cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5461
Views
8
Helpful
20
Replies

client cannot use MAC authentication with ISE

sbmc014
Level 4
Level 4

Hi , PC want to use MAC authentication with ISE but fail , i made the document for detail process and result (as attachment) , Could you help me to figure it out ? thx

20 Replies 20

sorry , after i double confirm , if i just enable PAP/ASCII in my profile (as attachment ) ,

then all clients can pass through 802.1x MAC auth even there is no this MAC exist ISE endpoint profile table , it is abnormally , what's configurations should i need to adjust ?only enable PAP and ASCII.jpg

hslai
Cisco Employee
Cisco Employee

Check the options for auth failures, especially in case of User Not Found. If User Not Found set to CONTINUE, then what you seeing is expected.

Screen Shot 2018-05-11 at 8.40.40 AM.png

ognyan.totev
Level 5
Level 5

Jason is right not same shared secret ,and i wonder in ise 2.2 we have a option to enable radius for third party vendors i dont know in ISE 2.4 there is same option

thanks for your reply , i am sure the secret value are the same between switch & ISE , it probably some other things going wrong.

ognyan.totev
Level 5
Level 5

As you see you there are invalid radius attributes .In cisco switch we define attributes like:

radius-server attribute 6 on-for-login-auth

radius-server attribute 6 support-multiple

radius-server attribute 8 include-in-access-req

radius-server attribute 25 access-request include

radius-server attribute 31 mac format ietf

radius-server vsa send accounting

radius-server vsa send authentication

I never configured switch on WEB i always do on cli.ANd this is the commands for cisco switch i don't know is your switch support it .

hslai
Cisco Employee
Cisco Employee

After reviewing your word doc, I am now thinking the user-password is not the same as the user-name. This RSA doc 000035182 - How to decrypt RADIUS traffic using... | RSA Link might help decrypting it.