ISE Endpoint losing IP after transition to Low-Impact-Mode

I've recently moved an ISE implementation into the low-impact authentication phase, and the client's security cameras are having a rough go of it. In monitor mode, they were able to stay connected as they should but in low-impact mode they are losing their IP addresses as evidenced in the auth session output below:
SWITCH-1#sh auth sess int g4/0/6            Interface:  GigabitEthernet4/0/6          MAC Address:  0040.8cc7.4822           IP Address:  10.92.6.3            User-Name:  00-40-8C-C7-48-22               Status:  Authz Success               Domain:  DATA       Oper host mode:  multi-domain     Oper control dir:  both        Authorized By:  Authentication Server          Vlan Policy:  N/A              ACS ACL:  xACSACLx-IP-PERMIT_ALL_TRAFFIC-5165e13c      Session timeout:  3600s (local), Remaining: 338s       Timeout action:  Reauthenticate         Idle timeout:  N/A    Common Session ID:  0AFF320A000661C965742D42      Acct Session ID:  0x00067E9F               Handle:  0x72000982Runnable methods list:       Method   State       dot1x    Failed over       mab      Authc SuccessSWITCH-1#sh auth sess int g4/0/6            Interface:  GigabitEthernet4/0/6          MAC Address:  0040.8cc7.4822           IP Address:  169.254.45.196            User-Name:  00-40-8C-C7-48-22               Status:  Authz Success               Domain:  DATA       Oper host mode:  multi-domain     Oper control dir:  both        Authorized By:  Authentication Server          Vlan Policy:  N/A              ACS ACL:  xACSACLx-IP-PERMIT_ALL_TRAFFIC-5165e13c      Session timeout:  3600s (local), Remaining: 338s       Timeout action:  Reauthenticate         Idle timeout:  N/A    Common Session ID:  0AFF320A000661C965742D42      Acct Session ID:  0x00067E9F               Handle:  0x72000982Runnable methods list:       Method   State       dot1x    Failed over       mab      Authc Success
This is happening approx. every 10 seconds which curiously is the timer value of my dot1x tx-period. As well, the host never has its reauthentication timer restarted but I can see the following in ISE approx. every 10-15 seconds:
Why is it going through Dynamic Authorization? Why am I losing my legitimate IP address every 10 seconds and getting an APIPA address in its place? The port configuration is as follows:
interface GigabitEthernet4/0/6 description Security switchport access vlan 292 switchport mode access ip access-group ACL-DEFAULT in power inline auto max 15400 authentication event fail action next-method authentication host-mode multi-domain authentication open authentication order dot1x mab authentication priority dot1x mab authentication port-control auto authentication periodic authentication violation restrict mab dot1x pae authenticator dot1x timeout tx-period 10 storm-control broadcast level 2.00 storm-control action shutdown spanning-tree portfast spanning-tree bpduguard enableend
And my ACL-DEFAULT is...
Extended IP access list ACL-DEFAULT    10 permit udp any eq bootpc any eq bootps    20 permit udp any any eq domain    30 permit icmp any any    40 permit udp any any eq tftp    50 deny ip any any log
Upon switch log review, I'd noticed that the ACL-DEFAULT is blocking the cameras from certain igmp and tcp/554 (RTSP) communications. To see if it would help, even though I shouldn't have to, I placed ACE's into my ACL-DEFAULT to permit this traffic and would still drop my IP address every 10 seconds. I shouldn't have to do this because the "xACSACLx-IP-PERMIT_ALL_TRAFFIC-5165e13c" is a simple "permit ip any any" ACL which should allow all of the traffic to flow.
Ideas?
Kind Regards,
Kevin

As well, the dACL is properly replacing the first "any" with the endpoint's IP:
SWITCH-1#show ip access-lists interface g4/0/6
     permit ip host 169.254.45.196 any
SWITCH-1#show ip access-lists interface g4/0/6
     permit ip host 10.92.6.3 any
Kind Regards,
Kevin

Similar Messages

  • ISE low impact mode/Closed/Monitor

    Can we put the the profiles one by one into closed mode in ISE
    for example:
     You have three rules
    Group A---Switch A---DOT1X-- Low impact mode
    Group B--Swicth A--DOT1X---Closed Mode
    Group c-- Switch A-- DOT1X-- Monitor Mode.
    -  Now, after testing Low-impact mode and Monitor mode, one by one can we put them in closed mode? 
    Can we accomplish this, Rule by rule?
    Minakshi

    Deploying Monitor Mode first allows to step through all the issues, gaining visibility into successful and failed authentications, with minimal impact to the users and endpoints. Once issues have been addressed through Monitor Mode you can provide secured network access  Closed Mode.
     note :Closed Mode is recommended only for IT environments that are experienced with 802.1X deployments and have considered all the nuances that go along with it.In closed mode  any traffic prior to authentication will be dropped, including DHCP, DNS, and Address Resolution Protocol (ARP) traffic.Make sure evry thing is sorted out

  • Critical vlan in low impact mode

    Hello,
    How is it possible managed a server radius failure when I'm using low impact mode and a port acl is applied ?
    Is there a similar configuration like critical vlan used in high security mode ?
    Regards,
    Iarno
    Sent from Cisco Technical Support iPad App

    Larno,
    If you are still in low impact mode then you can leave the critical vlan as the same vlan as the access vlan then verify how the user was authorization by issuing a "show authentication sessions" command if you are going to place the users in a guest vlan or a vlan that has limited access then the port acl will only apply to the ingress traffic from the port not from any ACLs that exist on the L3 interface itself.
    Thanks
    Tarik Admani

  • Possible fix for OS X 10.5.7,  losing connection after sleep, restart

    Possible fix for OS X 10.5.7, Airport, losing connection after sleep, restart, or cold reboot.
    Issue: (For OS X 10.5.7 on iMac5,1, Intel Core 2 Duo)
    =============================================
    - After sleep, restart, cold reboot, even though cannot connect to Internet, but the AirPort bars are still full, as if connected.
    - Losing Internet connection after sleep, restart, cold reboot.
    Possible Fix:
    1.Open Network Preference, click on the Location drop down list > Edit Location... > click on the wheel button > Duplicate Location.
    a)Select this newly setup location; Use Diagnostic button to connect to the internet. Select Network or enter WEP password if necessary.
    b)Test to make sure you can connect to a web page.
    c)Go to sleep & wake up.
    d)This time, the Airport bar will start to show correctly. Before, it will always be full even when not connected. Now there will be no bars or grey out when not connected.
    2.On the left hand side of the Network Preference Window, there is a list of services, such as Airport, build-in ethernet, built-in FireWire, bluetooth, etc.
    a)Click on the wheel button on the bottom of the service list; select Set Service Order...; move Airport to the top of the list.
    b)Delete any services which you are sure that you are not going to use, such as Bluetooth, etc.
    3.Pick one of the locations mentioned in #1, and make it sure it is connected. If not, use Diagnostic button. If you have to select Network or enter WEP password to connect, make it so.
    a)Check to make sure you can connect to a web page.
    4.Go to sleep & wake up. The Airport bar should be filled up quickly. Try to connect to a web page.
    5.Restart computer. Test a web page.
    6.Shut down & Start computer. Test a web page.
    7.When everything is working fine, you can delete the extra location that you created in step #1.
    8.Click the lock on the left lower corner of the Network Preference window to safeguard the setting.

    If my assessment is correct, the LIDE 200 driver is version 14.8.1 and dated 26-Sep-2008. It is possible that the driver will not work with the latest version of OSX. I would advise that you contact Canon and ask them the question.
    (Removed link because of the way Flash drives the Canon site).
    It is not uncommon (though irritating) that devices no longer work when an OS is upgraded. One has to ask the question if (or why) the driver was not written in such a way as to be OS version independent.
    Chris
    I spoke to Canon over here in Australia. Not helpful at all. In fact they were about as useful as an ashtray on on motorcycle. Having said that the tech seemed to think that there would be an update soon. But that is assuming that Canon are aware that there is a problem with that Scanner under OS X 10.5.7.
    Message was edited by: 2point5

  • Losing internet after waking

    anyone having a prblm with the imac losing internet connection after waking up?
    [IMG]http://i88.photobucket.com/albums/k163/jerseygirlac/golfgreen.gif[/IMG]
    15 pbg4, imac core2duo   Mac OS X (10.4.7)   imac core2duo & pbg4/MM/ISIGHT/IPOD5TH/FIRELITE60GBEXT.HD ilife6/sony dcw70

    Hi computerconfuser,
    It sounds like your MacBook Pro's ethernet port is being disabled when it goes into sleep mode. Take a look at the article below for more information about sleep mode and how to prevent this from happening in the future.
    About Energy Saver sleep and idle modes in Mac OS X
    http://support.apple.com/kb/ht2412
    What happens when the Mac goes to sleep (not just into idle mode or display sleep)?
    On all Macs:
    The microprocessor goes into a low-power mode
    Video output is turned off, and a connected display may turn off or enter its own idle state
    Apple-supplied hard disks spin down; third-party hard disks may spin down
    On portable Macs:
    The Ethernet port turns off, if applicable (see note below)
    Expansion card slots turn off
    The built-in modem, if present, turns off (see note below)
    An AirPort card, if present, turns off (see note below)
    The USB ports only responds to the power key on an external keyboard (see below)
    The optical media drive, if present, spins down
    Audio input and output turns off
    Keyboard illumination, if a feature of your portable computer, turns off
    A computer uses considerably less power when in sleep mode than when awake. The computer will continue to power RAM in sleep mode, so that whatever was in RAM when the computer went to sleep will still be there when the computer wakes. This also means that computers with more RAM use slightly more power in sleep mode.
    Note: Portable computers have no network connectivity when in sleep mode, but can wake if the Energy Saver option "Wake for network access" is enabled. If you wish to use file sharing or don't want to interrupt your Internet connection, you should not manually put the computer to sleep, and you should drag the "Computer sleep" slider to Never.
    -Jason

  • Did anyone experience drop down in # of user usage in Apple's weekly report after transitioning?

    Hello,
    Did anyone experience drop down in # of user usage in Apple's weekly report after transitioning to the new structure (or design)?
    We transitioned our public iTunes U site on the first week of April.
    Since then, the number in the apple's weekly report showing the user usage of the site dramatically went down.
    I don't think all the RSS feeds and the URL of our podcasts changed due to the transition.

    Greetings;
    The following previous discussion thread might shed some light on your issue.  All the best...
    Syd Rodocker
    Tennessee Department of Education
    http://discussions.apple.com/thread.jspa?messageID=13000515&#13000515

  • ICloud after transition to iOS 7 is disconnected

    After transition to iOS 7 already several times in the iCloud settings all settings are disconnected. Regularity I didn't find. I want to call, I open contacts, and the list is empty. Slightly the heart attack didn't grab. It appeared that in the iCloud settings all points were disconnected. I included - everything was restored. Thus he didn't forget the password.

    not know?????

  • After transition from mobileme to iCloud everything seems working as expected, except from my music that doesn't sync within devices. Any suggestions?

    After transition from mobileme to iCloud everything seems working as expected, except from my music that doesn't sync within devices. Any suggestions?

    Hi pvonk,
    Thanks for the tip...I just logged onto iCloud.com and the folders/mail are correct (compared to my laptop). This tells me the problem is on my phone. So I will try an erase/restore to see what that does!
    thanks,
    N.

  • My Mac book pro shut down after getting a low battery message, and now or won't start at all. It's plugged in now and nothing, no fan, no chime when I hold down the power button

    My Mac book pro shut down after getting a low battery message and now it won't start. Any ideas?

    Hey Citrinesky,
    Thanks for the question. I understand your MacBook Pro is not responding. The following resource may provide a solution:
    Troubleshooting: My computer won't turn on
    http://support.apple.com/kb/TS1367
    Thanks,
    Matt M.

  • My Iphone doesnt turn on after updating. It keeps on blinking the apple logo, even after seeing the low battery image, i tried to charge the iphone. Then I tried to connect to itunes. But itunes cant recognize the device. What should I do?

    My Iphone doesnt turn on after updating. It keeps on blinking the apple logo, after seeing the low battery image, i tried to charge the iphone. After charging for 30 minutes, it still wont turn on but keeps on blinking the apple logo. It has been blinking for 2 days. Then I tried to connect to itunes, but itunes cant recognize the device. What should I do?

    See Here  >  http://support.apple.com/kb/HT1808
    You may need to try this More than Once...  Be sure to Follow ALL the Steps..
    But... if the Device has been Modified... this will Not necessarily work.
    Unauthorized modification of iOS  >  http://support.apple.com/kb/HT3743

  • Webcam not entering low-power mode after resume

    Can other W520 owners with a webcam (and potentially other models) confirm whether or not the camera prevents the USB subsystem from entering low power mode?
    1) Unplug all USB peripherals, and turn off Bluetooth (this runs on USB as well)
    2) Put the system into standby, unplug the AC adapter, and resume the system on battery.
    3) Load a Command Prompt and run powercfg -energy
    4) Load the generated report and look for the following:
    The most noticeable issue caused by this is unnecessarily high power consumption, and as a result, lower battery life.
    Turning the camera on and off (using the Fn=F6 preview window) turns this off and returns power consumption to normal.
    On the latest available BIOS, chipset, and camera drivers.
    Would like someone to confirm whether this is a driver issue or if it's just my system.
    W520: i7-2720QM, Q2000M at 1080/688/1376, 21GB RAM, 500GB + 750GB HDD, FHD screen
    X61T: L7500, 3GB RAM, 500GB HDD, XGA screen, Ultrabase
    Y3P: 5Y70, 8GB RAM, 256GB SSD, QHD+ screen

    I have a very similar spec also. The pair of U2410's (updated revision A01) connected to it won't go into sleep mode (just go black, with backlight still on).
    The pair of cheapie BenQ 2420HD's I had connected while I waited for the Dells went into sleep mode fine.
    Someone on another forum noted that they had a different model Dell on Mac with the same problem, and he found it only happened when the USB uplink cable was connected to the Mac. I disconnected mine (uplink and down), but no change unfortunately.
    Google searching seems to suggest this is almost exclusively only with a Dell/Mac combo (same monitor on PC works fine and other brands on Mac work fine). These U2410 monitors get an absolute bagging on most forums, and I think most of it is deserved. These will both be going back for a refund with severe blue/pink tints making them visually perform worse than the BenQ's that were 1/3 the price. What's the point of spending 2 to 3 times the amount on IPS monitors when they're off colour even right in front of them!
    The HP 24" IPS uses the same crap LG panel as these Dells, I can't justify 2 x 30" Apple Cinema displays for AU$5000, and one just won't cut it. No simple answer it seems....
    Cheers
    Dav

  • Smartphones - Low Battery Mode?

    Just woken up this morning, and my battery's only on 2 bars... which isn't a problem in itself, but it made me think of an idea lol
    Wouldn't it be good if the phone could have an option to automatically switch to a 'Low Battery Mode' which would shut down all the fancy, battery intensive settings - bluetooth, fancy wallpapers & screensavers, active desktop, camera (or the camera switching on if the slide opens - the user must go to camera in the menu to activate
    I'm sure there's a lot more that could be done with that, but I thought I'd throw it open for discussion here and see what people think... I'm sure it would be a valuable tool for people that just want their phone to last longer until they can get home to charge it.
    Obviously if Nokia decide to use my idea after seeing this post, I'd love to take the credit for it :-p
    Nokia History: 3110, 5110, 7110, 7110, 3510i, 6210, 6310i, 5210, 6100, 6610, 7250, 7250i, 6650, 6230, 6230i, 6260, N70, N70, 5300, N95, N95, E71, E72
    Android History: HTC Desire, SE Xperia Arc, HTC Sensation, Sensation XE, One X+, Google Nexus 5

    Thanks richcowell, that sounds like a good idea.
    You'll certainly get credit here on the boards for posting the idea - however, here is an excerpt from the Membership terms:
    License to Nokia for Any Submitted Content
    By submitting, and upon such submission of, any information or materials such as feedback, data, text, software, music, sound, photographs, graphics, video, messages, answers, questions, comments, suggestions, scores, hints, strategies, concepts, designs, ideas, plans, orders, requests or the like, or any other material ("Content") to Nokia or through the Site(s) and Services, for example, by e-mail, SMS, and/or MMS, you license and grant Nokia and its affiliates and sub- licensees a non-exclusive, royalty-free and free of charge, perpetual, worldwide, irrevocable, and fully sub-licensable right to use, reproduce, modify, adapt, communicate to the public, make available, publish, translate, copy, modify, adapt, create derivative works of, distribute, and display such Content or any concept described in it throughout the world in any media, product and/service, including, without limitation wireless devices, mobile phones and any related products, services and accessories, advertising, marketing and promotional materials, and digital reproductions, without compensation, restrictions on use, acknowledgement of source, accountability or liability, and with waiver of all moral rights and rights of attribution, integrity and identity.
    I wrote all my posts from 2005-2011 as an "Admin" for this community. I still work for Nokia as an external consultant, so my rank in all posts is now "Employee".

  • Win10 defeating my system's low power modes

    Both of these devices ran properly in their low-power modes under 8.1x64:
    1) Radeon HD 7850 2GB--For some reason after a boot up, 10-20 minutes later, my GPU jumps from its low-power clocks of 300Mhz/150MHz (core/ram) to full power, and shows 92% GPU activity and appears "stuck" there.  Removing all of the Win10
    updates did not alleviate the problem as I was hoping for.  This is the case regardless of AMD gpu driver used.  But it gets better...
    2) Not only is my GPU stuck on full throttle mode (even when doing nothing or else simply browsing), but my *CPU,* which under 8.1x64 ran fine with AMD's Cool'nQuiet power reduction modes (like Intel's Speed Step), *also* (at the same time) kicks up to *full
    power* although set in Windows to fluctuate between 10% and 100% on a demand basis.
    The only cure that works is to log off and then back on...which corrects the problem for about another 20-30 minutes before both devices go to full power again. Definitely something is strange in the Win10 Preview (which I upgraded from an 8.1 installation
    with none of these problems.)
    Now this may or may not be tied to the problem, but for some really oddball reason Windows10TP will not let me install two innocuous utilities I've used for years: CPU-Z & HWmonitor.  Win10 claims these application are incompatible with it--yet,
    these are only simple hardware identifying programs--and both ran without difficulty under 8.1x64.
    Suggestions appreciated...!

    Mike...Thanks for the reply!  This is a real head-scratcher...;)  I've used the last three drivers from AMD for the gpu--same result every time.  All clocks in the system bios (UEFI) are set to default, and my Win10 install is UEFI (not legacy)
    and the Secure Boot State is ON. All clocks are running at defaults. I also reinstalled the Win10TP updates as I determined they weren't the problem as it continued after I uninstalled them.
    Yes, C'nQ it is enabled in the bios (as I mentioned, all of this stuff worked like a clock under 8.1x64)...and that's the weird thing...Win10TP...operates exactly like it should in relation to the low power modes for around 20-30 minutes--exactly like it
    did in 8.1 all the time--and then for some inexplicable reason both devices jump to full power/full speed--as if something is running that demands the power/speed--but it isn't!
    I've run differing browsers with hardware acceleration turned off; I've run nothing at all apart from normal boot-up running programs, and it makes no difference.  Something is throwing these devices into max-power mode after 20-30 minutes from a boot/log-off/on
    having occurred.
    Motherboard is MSI G46-970a, UEFI version 2.6 (latest)
    CPU is AMD FX-6300 @ stock speeds & voltages
    8GBs DDR 3 running with stock timings and settings (2x4GB)
    HIS HD 7850 2GB running @ stock speeds/voltages
    I've all through the power savings options I'm using and can't find anything that might explain this--I keep going back to the fact that this never happened even once under 8.1, and I started with 8.0 in Jan '13 and have upgraded from there--never happened
    with Win7x64, either (same hardware, same settings.)
    I'm wondering if maybe I ought to be running the Enterprise version of Win10TP, but I can't really think of *why* that would make a difference with these symptoms...
    If you think of anything else, I'm all ears...;)
    Edit: BTW,  I am Migration User 1...;)  I hadn't signed in when I posted the original question--I suppose--although I didn't think I could post without being signed in...

  • Low latency mode: what's the sense?

    I've read it bypasses plug ins which causes latency. But if it is so what'is the sense of this function? If I understand well in this mode I don't know exactly which plug in will work and which no....
    I cannot accept a situation like this.
    Apart from anything else I did use low latency mode (because I listened some latency after having inserted a plug) and I checked all the plugs during playback and they all seem to work. So?
    I don't understand...

    Usually I use Low Latency mode in when mixing-mastering.
    I use UAD DSP plugins on the master... this is cause of many issue... the MAIN problem is that Logic is able to compensate Plugin Audio Latency (PDC)... but not Graphics .. (GPDC is not available... instead Logic 7... Logic 7 have GPDC!!! ... in Logic 8 graphical plugin delay compensation is a missing features)
    the resulting behavior is that All meters show anticipate by the sound...
    but this is not fixable.. or better.. Apple developers must included the Graphic delay compensation in order to get metering in sync with Audio... (I hope in the 8.1 version)
    Anyway.. i love UAD sound and I use them in any case..
    return back to your question, I use Low Latency mode when i need to record some missing details .. without get DSP latency!
    It is a helpful features (not so basical but helpfull).
    Logic Pro 7 is also a great DAW!
    G

  • Xperia Z3 always awake sometimes, even with Stamina, Ultra Stamina, Low Battery modes

    Hi to all,
    Has anyone every noticed his/her Z3 always awake (and thus bad battery life), even from within Ultra Stamina mode with no running apps?
    This happened to me twice now with just over two weeks of using this phone. I haven't been able to take specific steps to replicate this yet, but 2 days in about 16 days means so far over 12% of the days.
    Usually, the phone lasts over 24 hours with moderate use. I normally have stamina mode "on", and set to activate at 50% battery level, and then Low Battery mode to activate at 20%. Note also that all the apps I am using have been installed from the first day I've been using the phone. That is, I have not installed any new apps before I noticed this happening, and when I have "normal" battery life it is using the same set of apps.
    Here is an outline of what happens:
    I notice a much faster than usual power drain, despite being a typical day of usage (i.e. nothing out of the ordinary).
    I go to battery usage, and see the history details, and see that "Awake" has been on constantly, including during long screen off times, and all the while with Stamina mode enabled and active.
    I then restart the phone. Problem still there, still constantly awake despite screen off and stamina.
    Battery dips below 20% and Low Battery mode activates.
    Phone keeps on being constantly "awake", despite no usage and now both low battery AND stamina modes on.
    Restart the phone. Same problem.
    I turn on Ultra Stamina mode. (I did this last time at 17%)
    Phone continues to be always awake. Battery quickly drains down to 5% within less than an hour and almost no use, even though Ultra Stamina is supposed to stretch the life for an order of magnitude longer than that.
    I shut off the phone to avoid complete discharge. When I return home, I plug it in and wait for a decent charge before turning the phone back on.
    After full charge, I take the phone off the charger.
    Phone now works normally again, without always being "awake".
    I can't figure out what causes this sequence of events to kick off in the first place. I'm trying to play around with things to get it to start doing this, but so far I haven't been successful in deliberately replicating the problem.
    Anyone else experience anything like this before?
    My android version is 5.0.2, v. 23.1.A.0.726.

    Perforn a clean update and report back in 3-5 days
    PC Companion (PCC)
    http://support.sonymobile.com/us/tools/pc-companion/
    Bridge (for Mac)
    http://support.sonymobile.com/global-en/tools/bridge-for-mac/
    Alternatives on How to backup Xperias
    http://talk.sonymobile.com/thread/36355
    "I'd rather be hated for who I am, than loved for who I am not." Kurt Cobain (1967-1994)

Maybe you are looking for

  • IPhone 5S manual network selection

    Hi all, I have an unlocked iphone 5S and seem to have an issue with the manual selection mode. I was travelling outside my resident country and switched to manual network selection mode to choose my preferred roaming network in the foreign country. A

  • Classification view

    For Material which i receive from customer i have activated Batch management. I want to give Batch number Externally whenever i receive the material. to identify which material is supplied from which customer. While creating the master data do i have

  • I'm getting annoying pop-ups on Safari; MacKeeper, Free Cam Secrets, Chrome User Survey.

    I've followed (I believe correctly) the directions in The Safe Mac to check the launch files and it always says nothing is found. I've also checked Safari's Extensions. The only thing I've done recently is install Photoshop Elements 10. Other than th

  • OS Update File's Containing Folder Location

    Hello: I want to delete a partial download of Mavericks 10.9.2 OS update (downloaded via Software Update >App Store). Where is this partial file kept ? Thank-you. MLR

  • Server.app "Could not connect to the server."

    I just downloaded and installed Mountain Lion (the day after its release).  It seems fine so far. The next day I decided to install Mac OS X Server, so I dished out $20 and downloaded it from the App Store. "setting up your server is incredibly simpl