cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2601
Views
5
Helpful
2
Replies

ISE reject MAC authentication even though have the MAC and Authorization Profiles.

msompong1
Level 1
Level 1

Hi All Please kindly advise my problem.

 

I've the ISE 2.3 with patch 7.

I found the error that some of new MAC address that had added to the identity group cannot pass the MAB on switch port. The ISE show error like "Authorization Profile with ACCESS_REJECT attribute was selected as a result of the matching authorization rule. Check the appropriate Authorization policy rule-results."

But the authorization profile is there and other MAC in the same group can work as normal. 

Please kindly advices.

Screenshot 2021-07-22 114541.png

 

Screenshot 2021-07-22 114821.png

 

Screenshot 2021-07-22 114955.png

Screenshot 2021-07-22 115157.png

1 Accepted Solution

Accepted Solutions

msompong1
Level 1
Level 1

The issue cam solve by tuning the RADIUS suppression under Administration > System > Settings > Protocols > RADIUS

View solution in original post

2 Replies 2

Pawan Raut
Level 4
Level 4

Could you please check the static assignment and Policy assignment like Cisco-Device or any other

msompong1
Level 1
Level 1

The issue cam solve by tuning the RADIUS suppression under Administration > System > Settings > Protocols > RADIUS