04-18-2023 01:28 AM - edited 04-18-2023 01:30 AM
Hi everyone,
I renewed it after existing eap certificate expired. After that day, the network started to break. Most of the errors I get are "5440 Endpoint abandoned EAP session and started new". Users connect to the internet but at random times there is 10 second disconnection. After that, reconnection is established. ISE version used: 2.7.0.356. The installed patch is 9.
04-18-2023 07:27 AM
Check your supplicant configuration for the setting to "Validate server certificate". Either uncheck it altogether or make sure you include the new certificate and its CA in the list.
(Generally this is configured in an enterprise via AD GPO.)
04-18-2023 09:57 AM - edited 04-18-2023 09:58 AM
"5440 Endpoint abandoned EAP session and started new". error could be network device or client side issue. Since EAP certificate renewal is the trigger, as @Marvin Rhoads mentioned, you can toggle "Validate server certificate" and see if that fixes the issue.
Check if client is trusting the updated EAP certificate.
Also, I would suggest taking a packet capture on client to understand at which step dot1x flow is breaking and proceed accordingly.
04-18-2023 11:49 PM
Hello Marvin,
Thank you for the answer. I will try the Validate Server Certificate option and I'll update this case
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide