Hey guys,
We have a 7 node deployment (3PSN, 2PAN, 2MNT) currently on 2.2p10. We ran the URT and everything came out fine.
However, upon upgrading the secondary PAN first, we encountered an issue that after the VM rebooted it ended up in the grub...
Hi,I have a customer running WIRELESS dot1x with ISE 2.2p6 with WSA integration. On the WIRED side, they use CDA+WSA. Trying to see if we can use the PIC feature set on a fully functional ISE deployment (not ISE PIC) without deploying wired dot1x. Th...
You might want to start with a service request so someone can do a bug scrub for you. Or see if a newer version gives you the same behavior.From preliminary searching I saw:CSCti28252Which would explain some differences in behavior when you shut/ no ...
You might want to try setting up wireshark on the end client with MAC 0019.f302.a378, see if they are sending EAP frames even after guest vlan assignment.Or turn on dot1x debugs and seeing if we RX any dot1x frames from this client.
It would make sense more perhaps if you tried 'clear authentication session interface gx/y/z'.Most likely just need to clear the current authentication session for this timer to take effect. Let me know if that doesn't work.
I assume this is happening.dot1x in your configuration fails over after tx-period X (max-reauth-req +1) which for you is 22 seconds.Auth-MGR (the software that controls (dot1x / MAB / webauth) is probably set to restart every 60 seconds.You can verif...
In new software (for Cisco switches) we provide multiple fallbacks for MAC authentication (MAB):1. 802.1x2. web authentication3. guest vlan (if no supplicant on the PC)4. auth fail vlan (if radius denies you access)So you could keep a list of MAC add...