cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2496
Views
10
Helpful
5
Replies

Wired dot1x failing from meraki switches with username USERNAME

rcullum
Level 1
Level 1

From packet capture on ISE, I can see meraki switch sends in the radius packet access-request the machine name host/<machine-name>as User-Name attribute and calling-station-id matches the endpoint mac address but in ISE I see 2 logs:

1st log says:

Event 5405 RADIUS Request dropped
Failure Reason 24708 User not found in Active Directory. Some authentication domains were not
available

because it thinks the username being passed is USERNAME.

2nd log says:

Event 5400 Authentication failed
Failure Reason 12953 Received EAP packet from the middle of conversation that contains a
session on this PSN that does not exist

for the username called USERNAME

After that, it's just being denied because MAB authentication is denying the machine mac address.

 

I don't see any ISE radius logs where the username=host/<machine-name> which is the one sent in the radius access-request.

ISE is v2.6 Patch 6

 

5 Replies 5

marce1000
VIP
VIP

 

 - Check configuration guidelines from this document :

          https://community.cisco.com/t5/security-documents/how-to-integrate-meraki-networks-with-ise/ta-p/3618650

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Also, you might want to check the option for "Disclose invalid usernames" in the Security Settings. Depending on the failure reason, enabling this setting could reveal the actual username that is being presented to ISE in the logs to aid in your troubleshooting.

That Security Setting "Disclose invalid usernames" does not appear to be in the UI. I am running v2.6 Patch 6

The option is there in 2.6 p6. Maybe ensure you're logging in with Super Admin credentials.

Screenshot from 2.6 p6:

Screen Shot 2020-07-16 at 9.35.50 am.png

Aha! They have moved it! On ISE 2.4, that was under the RADIUS Settings. Thanks.ISE_2.4_RADIUS_Settings.JPG