cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3301
Views
0
Helpful
2
Replies

dot1x authentication failed

Rickey369
Level 1
Level 1

Hi,

 

A user is getting dot1.x authentication failed. I connected the user laptop to the switch and i shut& no shut the switch interface.

I got the following debug logs.

 

the config on the switch port is same as the other port and rest of the ports works fine. I cannot connect any laptop to this port. The user connecting to this gets "Network2" domain instead of abc.com .

is this because of ISE employed in our site ?

-----------------------------------------------------

 

Oct 31 10:58:08.340: %ILPOWER-5-IEEE_DISCONNECT: Interface Gi1/0/25: PD removed
Oct 31 10:58:08.697: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:58:09.700: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:59:00.667: %ILPOWER-7-DETECT: Interface Gi1/0/25: Power Device detected: IEEE PD
Oct 31 10:59:01.702: %ILPOWER-5-POWER_GRANTED: Interface Gi1/0/25: Power granted
Oct 31 10:59:06.106: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:07.106: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:50.482: %DOT1X-5-FAIL: Authentication failed for client (e9ba.8006.1ac1) on Interface Gi1/0/25 AuditSessionID 0A20D4670001BA 128558887 packets output, 101177004390 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out

 

 

--------------------------------------------------

 

 

Pls help me find the root cause.

 

rick

2 Replies 2

Hi,
Have you checked the RADIUS server logs for a reason why authentication has failed?
What is the output of "show authentication session interface Gig 1/0/25"?

Turn on debugging "debug radius" and try connecting a laptop, please upload the output of the debug here.

nspasov
Cisco Employee
Cisco Employee

Can you:

1. Check in ISE and see if this particular port has a specific/special policy that is different than the rest of them

2. Post the switchport configuration

 

Thank you for rating helpful posts!

Review Cisco Networking for a $25 gift card