cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
695
Views
0
Helpful
17
Replies

NAC Failure | Authentication failed for client - TimeOut

ramirezcyrus
Level 1
Level 1

Jan 30 17:11:56.881: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:12:41.882: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:13:26.884: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:16:35.380: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:26:56.744: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:27:41.746: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

Jan 30 17:28:26.748: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous

17 Replies 17

Timeout it seem SW can not connect to server

Share 

Show aaa server <<-

Debug aaa authentication <<- 

MHM

SW1#show aaa server

RADIUS: id 1, priority 1, host 10.23.96.51, auth-port 1812, acct-port 1813, hostname ISE-Local
State: current UP, duration 3281428s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 662311, timeouts 4, failover 0, retransmission 4
Response: accept 19291, reject 0, challenge 643016
Response: unexpected 2, server error 0, incorrect 0, time 5ms
Transaction: success 662307, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 661626, avg response time: 5ms
Transaction: timeouts 0, failover 0
Transaction: total 18610, success 18610, failure 0
MAC auth transactions:
Response: total responses: 681, avg response time: 100ms
Transaction: timeouts 0, failover 0
Transaction: total 681, success 681, failure 0
Author: request 45, timeouts 0, failover 0, retransmission 0
Response: accept 45, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 1ms
Transaction: success 45, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 32991, timeouts 1792, failover 0, retransmission 1792
Request: start 3788, interim 23729, stop 3682
Response: start 3788, interim 23729, stop 3682
Response: unexpected 0, server error 0, incorrect 0, time 3ms
Transaction: success 31199, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0

RADIUS: id 2, priority 2, host 10.1.90.58, auth-port 1812, acct-port 1813, hostname ISE-NJCS
State: current UP, duration 3281428s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0

RADIUS: id 3, priority 3, host 10.1.80.32, auth-port 1812, acct-port 1813, hostname ISE-LACS
State: current UP, duration 3281425s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0
SW1#

SW1#sh aaa server

 

RADIUS: id 1, priority 1, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-Local

State: current UP, duration 3349063s, previous duration 0s

Dead: total time 0s, count 0

Platform State from SMD: current UP, duration 4294967s, previous duration 0s

SMD Platform Dead: total time 0s, count 0

Platform State from WNCD (1) : current UP

Platform State from WNCD (2) : current UP

Platform State from WNCD (3) : current UP

Platform State from WNCD (4) : current UP

Platform State from WNCD (5) : current UP

Platform State from WNCD (6) : current UP

Platform State from WNCD (7) : current UP

Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s

Platform Dead: total time 0s, count 0UP

Quarantined: No

Authen: request 742007, timeouts 4, failover 0, retransmission 4

Response: accept 21204, reject 0, challenge 720799

Response: unexpected 2, server error 0, incorrect 0, time 5ms

Transaction: success 742003, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Dot1x transactions:

Response: total responses: 741312, avg response time: 5ms

Transaction: timeouts 0, failover 0

Transaction: total 20513, success 20513, failure 0

MAC auth transactions:

Response: total responses: 691, avg response time: 99ms

Transaction: timeouts 0, failover 0

Transaction: total 691, success 691, failure 0

Author: request 47, timeouts 0, failover 0, retransmission 0

Response: accept 47, reject 0, challenge 0

Response: unexpected 0, server error 0, incorrect 0, time 1ms

Transaction: success 47, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

MAC author transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

Account: request 35296, timeouts 1810, failover 0, retransmission 1810

Request: start 3951, interim 25684, stop 3851

Response: start 3951, interim 25684, stop 3851

Response: unexpected 0, server error 0, incorrect 0, time 3ms

Transaction: success 33486, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Elapsed time since counters last cleared: 5w3d18h17m

Estimated Outstanding Access Transactions: 0

Estimated Outstanding Accounting Transactions: 0

Estimated Throttled Access Transactions: 0

Estimated Throttled Accounting Transactions: 0

Maximum Throttled Transactions: access 0, accounting 0

Consecutive Response Failures: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Consecutive Timeouts: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Requests per minute past 24 hours:

high - 18 hours, 16 minutes ago: 0

low - 18 hours, 16 minutes ago: 0

average: 0

 

RADIUS: id 2, priority 2, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-NJ

State: current UP, duration 3349064s, previous duration 0s

Dead: total time 0s, count 0

Platform State from SMD: current UP, duration 4294967s, previous duration 0s

SMD Platform Dead: total time 0s, count 0

Platform State from WNCD (1) : current UP

Platform State from WNCD (2) : current UP

Platform State from WNCD (3) : current UP

Platform State from WNCD (4) : current UP

Platform State from WNCD (5) : current UP

Platform State from WNCD (6) : current UP

Platform State from WNCD (7) : current UP

Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s

Platform Dead: total time 0s, count 0UP

Quarantined: No

Authen: request 0, timeouts 0, failover 0, retransmission 0

Response: accept 0, reject 0, challenge 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Dot1x transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

MAC auth transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

Author: request 0, timeouts 0, failover 0, retransmission 0

Response: accept 0, reject 0, challenge 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

MAC author transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

Account: request 0, timeouts 0, failover 0, retransmission 0

Request: start 0, interim 0, stop 0

Response: start 0, interim 0, stop 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Elapsed time since counters last cleared: 5w3d18h17m

Estimated Outstanding Access Transactions: 0

Estimated Outstanding Accounting Transactions: 0

Estimated Throttled Access Transactions: 0

Estimated Throttled Accounting Transactions: 0

Maximum Throttled Transactions: access 0, accounting 0

Consecutive Response Failures: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Consecutive Timeouts: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Requests per minute past 24 hours:

high - 18 hours, 16 minutes ago: 0

low - 18 hours, 16 minutes ago: 0

average: 0

 

RADIUS: id 3, priority 3, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-LA

State: current UP, duration 3349062s, previous duration 0s

Dead: total time 0s, count 0

Platform State from SMD: current UP, duration 4294967s, previous duration 0s

SMD Platform Dead: total time 0s, count 0

Platform State from WNCD (1) : current UP

Platform State from WNCD (2) : current UP

Platform State from WNCD (3) : current UP

Platform State from WNCD (4) : current UP

Platform State from WNCD (5) : current UP

Platform State from WNCD (6) : current UP

Platform State from WNCD (7) : current UP

Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s

Platform Dead: total time 0s, count 0UP

Quarantined: No

Authen: request 0, timeouts 0, failover 0, retransmission 0

Response: accept 0, reject 0, challenge 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Dot1x transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

MAC auth transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

Author: request 0, timeouts 0, failover 0, retransmission 0

Response: accept 0, reject 0, challenge 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

MAC author transactions:

Response: total responses: 0, avg response time: 0ms

Transaction: timeouts 0, failover 0

Transaction: total 0, success 0, failure 0

Account: request 0, timeouts 0, failover 0, retransmission 0

Request: start 0, interim 0, stop 0

Response: start 0, interim 0, stop 0

Response: unexpected 0, server error 0, incorrect 0, time 0ms

Transaction: success 0, failure 0

Throttled: transaction 0, timeout 0, failure 0

Malformed responses: 0

Bad authenticators: 0

Elapsed time since counters last cleared: 5w3d18h17m

Estimated Outstanding Access Transactions: 0

Estimated Outstanding Accounting Transactions: 0

Estimated Throttled Access Transactions: 0

Estimated Throttled Accounting Transactions: 0

Maximum Throttled Transactions: access 0, accounting 0

Consecutive Response Failures: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Consecutive Timeouts: total 0

SMD Platform : max 0, current 0 total 0

WNCD Platform: max 0, current 0 total 0

IOSD Platform : max 0, current 0 total 0

Requests per minute past 24 hours:

high - 18 hours, 16 minutes ago: 0

low - 18 hours, 16 minutes ago: 0

average: 0

SW1#

 

SW1#sh dot1x interface gi3/0/28

Dot1x Info for GigabitEthernet3/0/28

--------------------------------------------

PAE = AUTHENTICATOR

QuietPeriod = 60

ServerTimeout = 0

SuppTimeout = 30

ReAuthMax = 2

MaxReq = 2

TxPeriod = 15

 

SW1#

ramirezcyrus
Level 1
Level 1

Port configuration:

nterface <port number>

description User-Voice Vlan_Nac-Config

switchport access vlan <vlan id>

switchport mode access

switchport voice vlan <vland id>

device-tracking attach-policy q-device-tracking

ip access-group IPV4_PRE_AUTH_ACL in

no cdp enable

authentication event fail action next-method

authentication host-mode multi-auth

authentication open

authentication order dot1x mab

authentication priority dot1x mab

authentication port-control auto

authentication timer reauthenticate server

authentication violation restrict

mab

dot1x pae authenticator

dot1x timeout tx-period 15

spanning-tree portfast

authentication event fail action next <<- this not need

authentication open <<-this Needed since you use pre-auth ACL

Also share output of command I share above

MHM

I ran the debug aaa authentication command but I see no output so far.

The issue seems to be the docking stations. Connecting directly to the laptops and desktops we are able to authenticate within 15 seconds. 

@ramirezcyrus the MAC address in the output appears to be a Plugable Technologies dock? So that dock is failing authentication in ISE and being rejected? Look to enable MAC passthrough https://community.cisco.com/t5/network-access-control/docking-station-best-practice-with-802-1x-authentication-and/td-p/4719031

 

We did think of this but unfortunately, we are not able to complete this task. The laptops do not have this capability. 

 

We are not testing wired autoconfig disabled to see if that can work.

Apologies for my last comment. I meant to say, I want to test to see if I disable Wired AutoConfig and kept Wireless AutoConfig enabled only, if I can bypass this issue. Since the BIOS of our laptops do not allow mac address bypass, I'm at a loss what else I can do. This method I'm suggesting does not fullfil our requirement but it would stop the calls until I can figure out how to resolve this docking station issue. Please advise, thanks.

 

That won't work. Some brain surgeon configure EAP-PEAP for wireless and we are doing EAP-TEAP for wired.... Any suggestions.

Hi friend

Can I see how you config policy set in ISE?

MHM