cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
131
Views
0
Helpful
1
Replies

windows client fail to authenticate on wake up on the network.

cghaderpour
Level 1
Level 1

I have deployed ISE for our organization and using cert for machine authentication only. the issue that I saw in several chats talking about host/ prepended to hostname happens for my setup. I have adjust the advanced setting to rewrite host/ so that got fixed when users click on SSID to connect manually. If the computer reboot or just come up on the network it automatically must connect based on wifi profile but when I look into logs I still see host/ is prepended when the machine want to connect without user interaction and the authentication fails. what can cause ISE to not rewrite the hostname when the machine itself tries to connect automatically?  Users always have to click manually to connect otherwise host/ prepend is there.

and I see this log on ISE for failed ones

Event5411 Supplicant stopped responding to ISE
Failure Reason12935 Supplicant stopped responding to ISE during EAP-TLS certificate exchange
ResolutionVerify that supplicant is configured properly to conduct a full EAP conversation with ISE. Verify that NAS is configured properly to transfer EAP messages to/from supplicant. Verify that supplicant or NAS does not have a short timeout for EAP conversation. Check the network that connects the Network Access Server to ISE. Verify that ISE local server certificate is trusted on supplicant. Verify that supplicant has a properly configured user/machine certificate.
Root causeSupplicant stopped responding to ISE during EAP-TLS certificate exchange
1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

What WLC Controller are you using? What Logs are shown in the control run debug against the MAC address? See the errors.

What Windows Version? Is this only 1 PC issue, or do all the Windows clients have the same issue? Does any other mobile device work as expected?

Also, check the post below to see if that can help troubleshoot more.

https://community.cisco.com/t5/network-access-control/12935-supplicant-stopped-responding-to-ise-during-eap-tls/td-p/4577834

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help