cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1414
Views
0
Helpful
7
Replies
Highlighted
Beginner

dot1x failing on certain clients after upgrade to 150-2.SE

We upgraded our switches recently from the 12 train to 150 train. We are now getting this error message on some clients which is forcing us to bypass authentication. Other ports are working just fine. It seems to happen most when users move there laptops to different locations.

%DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi0/5              

88    1803.73xx.xxxx    DYNAMIC     Drop

notice above the MAC address is listed as DROP....

any ideas?

Aaron

7 REPLIES 7
Highlighted
Rising star

Could you show us the interface config for port Gi0/5 ?

Highlighted

sure

aaa authentication dot1x default group radius

interface gigabitethernet0/30

switchport access vlan 1

switchport mode host

authentication port-control auto

dot1x pae authenticator

spanning-tree portfast

Highlighted

How is the client supposed to be authenticated? (EAP, PEAP, etc)? Also, can you post a screen shot of the detailed screen from the live authentication screen?

Highlighted

Clients are authenticating using PEAP. I don't know what you mean by a detailed screen from live authentication screen? On the switch, we are getting this error in the logs %DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi0/5. We are using MS NAP for Radius. The request isn't even arriving to the NAP, as its getting denied from the Switch before it gets to NAP so there is no event results-

Aaron

Highlighted

Unknown mac means the switch is not seeing any mac address on the port, but there is link, so dot1x is just running, but there is no radius request sent to your radius server.

Try to do a show mac-address-table interface x/x, and see if any macs are known on the port. If yes, try to shut/no shut the port, and see if that triggers the dot1x process.

Highlighted

debug authentication all

debug radius

show authentication sessions

Highlighted
Cisco Employee

Did you ever get this resolved?