authentication attempt passed0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request4
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response1
 11810Extracted EAP-Response for inner method containing MSCHAP challenge-response0
 11814Inner EAP-MSCHAP authentication succeeded0
 11519Prepared EAP-Success for inner EAP method0
 12314PEAP inner method finished successfully0
 12305Prepared EAP-Request with another PEAP challenge0
 11006Returned RADIUS Access-Challenge0
 11001Received RADIUS Access-Request3
 11018RADIUS is re-using an existing session0
 12304Extracted EAP-Response containing PEAP challenge-response0
 24715ISE has not confirmed locally previous successful machine authentication for user in Active Directory0
 15036Evaluating Authorization Policy1
 24209Looking up Endpoint in Internal Endpoints IDStore - test0
 24211Found Endpoint in Internal Endpoints IDStore1
 15048Queried PIP - Network Access.AuthenticationStatus0
 24432Looking up user in Active Directory - test
 24355LDAP fetch succeeded
 24416User's Groups retrieval from Active Directory succeeded
 15048Queried PIP - NibHQ-AD.ExternalGroups3
 15048Queried PIP - Session.Device-OS0
 15016Selected Authorization Profile - DenyAccess1
 15039Rejected per authorization profile0
 12306PEAP authentication succeeded0
 61026Shutdown secure connection with TLS peer0
 11503Prepared EAP-Success0
 11003Returned RADIUS Access-Reject1
3 Replies 3

PSM
Level 1
Level 1

This is because from the radius packet ISE is not able to identify if it the device OS is android. Either you remove this or you find another better attribute which can be used in condition.

ok i use profile called android and also didnt work 

PSM
Level 1
Level 1

Can you share updated policy and logs ?