cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1360
Views
0
Helpful
7
Replies

Cisco ISE 802.1X Configuration

AbrarMukit
Level 1
Level 1

Hi, I am new to Cisco ISE. Trying to set up authentication and authorization based on the certificate but it's not working. I have configured my router for the AAA model as well my test laptop got a certificate. I have uploaded the same root cert to cisco ISE as a trusted cert. 

AbrarMukit_0-1662078502930.pngWhen it's authenticating its using the MAB authenticating method instead of 802.1x

 

7 Replies 7

ammahend
VIP
VIP

If it’s going mab then make sure your supplicant (endpoint) is properly configured for EAP-TLS.  The picture you attached is blurr so I can not confirm your policy.

follow this guide, even if you have different version of ISE concept is same  : https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/214975-configure-eap-tls-authentication-with-is.html

-hope this helps-

AbrarMukit_1-1662084015731.png

 

AbrarMukit_5-1662084104146.png

 

AbrarMukit
Level 1
Level 1

Steps

 11001Received RADIUS Access-Request
 11017RADIUS created a new session
 11027Detected Host Lookup UseCase (Service-Type = Call Check (10))
 15049Evaluating Policy Group
 15008Evaluating Service Selection Policy
 15048Queried PIP
 15048Queried PIP
 15041Evaluating Identity Policy
 15048Queried PIP
 15048Queried PIP
 22072Selected identity source sequence
 15013Selected Identity Source -
 24210Looking up User in Internal Users IDStore - 60:6D:3C:D3:F3:F1
 24216The user is not found in the internal users identity store
 15013Selected Identity Source -
 24497Selected Active Directory Scope is empty
 15013Selected Identity Source -
 24631Looking up User in Internal Guests IDStore
 24633The user is not found in the internal guests identity store
 22016Identity sequence completed iterating the IDStores
 22056Subject not found in the applicable identity store(s)
 22058The advanced option that is configured for an unknown user is used
 22060The 'Continue' advanced option is configured in case of a failed authentication request
 24715ISE has not confirmed locally previous successful machine authentication for user in Active Directory
 15036Evaluating Authorization Policy
 24209Looking up Endpoint in Internal Endpoints IDStore - 60:6D:3C:D3:F3:F1
 24211Found Endpoint in Internal Endpoints IDStore
 15048Queried PIP
 15016Selected Authorization Profile - DenyAccess
 15039Rejected per authorization profile
 11003Returned RADIUS Access-Reject
 5434Endpoint conducted several failed authentications of the same scenario

AbrarMukit
Level 1
Level 1

Overview

Event5434 Endpoint conducted several failed authentications of the same scenario
Username60:6D:3C:D3:F3:F1
Endpoint Id60:6D:3C:D3:F3:F1 
 
Endpoint ProfileUnknown
Authentication PolicyNomad_Test >> Nomad_R1
Authorization PolicyNomad_Test >> Default
Authorization ResultDenyAccess

 

Authentication Details

Source Timestamp2022-09-02 11:10:25.992
Received Timestamp2022-09-02 11:10:25.992
Policy Serverdidge-lab-ise1
Event5434 Endpoint conducted several failed authentications of the same scenario
Failure Reason15039 Rejected per authorization profile
ResolutionAuthorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results.
Root causeSelected Authorization Profile contains ACCESS_REJECT attribute
Username60:6D:3C:D3:F3:F1
Endpoint Id60:6D:3C:D3:F3:F1
Endpoint ProfileUnknown
IPv4 Address10.200.130.57
Identity GroupUnknown
Audit Session Id0AC8823400000FFB13D7B942
Authentication Methodmab
Authentication ProtocolLookup
Service TypeCall Check
Network DeviceDidgeLab_3850
Device TypeAll Device Types
LocationAll Locations#h
NAS IPv4 Address10.200.130.52
NAS Port IdGigabitEthernet1/0/17
NAS Port TypeEthernet
Authorization ProfileDenyAccess

 

Other Attributes

ConfigVersionId6827
Device Port1645
DestinationPort1812
RadiusPacketTypeAccessRequest
UserName60-6D-3C-D3-F3-F1
ProtocolRadius
NAS-IP-Address10.200.130.52
NAS-Port60000
Framed-MTU1500
OriginalUserName606d3cd3f3f1
IsEndpointInRejectModefalse
NetworkDeviceProfileNameCisco
NetworkDeviceProfileIdb0699505-3150-4215-a80e-6753d45bf56c
IsThirdPartyDeviceFlowfalse
RadiusFlowTypeWiredMAB
SSIDC8-00-84-D3-F8-11
AcsSessionIDdidge-lab-ise1/448433138/2982
UseCaseHost Lookup
SelectedAuthenticationIdentityStoresInternal Users
SelectedAuthenticationIdentityStoresAll_AD_Join_Points
SelectedAuthenticationIdentityStoresGuest Users
IdentityPolicyMatchedRuleNomad_R1
AuthorizationPolicyMatchedRuleDefault
CPMSessionID0AC8823400000FFB13D7B942
EndPointMACAddress60-6D-3C-D3-F3-F1
ISEPolicySetNameNomad_Test
IdentitySelectionMatchedRuleNomad_R1
StepData5= Radius.Service-Type
StepData6= Network Access.Protocol
StepData8= Radius.Service-Type
StepData9= Network Access.Protocol
StepData10=All_User_ID_Stores
StepData11=Internal Users
StepData14=All_AD_Join_Points
StepData15=All_AD_Join_Points
StepData16=Guest Users
StepData27= Normalised Radius.RadiusFlowType
DTLSSupportUnknown
HostIdentityGroupEndpoint Identity Groups:Unknown
Network Device ProfileCisco
LocationLocation#All Locations#h
Device TypeDevice Type#All Device Types
IPSECIPSEC#Is IPSEC Device
Called-Station-IDC8:00:84:D3:F8:11
CiscoAVPairservice-type=Call Check
audit-session-id0AC8823400000FFB13D7B942
methodmab

 

Result

RadiusPacketTypeAccessReject
AuthenticationResultUnknownUser

 

Session Events

2022-09-02 11:08:54.27Authentication failed

Hi @AbrarMukit ,

 please double check your NAD configuration, special attention to the:

(config-if)# authentication order dot1x mab
(config-if)# authentication priority dot1x mab

also, use the debug radius all to check EAP packets from the Endpoint to the NAD.

Hope this helps !!!

Thats what it giving when I am trying to configure the NAD
Switch(config-if)#authentication order dot1x mab
Command deprecated (authentication order dot1x mab) - use cpl config