cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
386
Views
0
Helpful
3
Replies

Authorization failed or unapplied for client

hs08
VIP
VIP

I was success integrated C9200 to Fortinac, but from yesterday i facing some random users is loss access / move to isolation network with below message in the log. I check from fortinac and the nac send access accept, also if i unplug and plug the lan cable then all is working fine. Anyone know this is switch configuration issue, nac issue or endpoint issue?

Aug 31 15:29:57: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (6c24.08f2.ce30) on Interface GigabitEthernet1/0/20 AuditSessionID 11C8640A00004BB456F07A17. Failure reason: Authc fail. Authc failure reason: Missing Config.

Sep  1 10:53:10: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (6c24.08f2.ce30) on Interface GigabitEthernet1/0/20 AuditSessionID 11C8640A00004BB5573C62FF. Failure reason: Authc fail. Authc failure reason: Cred Fail.

 

interface GigabitEthernet1/0/20

switchport access vlan 37

switchport mode access

switchport voice vlan 38

authentication event server dead action authorize vlan 32

authentication event server dead action authorize voice

authentication event server alive action reinitialize

authentication host-mode multi-domain

authentication order dot1x mab

authentication port-control auto

authentication periodic

authentication violation restrict

mab

dot1x pae authenticator

spanning-tree portfast

end

3 Replies 3

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

I think that you're dealing with an authentication/session state problem rather than a simple FortiNAC authorization problem.

Cisco documents that periodic reauthentication causes the switch to attempt authentication again according to the reauthentication timer.

For a single test port, I would temporarily remove periodic reauthentication, then leave the PC connected for a day and see whether the problem disappears.

I am not a Cisco employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I think the issue could be caused by the command "authentication violation restrict". Please try to remove and see if that fixes the issue.

Why are you using IBNS 1.0?