ISE 1.1.3 posture status OK but network connection failed

hello,
I am on my way to make this ISE works.
Now I am able to do posture assessment and reauthenticate with success.
The logs says that's OK, I have two lines.
NACAgent on the host do the job correctly but the NIC says : "Network failure" despite NACagent grants the access.
Any Ideas folks ???
Regards.
Vincent.
The switch says :
03:04:28: %AUTHMGR-5-START: Starting 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8
03:04:59: %DOT1X-5-FAIL: Authentication failed for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID
03:04:59: %AUTHMGR-7-RESULT: Authentication result 'no-response' from 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8
03:04:59: %AUTHMGR-7-FAILOVER: Failing over from 'dot1x' for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8
03:04:59: %AUTHMGR-7-NOMOREMETHODS: Exhausted all authentication methods for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8
03:04:59: %AUTHMGR-5-FAIL: Authorization failed for client (bcae.c530.0948) on Interface Fa1/0/1 AuditSessionID C0A8066400000028009C4FA8
Here is the SW's config :
aaa new-model
aaa authentication dot1x default group radius
aaa authorization network default group radius
aaa authorization auth-proxy default group radius
aaa accounting dot1x default start-stop group radius
aaa server radius dynamic-author
client 192.168.6.10 server-key 123456789
aaa session-id common
no ip domain-lookup
ip domain-name security.com
ip dhcp excluded-address 192.168.6.29 192.168.6.100
ip dhcp pool test
   network 192.168.6.0 255.255.255.0
ip dhcp snooping vlan 1
ip device tracking
dot1x system-auth-control
dot1x critical eapol
spanning-tree mode pvst
spanning-tree extend system-id
vlan internal allocation policy ascending
interface FastEthernet1/0/1
switchport mode access
authentication open
authentication port-control auto
authentication periodic
authentication timer reauthenticate server
dot1x pae authenticator
dot1x timeout tx-period 10
spanning-tree portfast
interface Vlan1
ip address 192.168.6.100 255.255.255.0
ip classless
ip http server
ip http secure-server
ip sla enable reaction-alerts
snmp-server community snmp RO
snmp-server enable traps mac-notification change move threshold
snmp-server host 192.168.6.10 version 2c snmp  mac-notification
radius-server attribute 6 on-for-login-auth
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
radius-server dead-criteria time 5 tries 3
radius-server host 192.168.6.10 auth-port 1645 acct-port 1646 key 123456789
radius-server vsa send accounting
radius-server vsa send authentication
line con 0
line vty 5 15
ntp clock-period 36029254
ntp server 192.168.6.29
end

Hello Tarik, thanks for trying to help !
I guess that we all have configured the Sw and ISE as described in the documentation.
It would be kind to give us a standard Sw config that works. In my opinion, dACL is the point to be clarified urgently.
No IP Phone at all.
How to configure dACL on ISE ? ( pre-posture, redirect ) ????
What are the ports ? ( 8443, 8905n any ?)
Do we need a ACL to be set in the Sw before the dACL is applied ???
Please answer those questions first, and we will provide you some logs.
I'am not able to have a stable behaviour any more.
Lastest tested IOS : c3750-ipbasek9-mz.122-52.SE.bin (compatibility matrix on Cisco Website)
We waste of lot of time trying not to debug the software, but trying to find which parts work together.
Thanks again Tarik.

Similar Messages

  • I cannot get my iMac with built-in airport to allow internet connections to Nook and PS3. The devices access the network, but internet connection fails. Internet sharing is enabled, network security (WEP, WPA) is completely off.  What to check next?

    I cannot get my iMac with built-in airport wi-fi to allow internet connections to Nook and PS3. The devices access the network, but internet connection fails. Internet sharing is enabled, network security (WEP, WPA) is disabled.  What to check next?

    On an additional note, I've purchased a wireless router and everything connected on the first attempt.  It just vexes me that the built-in wireless isn't working as a router.  Is this another example of "Mac only plays with Mac"?

  • IMessage/ FaceTime not going on iPad. Have internet connection but 'network connection error' message coming up

    I Have seen similar questions to this but still can't seem to be able to fix the issue...
    a Few months ago my iMessage and FaceTime stopped working, along with any notifications from apps such as Facebook. iMessage comes up saying 'iMessage activation. Could not sign in. Please check network connection settings.' I am currenttly using wifi on my iPad so I have internet, I've signed in and out of iTunes - as apps such  as Facebook when open come up with 'connect to iTunes to receive push notifications.' I've checked the date and set it to automatically update and I've tried using different wifi And I've tried resetting the network settings. Does anyone have any other ideas? It's really annoying!
    TThanks

    Hi, Trinahughes. 
    Thank you for visiting Apple Support Communities. 
    Try updating your devices to iOS 7.0.3 which was recently released as it provides a fix for issues with  iMessage and FaceTime.  If the issue persists, try the troubleshooting steps in the article below.
    iOS 7.0.3
    http://support.apple.com/kb/DL1691
    iOS: Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/ts4268
    Cheers,
    Jason H.

  • Airplay is stop working but network connection ok: airport express

    Hi,
    I hope someone could help me, I can't find the solution.
    I have an airport express which I use for internet access and airplay.
    Sometimes when I awake (from sleep mode) my MBP (running OSX 10.6.8) airplay doesn't work anymore. It means Itunes says that remote speaker airport express cannot be found and airport utility can't find the airport express either. But internet connection still works perfectly!
    So I have to reboot the MBP to get back my airplay service, the problem seems to be on the mac.
    I have updated airport utility and airport express to the latest firmware, so I don't have any other idea.
    Would you have ideas?
    Thanks!

    Found the fix under a different search. Turns out the Linksys router was blocking the iTunes. Have no idea why it would show up momentarily and then disappear though. In any event, the fix is:
    I have a wired Ethernet network and run through a Linksys cable/DSL 4-port router. Model #BEFSR41. Here's how we fixed the problem step-by-step:
    1) Open a browser window and access the router control panel by typing in 192.168.1.1
    2) Click on the "Security" button at the top of the screen
    3) There are two subnav options under Security. Click on "Filter IP" (I believe it's already highlighted.)
    4) At the bottom of that page, there is a set of four or five radio buttons. One of them says "Filter Multicast". Mine was disabled. CLICK THIS TO ENABLED.
    This fix comes directly from this post about getting Apple TV to work:
    http://discussions.apple.com/thread.jspa?threadID=2234430&tstart=0
    Hope this helps anyone else who has this problem!

  • Installed Oracle Workflow Client but database connection fails,why?

    Hi
    I have installed Oracle Workflow Client (windows) but database connection using apps user (EBS R12 database) is not establishing.Getting the following error '1300:Could not load'. How can i make succesfull connection & use it?
    Regards
    Ariz

    Hi,
    Please see these documents.
    Note: 389432.1 - 2.6.x: Access the Builder errors with 1300, 1114, 1101, 333, 332, 306 & 203: Value contains leading or trailing spaces
    Note: 747485.1 - Oracle Workflow Builder: Could not load from database Error
    Note: 179987.1 - Workflow Builder Cannot Load Objects From Applications when the NLS_LANG is Non-American
    Regards,
    Hussein

  • Time capsule doesnt show up anymore but network connection works

    I meant to make my user name i hate time capsule. Time machine, I actually like.
    Here is the situation, and I am lost as to what to do, and nervous about rebooting or resetting the time capsule.
    My network connections work fine. I have an iMAc and a macbookpro that both are getting excellent wireless connections.
    The problem is that the time machine backups have stopped working because they cant see the drive anymore. (Initial backups worked fine.)
    I did do the firmware upgrade to 7.3.1, but didnt notice anything strange immediately.
    Airport Utility is useless. It claims there is no wireless device in range, even though it is using the wireless device to make a network connection.
    Now, my first guess is that rebooting the device might help, but I worry that it will be the death of my network connection, which I dont want to do without the ability to commit a day to fixing it.
    Any advice is appreciated.

    Hi,
    I'm not techno-geek at all, but I had a similar problem when I did something and Airport Utility no longer could find Time Capsule. I tried one thing and TC wound up with the amber light blinking. Ultimately I just reset TC. Doing that shifts everything back to factory settings, so you have to go through the set up like new all over again, naming your network, re-entering passwords, etc. Between me and Keychain I was able to duplicate what I had entered previously. Airport Utility did it's job and TC has been working fine ever since. For all of this, I just followed the directions in the TC booklet.
    You might want to wait for a few other posts to see if others advise the same, but maybe this will be helpful. Good luck.

  • AirPort Express indicates status OK, but no connection!!

    My AirPort Express has been going down hill ever since maybe 6-8 months after I purchased it. First it started losing the connection randomly and it would flash yellow for about 10 min. until it got it back every 5-6 hours or so. Then AirTunes would not work. Now after I've finally gotten those under control (i think!), It seems to just randomly just stop working, but it doesn't indicate so. The AirPort Express meter on my powerbook just has no signal, and the AirPort Express is not in the list of available wireless networks. This is not just my computer, 4 other laptops in my house (3 pc, 1 ibook w/ built in airport) are experiencing the same. However, when I go and look @ the AirPort Express, the light is still a solid green as if it were working fine, and usually if i just unplug it and wait about 30 seconds and then plug it back in, it works fine again. But why is it doing this, and is their anything i can do to fix it!?!
    P.S. my AirPort Express is running on 6.2 firmware if that makes any diff.

    Since your Airport Express is still under warranty, I suggest you try to get a warranty replacement for it.

  • Windows 7 No internet Access but network connected

    Just installed Win7 which was needed for BF3 as i was previously using XP. All was good until my net has just stopped. the LAN icon on the task bar has the yellow symbol with the "!" mark on it.
    ive tried unistalling and reinstalling drivers for my NIC. tried resetting my tcp stack, release/renew, dnsflush. have gone through the forums and tried the Bonjour services fix. nothing works. also tried rolling back restore points, no go.
    the pc has 2 drives which i switch between, 1 with xp still and 1 with win 7. the xp drives still works no problem and another pc connecting via wi-fi also works just not Win7.
    when running the diagnosting tool it keeps coming up with dns not responding
    would love some help. this is BS

    OK I found the answer! It is a McAfee bug. Go to
    http://mvt.mcafee.com. Run Autofix and update the Def file and your done. Wasted too much time on this. I check the Dell Support and they also had this solution.
    http://support.dell.com/support/topics/global.aspx/support/kcs/document?c=us&cs=19&docid=576372&l=en&s=dhs
    Thanks for posting this! And get this...just yesterday I received an email (from my working laptop) from McAfee titled "Service Notification: Important Update for your PC". Yea, whatever, I'll get to it later. My desktop hadn't connected to the internet
    for a couple of days. Tonight I started troubleshooting and couldn't figure it out. I had network access; my router was giving me an IP and my gateway was my router. But I couldn't ping the router and couldn't get to the internet.
    Then I searched and thankfully found your post! As soon as I read it was a McAfee bug I remembered that crucial email! Pasted below is a subset of the entire email, with the relevant portion for those of us who can only access the internet after -rebooting
    into 'Safe Mode with Networking':
    from: [email protected]
    Use this procedure for McAfee Virtual Technician (MVT) to detect and repair the issue. The following steps will repair your product and update your McAfee
    software.
    Run McAfee Virtual Technician (MVT)
    1. Launch your web browser and go to http://mvt.mcafee.com.
    2. On the Welcome screen, click Next.
    NOTE: The message McAfee
    Virtual Technician not found means that MVT is not YET installed on your system. 
    3. Click Next again.
    4. When you are prompted to save or run the file, click Run.
    Click Run a second time
    if prompted by the Windows operating system.
    NOTE: Windows Vista and 7 users may be prompted to allow the application to run. Click Yes in
    the User Account Control dialog if prompted.
    5. Click I Agree to
    begin the installation.
    6. Click Finish to
    complete the installation.
    7. When the MVT installation completes, click Next to
    run the scan.
    8. If MVT detects issues with your McAfee software, leave the default optionAutoFix and
    click Next. 
    If there are no issues, MVT will complete on its own.
    9. When MVT and the AutoFix complete, restart your computer.
    Ensure the MVT solution worked properly
    After your computer restarts please confirm the following:
    You should able to access Internet resources by going to familiar web pages.
    You should be able to open your McAfee Security software by double-clicking on the M icon in the Windows system tray.
    When McAfee SecurityCenter opens, the status bar should be green and state that "Your computer is secure".
    While the McAfee SecurityCenter window is still open, you should request and complete an update successfully by doing the following:
    1. Click the Updates drawer.
    2. Click Check for Updates.
    Run a quick scan
    After you know that you can access the Internet and your system is protected, perform a quick scan:
    1. Open McAfee SecurityCenter by double-clicking on the M icon
    in the Windows system tray.
    2. Click the Real-Time Scanning drawer.
    3. Click the Scan your PC option.
    4. Click Run a quick scan.
    If you still experience issues, continue to the next Resolution.

  • Remote connection works but local connection fails.

    Hi
    I know this might not be the correct forum, but many DBAs might have encountered this problem.
    I have a machine installed on it Oracle 9.2.0.1.0 Win 2000
    and i have forms 6i installed on it with patchset 16.
    In my tnsnames i have 2 different connections 'DEV' and 'PROD'. DEV is the local db and PROD is the remote db.
    Whenever i connect to the remote db everything's working perfectly, but whenever i try to connect to the local db fors or sqlplus or any other tool is generating an error and being closed. I uninstalled and re-installed 4 times maybe, i even formatted my machine and re-installed everything fresh but the problem persists.
    Anyone encountered anything like this??
    Any suggestion is apreciated, help needed urgent!
    Thanks in advance.
    Tony S. Garabedian

    Hi again
    i tried everything but no changes, so i re-installed forms6 i noticed during installation the followin error message.
    C:docum. & settings\all users\start menu\programs\Oracle Developer 60 - <ORACLE_HOME> is not accessible.
    The folder was moved or removed.
    after that when i tried to run anything, form builder sqlplus80 etc... all i got was this.
    <program_name> The ordinal 8030 could not be located in the dynamic link library UIW60.dll.
    Please i need urgent help
    Regards
    Tony
    PS: THANKS GOD FOR 9iDS :)

  • Printer reports Offline but network connected

    My deskjet 3056a printer prints wirelessly with no problem most of the time. But occasionally reports being offline. After I set it to share on network it typically works again but now will not change from offline. Typically messes up after power blinks on and off. (I have Windows 8)

    This article should help with your printer offline error:
    http://h10025.www1.hp.com/ewfrf/wc/document?docname=c02221706&cc=us&dlc=en&lc=en
    Give the steps outlined a try and let us know if it helps.
    Best of Luck!
    You can say thanks by clicking the Kudos Star in my post. If my post resolves your problem, please mark it as Accepted Solution so others can benefit too.

  • Ipad update failed, says network connection failed or timed out, but have good coverage, tried several times

    Been trying to update my ipad, and it keeps failing. the screen message I get says network failed ot timed out. Have no problem with internet coverage. Have tried on several occasions now.

    Tap Settings > General > Reset > Reset Network Settings
    Then restart the device.
    Hold the On/Off Sleep/Wake button down until the red slider appears. Slide your finger across the slider to turn off iPhone. To turn iPhone back on, press and hold the On/Off Sleep/Wake button until the Apple logo appears.

  • Why with Firefox 33.0 do I get "secure connection failed" when I bring up my banking site, but it doesn't happen using Firefox 32.0.3?

    The website comes up fine but "secure connection failed" shows in the space where I'm supposed to put my account number. (I'm prevented from putting my account number in that field.) This computer is running Win 7 Pro. The older version of Firefox on another computer with Win XP has no such problem with the website, nor does the IE browser on this computer.

    One possibility is: Some users had problems with secure sites starting in Firefox 31 related to the new PKIX security component, and worked around it by disabling it. Starting in Firefox 33, it can no longer be disabled, and that setting is ignored.
    Are you comfortable posting the address of the login page so others could see whether they have the same experience with the form?

  • ISE Posture Status Pending

    Hello,
    I am newly configuring and testing  Posturing/Client Provissioning on ISE.  I configured Client_Provissioning Policy without any Posture_Policy just to test it works or not.
    My Wireless client can authenticate and get and install NAC_Agent successfully,  but after that no network access is given to the client pc. 
    on the ISE Authentication Reports it shows ( Posture Status Pending )
    and on the Wireless client everytime when i open browser i get this message " Cisco Agent was detected and is running. If you are still unable to access the network please contact you administrator"
    I dont know what is the issue, plz help

    Hi Ravi,
    I have not yet configured any Posture policies.  i have configured only client-provissioning policy, i want to first test client-provissioning works properly before applying any Posture-Policy.
    So My wireless clients are correctly redirected and recieve NAC Agent, but afterthat it seems that the NAC_Agent does not do anything and does not send any report back to ise for further processings.
    on the ise Authentication Report i can see, the client is stuck in UKNOWN-STATUS , and shows Posture_Status Pending...
    it does not go to Uncompliant or Compliant Status.
    I dont know what can be the issue? neither ISE shows me the error , nor the WLC.

  • Ise posture status notapplicable

    Hello ,
             after upgrading ISE 1.2 to 1.2.1 , I can't see posture status (pending) although it is working properly. I tried to install patch 1 but the same result.
    before upgrading , posture status was Pending when posture status still not reach to ISE.

    I have same problem too.
    When workstation install NacAgent 4.9.4.3 successfully, then the posture will be stucked.
    I didn't see about NAC Agent on report: "Posture Detailed Assessment" and "Client Provisioning"
    Any help or advice please ? Should I configure the redirect ACL, dACL, switch ACL, or something like that ?

  • [ISE] Posture Status - Not applicable

    Hi,
    I configured WiFi Guest Access with WLC and ISE and it works great.
    Now I want to check client posture.
    I configured a posture policy
    On Windows7 client, I installed NAC client. With network sniffer, I can see SWISS protocol (TCP 8905) between client and ISE.
    In authentications log, Posture Status is always "NotApplicable"
    Why is this posture not applicable?
    Thanks a lot!
    Patrick

    Hello Tarik,
    Result NonCompliant: http://uploaddeimagens.com.br/imagens/result_noncompliant-jpg
    Posture rule: http://uploaddeimagens.com.br/imagens/posture_rule-jpg
    The client provisioning is set to force NAC Agent version 4.9.0.47
    Yes, the vlan is correct.
    The major problem is the NotApplicable ststus in the posture log, the ISE is not applying the posture, some times works fine, some times dont work and appear the NotApplicable in the log.

Maybe you are looking for

  • Mail.app not working

    I'm running an iMac G5 with OS 10.6.8. Someone moved our Mail.app off of the doc and now it will not work. I tried to reinstall it with the Snow Leopard disc and I also updated the combo package. The Mail.app shows up in the applications folder but g

  • How do I middle click and close tabs in safari? please help!

    I am used to google chrome and  adapted to use middle clicks to interact with tabs. My friend introduced me to safari and as i am using macbook pro I think using safari should be more compatible. The only thing that is holding me back is closing tabs

  • How do I print a list of messages in an Inbox?

    I have 4 e-mail accounts and have a separate Inbox for each account. Is there a way to print a list of the messages in a particular Inbox? I'm just looking for a simple list that I can open in Word or Excel with the From, Subject and Received or Sent

  • HT4528 How do I use a song I bought in iTunes as my ringtone?

    How do I use a song I purchased through iTunes as my ringtone?

  • Changing Content type

    Hi all, We are trying to post data from XI to a Webservice using SOAP adapter. XI sends the payload in "application/xml" content type whereas the webservice expects the "text/xml" content type. Though I have used the standard apdater module "localejb