We have configured our access switchports to MAB to authenticate in the event the Radius server is unreachable and reinitialize and reauthenticate when the Radius server becomes reachable. We experienced a recent occurance where a port was authenticated as the Radius server was unreachable for a MAC address which is part of the Black List on our ISE server, which is the expected behavior, but once the Radius server became reachable again (in this particular instance the up stream switch was down/up) the port failed to reinitialize and remained authorized with the Black Listed MAC. The port needed to be reset to force re authorization. The following configuration is included on the port
authentication event server dead action authorize
authentication event server alive action reinitialize
Any ideas/suggestions on how to cause the port to reauthenticate after RADIUS server connection is restored would be appreciated