01-30-2025 12:36 PM
Jan 30 17:11:56.881: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:12:41.882: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:13:26.884: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:16:35.380: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:26:56.744: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:27:41.746: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
Jan 30 17:28:26.748: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (8cae.4cc6.58f6) with reason (Timeout) on Interface Gi2/0/29 AuditSessionID 035A170A000002F1B83067BE Username: anonymous
01-30-2025 12:40 PM
Timeout it seem SW can not connect to server
Share
Show aaa server <<-
Debug aaa authentication <<-
MHM
01-31-2025 07:06 AM
SW1#show aaa server
RADIUS: id 1, priority 1, host 10.23.96.51, auth-port 1812, acct-port 1813, hostname ISE-Local
State: current UP, duration 3281428s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 662311, timeouts 4, failover 0, retransmission 4
Response: accept 19291, reject 0, challenge 643016
Response: unexpected 2, server error 0, incorrect 0, time 5ms
Transaction: success 662307, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 661626, avg response time: 5ms
Transaction: timeouts 0, failover 0
Transaction: total 18610, success 18610, failure 0
MAC auth transactions:
Response: total responses: 681, avg response time: 100ms
Transaction: timeouts 0, failover 0
Transaction: total 681, success 681, failure 0
Author: request 45, timeouts 0, failover 0, retransmission 0
Response: accept 45, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 1ms
Transaction: success 45, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 32991, timeouts 1792, failover 0, retransmission 1792
Request: start 3788, interim 23729, stop 3682
Response: start 3788, interim 23729, stop 3682
Response: unexpected 0, server error 0, incorrect 0, time 3ms
Transaction: success 31199, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0
RADIUS: id 2, priority 2, host 10.1.90.58, auth-port 1812, acct-port 1813, hostname ISE-NJCS
State: current UP, duration 3281428s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0
RADIUS: id 3, priority 3, host 10.1.80.32, auth-port 1812, acct-port 1813, hostname ISE-LACS
State: current UP, duration 3281425s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w2d23h30m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 23 hours, 29 minutes ago: 0
low - 23 hours, 29 minutes ago: 0
average: 0
SW1#
01-31-2025 07:49 AM
SW1#sh aaa server
RADIUS: id 1, priority 1, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-Local
State: current UP, duration 3349063s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 742007, timeouts 4, failover 0, retransmission 4
Response: accept 21204, reject 0, challenge 720799
Response: unexpected 2, server error 0, incorrect 0, time 5ms
Transaction: success 742003, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 741312, avg response time: 5ms
Transaction: timeouts 0, failover 0
Transaction: total 20513, success 20513, failure 0
MAC auth transactions:
Response: total responses: 691, avg response time: 99ms
Transaction: timeouts 0, failover 0
Transaction: total 691, success 691, failure 0
Author: request 47, timeouts 0, failover 0, retransmission 0
Response: accept 47, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 1ms
Transaction: success 47, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 35296, timeouts 1810, failover 0, retransmission 1810
Request: start 3951, interim 25684, stop 3851
Response: start 3951, interim 25684, stop 3851
Response: unexpected 0, server error 0, incorrect 0, time 3ms
Transaction: success 33486, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w3d18h17m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 18 hours, 16 minutes ago: 0
low - 18 hours, 16 minutes ago: 0
average: 0
RADIUS: id 2, priority 2, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-NJ
State: current UP, duration 3349064s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w3d18h17m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 18 hours, 16 minutes ago: 0
low - 18 hours, 16 minutes ago: 0
average: 0
RADIUS: id 3, priority 3, host 10.x.x.x, auth-port 1812, acct-port 1813, hostname ISE-LA
State: current UP, duration 3349062s, previous duration 0s
Dead: total time 0s, count 0
Platform State from SMD: current UP, duration 4294967s, previous duration 0s
SMD Platform Dead: total time 0s, count 0
Platform State from WNCD (1) : current UP
Platform State from WNCD (2) : current UP
Platform State from WNCD (3) : current UP
Platform State from WNCD (4) : current UP
Platform State from WNCD (5) : current UP
Platform State from WNCD (6) : current UP
Platform State from WNCD (7) : current UP
Platform State from WNCD (8) : current UP, duration 0s, previous duration 0s
Platform Dead: total time 0s, count 0UP
Quarantined: No
Authen: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Dot1x transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
MAC auth transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Author: request 0, timeouts 0, failover 0, retransmission 0
Response: accept 0, reject 0, challenge 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
MAC author transactions:
Response: total responses: 0, avg response time: 0ms
Transaction: timeouts 0, failover 0
Transaction: total 0, success 0, failure 0
Account: request 0, timeouts 0, failover 0, retransmission 0
Request: start 0, interim 0, stop 0
Response: start 0, interim 0, stop 0
Response: unexpected 0, server error 0, incorrect 0, time 0ms
Transaction: success 0, failure 0
Throttled: transaction 0, timeout 0, failure 0
Malformed responses: 0
Bad authenticators: 0
Elapsed time since counters last cleared: 5w3d18h17m
Estimated Outstanding Access Transactions: 0
Estimated Outstanding Accounting Transactions: 0
Estimated Throttled Access Transactions: 0
Estimated Throttled Accounting Transactions: 0
Maximum Throttled Transactions: access 0, accounting 0
Consecutive Response Failures: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Consecutive Timeouts: total 0
SMD Platform : max 0, current 0 total 0
WNCD Platform: max 0, current 0 total 0
IOSD Platform : max 0, current 0 total 0
Requests per minute past 24 hours:
high - 18 hours, 16 minutes ago: 0
low - 18 hours, 16 minutes ago: 0
average: 0
SW1#
01-31-2025 07:50 AM
SW1#sh dot1x interface gi3/0/28
Dot1x Info for GigabitEthernet3/0/28
--------------------------------------------
PAE = AUTHENTICATOR
QuietPeriod = 60
ServerTimeout = 0
SuppTimeout = 30
ReAuthMax = 2
MaxReq = 2
TxPeriod = 15
SW1#
01-30-2025 12:44 PM
Port configuration:
nterface <port number>
description User-Voice Vlan_Nac-Config
switchport access vlan <vlan id>
switchport mode access
switchport voice vlan <vland id>
device-tracking attach-policy q-device-tracking
ip access-group IPV4_PRE_AUTH_ACL in
no cdp enable
authentication event fail action next-method
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
authentication timer reauthenticate server
authentication violation restrict
mab
dot1x pae authenticator
dot1x timeout tx-period 15
spanning-tree portfast
01-30-2025 12:49 PM - edited 01-31-2025 07:18 AM
authentication event fail action next <<- this not need
authentication open <<-this Needed since you use pre-auth ACL
Also share output of command I share above
MHM
01-31-2025 08:00 AM
I ran the debug aaa authentication command but I see no output so far.
01-30-2025 01:07 PM
The issue seems to be the docking stations. Connecting directly to the laptops and desktops we are able to authenticate within 15 seconds.
01-30-2025 01:28 PM
@ramirezcyrus the MAC address in the output appears to be a Plugable Technologies dock? So that dock is failing authentication in ISE and being rejected? Look to enable MAC passthrough https://community.cisco.com/t5/network-access-control/docking-station-best-practice-with-802-1x-authentication-and/td-p/4719031
01-30-2025 02:24 PM
We did think of this but unfortunately, we are not able to complete this task. The laptops do not have this capability.
01-30-2025 02:25 PM
We are not testing wired autoconfig disabled to see if that can work.
01-30-2025 02:32 PM
Apologies for my last comment. I meant to say, I want to test to see if I disable Wired AutoConfig and kept Wireless AutoConfig enabled only, if I can bypass this issue. Since the BIOS of our laptops do not allow mac address bypass, I'm at a loss what else I can do. This method I'm suggesting does not fullfil our requirement but it would stop the calls until I can figure out how to resolve this docking station issue. Please advise, thanks.
01-30-2025 02:36 PM
That won't work. Some brain surgeon configure EAP-PEAP for wireless and we are doing EAP-TEAP for wired.... Any suggestions.
01-31-2025 07:19 AM
Hi friend
Can I see how you config policy set in ISE?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide