cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2269
Views
0
Helpful
1
Replies

Authorization Failure Reason: ACL Failure

Walker
Level 1
Level 1

I have a Cisco 3650 on IOS XE 16.12.06 that has some endpoints connected to it and authorizing successfully via MAB.

Here is the issue that has happened multiple times now - Randomly, usually during the middle of the night, these devices will fail with the following error:

%SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (abcd.1234.954a) on Interface GigabitEthernet1/0/5 AuditSessionID 0A98004A000000115673EC93. Failure Reason: ACL Failure. Failed attribute name xACSACLx-IP-ALLOW-627e6a57.

The devices do have a reauthentication timer set and the DACL is pulled from ISE. The DACL is a single line, allowing ipv4 any. The fix action for when this occurs is to just bounce the port - then they will auth successfully.

Does anyone have an idea of what could be causing this random ACL failure?

1 Reply 1

Rodrigo Diaz
Cisco Employee
Cisco Employee

hello @Walker , your behavior may be related to the following bug CSCvz32377 , it would be worthy to verify if with a different version of IOS the behavior improves. 

Let me know if that helped you.