02-22-2017 03:12 AM - edited 03-11-2019 12:29 AM
Dears,
we have fingerprint machines, when connecting the machine to a port configured for dot1x the dot1x authentication fails, and MAB authentication keeps in running state as the result below. the mac address keeps unknow
Interface: GigabitEthernet3/0/7
MAC Address: Unknown
IP Address: Unknown
Status: Running
Domain: UNKNOWN
Security Policy: Should Secure
Security Status: Unsecure
Oper host mode: multi-domain
Oper control dir: both
Session timeout: N/A
Idle timeout: N/A
Common Session ID: 0A0A6507000032815AE3D7D3
Acct Session ID: 0x000097C0
Handle: 0x8F000394
Runnable methods list:
Method State
dot1x Failed over
mab Running
and i receive the message below
%DOT1X-5-FAIL: Authentication failed for client (Unknown MAC) on Interface Gi3/0/7 AuditSessionID 0A0A6507000032965B2927BB
%AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (Unknown MAC) on Interface Gi3/0/7 AuditSessionID 0A0A6507000032965B2927BB
%AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (Unknown MAC) on Interface Gi3/0/7 AuditSessionID 0A0A6507000032965B2927BB
no port security is configured on the port.
when we remove the dot1x configuration and configure port security we see the machine mac address on the port.
switch ios Version 15.0(2)SE10a switch hardware 3750 stacked.
please advise,
Thanks in advance.
02-22-2017 03:44 AM
Hi Maher,
Could you change the authentication order and make it 'mab' first then dot1x and check the status?
Regards,
Kush
02-22-2017 04:45 AM
Hi Kush,
I've had tried that too with no news.
Thanks,
Maher
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide