dot1x authentication failed
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2018 05:45 AM - edited 02-21-2020 08:25 AM
Hi,
A user is getting dot1.x authentication failed. I connected the user laptop to the switch and i shut& no shut the switch interface.
I got the following debug logs.
the config on the switch port is same as the other port and rest of the ports works fine. I cannot connect any laptop to this port. The user connecting to this gets "Network2" domain instead of abc.com .
is this because of ISE employed in our site ?
-----------------------------------------------------
Oct 31 10:58:08.340: %ILPOWER-5-IEEE_DISCONNECT: Interface Gi1/0/25: PD removed
Oct 31 10:58:08.697: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:58:09.700: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:59:00.667: %ILPOWER-7-DETECT: Interface Gi1/0/25: Power Device detected: IEEE PD
Oct 31 10:59:01.702: %ILPOWER-5-POWER_GRANTED: Interface Gi1/0/25: Power granted
Oct 31 10:59:06.106: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:07.106: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:50.482: %DOT1X-5-FAIL: Authentication failed for client (e9ba.8006.1ac1) on Interface Gi1/0/25 AuditSessionID 0A20D4670001BA 128558887 packets output, 101177004390 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out
--------------------------------------------------
Pls help me find the root cause.
rick
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-31-2018 06:06 AM
Have you checked the RADIUS server logs for a reason why authentication has failed?
What is the output of "show authentication session interface Gig 1/0/25"?
Turn on debugging "debug radius" and try connecting a laptop, please upload the output of the debug here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-16-2018 09:33 PM
Can you:
1. Check in ISE and see if this particular port has a specific/special policy that is different than the rest of them
2. Post the switchport configuration
Thank you for rating helpful posts!
