ā08-01-2024 06:53 PM - last edited on ā08-01-2024 09:45 PM by rupeshah
Dear Cisco Community,
In my lab, PC installs Cisco Secure Client 5.1.2.42 with CM 4.3.3335.6146 (ISE 3.1 P6).
There have few PCs when turn on the first time, where SC agent status is Complaint but can not access to internal access / systems. Some times it occur randomly PC.
Remark:
- On ISE livelog we can see this endpoint status is working fine, status is Complaint.
- On PC - Cisco Secure Complaint module status is "Complaint - network access allowed" We need to wait around 2 - 3mins later then it work.
- or we need to click on "Scan Again" then PC can access to any systems and internet
Kindly review and advise how to ensure PC can work properly.
Thanks,
ā08-05-2024 05:37 AM
CoA configured properly? What is the NAD? Are you also using dACLs? Redirectionless or redirection-based posture?
ā08-05-2024 07:26 PM
ā08-06-2024 08:25 AM
Do you see successful CoA logs on live logs? What version of IOS-XE? What does show auth sessions details display for the interface when the device is having the issue?
ā08-06-2024 07:13 PM
Hello @ahollifield ,
We can see CoA on live log, Auth session is working properly.
This issue occurs the most for supplicant which sleep mode (Laptop do not turn off ) while perform authentication EAP-FAST (EAP-MSCHAPv2, EAP-TLS).
Thanks,
ā08-07-2024 08:08 AM - edited ā08-07-2024 08:08 AM
So you see a successful CoA? Note that CoA live log is a completely separate entry from the auth session. You see a log with details "Dynamic Authorization Succeeded"?
You should no longer be using MSCHAPv2. You should migrate to TLS methods. You should have a look at TEAP natively supported in Windows and not using the NAM module for EAP-FAST.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide