- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 06:12 AM
Hello. We have a user that has a laptop that can not get network access when used on a particular switch. His laptop gets an authenticated by ISE and gets an IP address but can not access/ping any network hosts. His issue just recently started.
All other users on this switch have no issues.
Troubleshooting steps:
I plugged my laptop to his port and I have no issues. I had him sign into my laptop and he is fine no issues.
Plugged his laptop on a different port still has the same issue.
If I plug his laptop into a different switch altogether then he has access. The issue goes away.
The port he is using does not have any errors. Full duplex, 100Mb/s etc.
Any thoughts or suggestions?
Thanks
Solved! Go to Solution.
- Labels:
-
Catalyst 4000
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:14 AM
Hello,
- What are the ISE logs saying?
- What does "show authentication sessions interface <interface name>" output?
- What is the IOS version of the Catalyst switch?
- How is his workstation authenticating to the network? MAB, 802.1X ?
- What is the NAC-related configuration on the switch? Is there dVLAN or dACL being pushed? Authentication order? etc.
Keep in mind that older IOS do not take CoA unless you add "radius-server vsa send accounting/authentication", for example.
That will help troubleshoot your issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:19 AM
Hi @GregH.NY ,
Can you share the settings of this switch and indicate the MAC of the device with connectivity problems?
Regards

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:14 AM
Hello,
- What are the ISE logs saying?
- What does "show authentication sessions interface <interface name>" output?
- What is the IOS version of the Catalyst switch?
- How is his workstation authenticating to the network? MAB, 802.1X ?
- What is the NAC-related configuration on the switch? Is there dVLAN or dACL being pushed? Authentication order? etc.
Keep in mind that older IOS do not take CoA unless you add "radius-server vsa send accounting/authentication", for example.
That will help troubleshoot your issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:19 AM
Hi @GregH.NY ,
Can you share the settings of this switch and indicate the MAC of the device with connectivity problems?
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:48 AM
Nevermind. I had the user plug his laptop back in (he was using wifi) so I can get the current authentication and ISE logs and he seems to be working again. He can get to network hosts with no issues. This issue was going on for about a week and just resolved itself. Maybe something had to time-out or something.
Thanks to all that replied!
