cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3511
Views
0
Helpful
2
Replies

dot1x authentication failed

Rickey369
Level 1
Level 1

Hi,

 

A user is getting dot1.x authentication failed. I connected the user laptop to the switch and i shut& no shut the switch interface.

I got the following debug logs.

 

the config on the switch port is same as the other port and rest of the ports works fine. I cannot connect any laptop to this port. The user connecting to this gets "Network2" domain instead of abc.com .

is this because of ISE employed in our site ?

-----------------------------------------------------

 

Oct 31 10:58:08.340: %ILPOWER-5-IEEE_DISCONNECT: Interface Gi1/0/25: PD removed
Oct 31 10:58:08.697: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:58:09.700: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to down
Oct 31 10:59:00.667: %ILPOWER-7-DETECT: Interface Gi1/0/25: Power Device detected: IEEE PD
Oct 31 10:59:01.702: %ILPOWER-5-POWER_GRANTED: Interface Gi1/0/25: Power granted
Oct 31 10:59:06.106: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:07.106: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/25, changed state to up
Oct 31 10:59:50.482: %DOT1X-5-FAIL: Authentication failed for client (e9ba.8006.1ac1) on Interface Gi1/0/25 AuditSessionID 0A20D4670001BA 128558887 packets output, 101177004390 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out

 

 

--------------------------------------------------

 

 

Pls help me find the root cause.

 

rick

2 Replies 2

Hi,
Have you checked the RADIUS server logs for a reason why authentication has failed?
What is the output of "show authentication session interface Gig 1/0/25"?

Turn on debugging "debug radius" and try connecting a laptop, please upload the output of the debug here.

nspasov
Cisco Employee
Cisco Employee

Can you:

1. Check in ISE and see if this particular port has a specific/special policy that is different than the rest of them

2. Post the switchport configuration

 

Thank you for rating helpful posts!

Thank you for rating helpful posts!
Review Cisco Networking for a $25 gift card