Currently have an issue with new user attempting to logon to workstations with anyconnect and NAM installed connected to a 802.1x switchport. If the user typed in the incorrect credentials they received the following errors "no logon servers available to service the logon request ", instead if windows telling the user that incorrect username or password was enter. On ISE side I see it logged as the user enter the wrong credentials. If a user typed in their credentials correctly, the no error. I been looking at the packet capture, when the user enter the wrong password I don't see traffic between the workstation and the AD servers, it just goes straight to the error. I have a permit all DACL applied during on the switchport during machine authentication process, so no traffic should be blocked. I have contacted TAC on this issue, they haven't see this issue before, so it suppose to work as design. I was wondering has encounter this issue, thanks