06-15-2022 06:40 AM
Hello there!
I've been facing a problem on a client, dot1x authentication occurs normally the problem happens on reauthentication I have two red flags in the live log and a new authentication occurs, the problem is that users feel the connection drop and are complaining...
The first error is "11051 RADIUS packet contains invalid state attribute" followed by the error "5440 Endpoint abandoned EAP session and started new"
I even found a similar case here on the forum where the solution was to apply the command "undo dot1x multicast-trigger" on the switches, but this configuration was already applied at the time of deployment.
I appreciate any information or help!
06-15-2022 06:52 AM
is this not working after patch 11 ? in this case i will roleback to old working status, and working with TAC to troubleshoot.
06-15-2022 07:03 AM
it wasn't working even before patch 11... I was using patch 6 and the same thing happened.
I already have an open TAC but I still haven't found a solution for it.
06-15-2022 07:31 AM
TAC is the best people can assits here. so i will follow with TAC again so they are SME
06-17-2022 07:23 AM
Could you be running into the bug below?
hth
Andy
Re-auth fails 3rd party, ISE sends RADIUS state in Access-Accept packet withot Termination-Action CSCvn39378
https://bst.cisco.com/bugsearch/bug/CSCvn39378
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide