cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1220
Views
0
Helpful
4
Replies

MAC learning on ISE authenticated switch port

patrick.dice
Level 1
Level 1

Seeing an issue on 4000IE switches, and others,  with Identity Services Engine authentication setup not learning the mac address of the client.  Running 152-4.EA9 on 4k switch with auth config below.

Suspect devices not permitted to talk on network until authenticated but with switch port not learning MAC of client then that never occurs.  Dont want to start statically assigning address's to ports and the security team would like all ports to be authenticated.  Anyone else seeing this issue?

 

"authentication control-direction in
authentication event fail action next-method
authentication event server dead action authorize voice
authentication event server alive action reinitialize
authentication host-mode multi-auth
authentication port-control auto
authentication periodic
authentication timer reauthenticate server
authentication timer inactivity server dynamic
authentication violation restrict
mab
dot1x pae authenticator
dot1x timeout tx-period 7
dot1x max-reauth-req 3"

4 Replies 4

marce1000
VIP
VIP

 

 - For starters check the relevant authentication logs on ISE and check what happens when the client  tries to authenticate.

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Mark,  the switch port never learns the MAC address and hence no authentication is performed.  ISE never gets the request to authenticate the port.  If I force switch to learn MAC via alternate methods, ie static assignment,  ISE performs as expected.

The switchport sees the device is connected in that the port comes up but never learns the client MAC address.

 

 - You are using quite a lot of port-options (settings); you should kind of tree-walk the 'settings-tree' either top-down or bottom up, to see 'from where' the problems start (e.g.). 

  M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

markasulin
Level 1
Level 1

Hi , 

i have this issue also what was the problem?

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco