cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
893
Views
10
Helpful
4
Replies

ISE - Wired Dot1x EAP-TLS - Intermittent

cegsm
Level 1
Level 1

Hi

New to ISE and want to use it for Dot1x authentication of windows AD clients using computer certificates with a Cisco 2960X switch.

I've got this working and the live logs show success and always end with a 'Returned RADIUS Access-Accept' 

My issue is that half of the time the client shows as failed authentication, often after being disconnected and reconnected, seems to work ok after most reboots. This happens even when the ISE logs showed success.

I'd be grateful for any help or suggestions on troubleshooting.

Thanks

1 Accepted Solution

Accepted Solutions

Check Cisco Bug: CSCvv93417, if conditions are met, upgrading to latest release will do the trick

View solution in original post

4 Replies 4

Nancy Saini
Cisco Employee
Cisco Employee

Hi @cegsm 

I would suggest checking below at the time of issue:

  1.  Authentication status of the endpoint on the network device.
  2.  IP connectivity on the client. Is it able to reach the network?
  3.  Any failed authentication request seen on the ISE server.
  4.  Check EAP, dot1x and RADIUS debugs on the network device.

Are clients connecting to the network via AnyConnect NAM or native supplicant?

Greg Gibbs
Cisco Employee
Cisco Employee

There is not enough information to provide any meaningful assistance for this issue. See How to Ask the Community for Help.

You should start by comparing your environment against the ISE Secure Wired Access Prescriptive Deployment Guide.

If you are new to ISE concepts, you might also want to review some of the relevant ISE Webinar training videos.

Check Cisco Bug: CSCvv93417, if conditions are met, upgrading to latest release will do the trick

Hi Massimo

We were indeed on the affected version, after moving the test laptops to the master switch it works perfectly

Thanks very much !