Order of port re-auth authentication and switch / stop of the session

Hi all

We are implementing an ISE (1,4) and met regarded questions on the agenda of the authentication and a stop of the session after posture in line. We got mab, dot1x as authentication order (priority of authentication is set to dot1x, mab). We have configured a reauthentication in the ports of the switch. Windows uses begging all-connect NAM (see 4.2) to dot1x and posture. During the re-authentication, either all-connecting NAM or switch does not start an eapol start and switch allows the session to the MAB, where - as when seen dot1x and mab authentication switch order generates eapol start. The switches are 3750 (15.0 (2) SE8).

Any possibility we could force the switch/NAM agent sent an eapol start during re-auth?

Regarding the posture, posture once conform for an endpoint (after dot1x authentication passes) following a judgment of the ISE manual session for an endpoint, switch creates a new session in ISE changes and switch the State of the unknown port to posture. Posture ise AC client still shows status of complaint of posture in the endpoint. It seems do not know about the stop of the session. During NAM endpoint agent session performs a re-auth component however posture remains unchanged "in line".

Does anyone have experience this problem?.

Thanks in advance.

Concerning

GA

Hi Gaj-

I had the similar problem in the past and for setting the following attribute:

Termination-action-AVPair attribute modifier = 1

Give that a go and let us know if you still have any questions.

Thank you for evaluating useful messages!

Tags: Cisco Security

Similar Questions

  • I have an imac 27 "... on power there is no signal to startap, usb ports are not working and its deadlock with the logo of the Apple with the circle of rotation... Help, please

    I have an imac 27 "... on power there is no signal to startap, usb ports are not working and its deadlock with the logo of the Apple with the circle of rotation... Help, please

    Wake the computer to your Apple store or Apple authorized service for the service provider. He probably suffered a hardware failure.

  • Firefox does not load pages and said "Stopped" in the lower left corner of the screen.

    Latest FF and XP Pro. 2.4 Ghz Celeron processor, 1 GB of RAM. FF will work for awhile then it will stop loading pages and say 'Stop' in the lower left corner of the screen. Sometimes I can refresh and the page loads, but 95 out of 100 times I can keep refreshing and it will say "stopped". Alternatively, the page will be partially load and then quit and say 'stop. ' I disabled IPv6 and DNS Prefetching and he always does. IE does the same. VERY frustrated. My last PC started doing this and I've finally upgraded to a newer version and it was fine for a few months, but began to do the same thing recently. Arghhh... Thank you!

    This has happened

    Each time Firefox opened

    is with my last computer a few months ago

    You, me and many others (from discussions throughout the net) have this same problem. I had a few glances at Mozilla, take a look, they couldn't find a problem or a solution.

    Here's what I found works - the problem arises on me when I upgraded to Firefox 3.63. 3.63 FF of uninstall and install 3.59. You can always download until the end of June or July I think.

    My problems went away with 3.59. Seems to only affect users of Windows as Mac Firefox 3.63 works very well.

    Found a few discussions pointing to ZoneAlarm Firewall time-out managers and some download tools. I have ZoneAlarm, so I don't think that was the cause, just another victim.

    I wish Mozilla would pull the plug on 3.63, repackage as 3.64 3.59 and go back to the drawing board until they find out what is wrong.

  • My gradient does not work.  He worked on an image and then stopped on the next!  I have cs6.  It is just the display of the background gray and white checkerboard on the upper left corner.  I click on the arrow down to see if I can it go back to black and

    He worked on an image and then stopped on the next!  I have cs6.  It is just the display of the background gray and white checkerboard on the upper left corner.  I click on the arrow down to see if I can get it back to black and white and it will not change... it will not change if I click on any of them.  I think it might be a bug?  Any ideas will be appreciated.  I tried to reset them as well.  Thank you!!

    Check your Options bar.  You have the opacity set to 10%.  Easy to do.  Just hit the 1 key while the gradient tool is selected, and it's done. By pressing the 0 key will take you back to 100%

  • Smartphones blackBerry automatically roboot and switch off when the loading and unloading...

    my phone gets off power using... and it reboot peremptory I did not able to use the mobile... and also my data is on, but the phone does not connect to the internet. so I couldn't go... my memory of inbuild is also free (137/480) and I already have the micro sd card. Please help me solve this problem...

    Your message is difficult to read and understand. Nevertheless, here are some thoughts and ideas...

    Turn off or restart in use: lack of battery Possible. Possible loss of connection of the battery with the unit because of the movement of battery in the compartment, or dirty or corroded contacts. Possible software or the definition glitch. Failure or damage possible peripheral equipment. Troubleshoot, exclude a possibility at a time, starting with the simple and the less than fresh.

    No BlackBerry data service: no data, or no service book plan. Add line if necessary plan. Do this correctly configured carrier plan. Return service directories.

    Out of memory? Too many applications, too much data. Remove the need to free up needed space.

  • AutoPlay and if stop at the last image does not not on android Tablet

    I'm trying to use folio Builder to make a portfolio for my work and post it on my Nexus 7 Andorid tablet.  The opening page is a video that should stop on the last image.  After reading many articles, it seems that only iOS is able to use these features, and it won't work on android.  Are there workarounds?

    In early February, we will have our new native Viewer available in large pre-release Android, and you will be able to compile a version using this new application that supports the stop on the last image. Until then, no, there is no work around.

    Neil

  • Authentication and authorization JPSUserProvider at the University Complutense of MADRID 11g

    Hello

    Can someone direct me on where I can find more information on JPSUserProvider. Documentation of the Complutense University of MADRID just mentions that JPSUserProvider is configured in the UCM by default and used for authentication, the authorization. In another document that it is mentioned that UCM 11 g has nothing to do with the authentication of the user, all the authentication will be supported by Weblogic and SSO must be configured against weblogic. If SSO is configured and an external LDAP is used as a user store in weblogic, I need to make changes to the AAU? I want to know the role JSPUserProvider plays in the University Complutense of MADRID and the series of events that take place after the user enters the credentials to < Server >: < port > / cs/login/login.htm.
    Any help in pointing the right resources is appreciated.

    Thank you
    Shyam

    Sometimes, you don't have no need to make changes, but other times, you may need to update the map attribute, the delimiter of account permissions, default roles and/or accounts. Occasionally, an ID card is applied to translate incoming AD group names to match the role names and/or account UCM.

    Meet real external LDAP permissions is made via the WLS, but the JPSProvider does the work of extracting data from WLS in object UserData of the AAU.

    -ryan

  • Procedure for starting and long stop on the Satellite P200 - 10 c

    I have a Satellite P200 - 10 c and I bought this laptop with pre-installed Vista Home Premium.
    Everything works fine, but it takes a long time for the computer to boot. Same thing with shut down and restart.
    Is this normal?

    * amaster *, it has nothing to do with the laptop - that's Vista. You would be to optimize your system.
    1. disable UAC (run msconfig on Tools choose disable UAP, where getting the message "Command completed successfully" - restart)
    2. turn off some visual effects: go to control panel / system / advanced system settings / Advanced tab / Performance settings / Visual effects (default tab) and disable the following list:
    Animate controls and elements inside windows
    Menu fade or slide into view
    ToolTip fade or slide into view
    Fading of items after clicking
    Show shadows under menus
    Show shadows under mouse pointer
    Show translucent selection rectangle
    Drag the open drop-down list boxes
    Drag the task bar buttons
    3. optimize virtual memory: first remove the existing file - control panel/system/advanced system settings/advanced/performance-settings/advanced/Virtual Memory-change... mark "No. Paging File." Reset. Then create the new paging file - Control Panel/System/advanced system settings/advanced/performance-settings/advanced/Virtual Memory-change... do fixed Page File with size equal to: amount of physical memory (RAM) + 1 GB. If you have two hard drives - best create the pagefile on no system disk. The min and max sizes of pagefile should be equal - not different.
    4 turn off System Restore. (Start / computer/properties/Advanced Settings/System Protection.) If UAC will ask you confirmation - allow)
    5. turn off the Hibernation (start programs/guest/in the context menu, choose "Run as Administrator" and in the command line write * powercfg OFF h *)
    6. cut unused services (do not turn it off completely - do, then manually run)
    7 edit the registry:
    [HKEY_CURRENT_USER\Control Panel\Desktop]
    MenuShowDelay = 0 (default 400)
    AutoEndTasks = 1
    HungAppTimeout = 1000
    WaitToKillAppTimeout = 1000
    LowLevelHooksTimeout = 1000

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro L]
    In all three destinations: WaitToKillServiceTimeout and make 5000 (default 20000)

    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\PriorityControl]
    Win32PrioritySeparation = 6 (default value 2)

    And so on and so forth... Actually-, it is a never-ending story...

  • Black screen and OS stops since the upgrade to VISTA SP2

    • I'm having a problem with my Vista operating system since I've upgraded to SP2
    • The problem is that the operating system stops often enough
    • I 'from the end-user point of view"tried to test," under what conditions it stop? And after trying different scenarios, I realized that it stops when it goes into sleep mode. And that's why I got black screen mainly. However if I change my screensaver, then he won't show me the black screen but still it stops.
    • Can you guys suggest me a solution?

    The problem persists if uninstall you SP2?

    How to uninstall Windows Vista service packs as a troubleshooting step
    http://support.Microsoft.com/kb/948537

    You did it that everything has been updated (drivers, etc) before installing SP2?
    Learn how to install Windows Vista Service Pack 2 (SP2)
    http://windowshelp.Microsoft.com/Windows/en-GB/help/105f7420-6f7f-4FE8-8698-2f40ca5f53711033.mspx TaurArian [MVP] 2005-2010 - Update Services

  • Remove both log and buttons stop of the start menu

    Hello

    I am creating a PC which should always be left on running a SCADA program. So I want to disable both the journal off and stop buttons. So far, I was through registry changes and disabled two buttons. I am now at the stage where they are all disabled however Log Off poster still in the start menu.
    Could someone let me know if it is possible for all the two be disabled? If yes how can I to do?
    Thanks in advance.

    Chris

    Hi Chris,

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    http://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w7itpro

    Hope this information helps.

  • Windows media player and youtube stops playing the music in a game full screen

    When I play music on my windows media player, I reduce it then go to another program which is a game LoL which is a game fullscreen. This also happens with youtube.

    Hello

    1. what game are you talking about?
    2. when the problem started?
    3. have you done any software or hardware changes to your computer recently?

    Please provide us with more information about the issue so that we can better guide you.

    I suggest you check the following settings.

    a. click Start, click Control Panel, and then double-click sounds.

    b. in the sound dialog box, click on the playback tab, click the speaker device and then click Properties.

    c. click on the Advanced tab, clear the checkbox "allow applications to take exclusive instrument control" and then click OK.

    d. also uncheck the option "give exclusive mode applications priority'.

    Check if it helps.

  • Service starts and then stops during the SRM 5.1.1 install


    My configuration is:

    • 5.1 ESXi
    • vCenter 5.1 has running on a virtual machine
    • Execution of SQL 2008R2 sparer vCenter VM
    • Separate the VM for the execution of SRM
    • Above config is replicated to the site of DR
    • vCentres are not in Linked mode
    • SSO separate databases for each site

    When I installed SRM, it was wrong at the end and then gave the service could start message.  Finally, after clicking try again several times, the installation is complete.  However, the SRM service has stopped.

    The service can be started, but it stops immediately without errors in the logs of Windows.  The only hint of information that may be useful is in the SRM Setup log:

    VMware: Srm::Installation:Utility:LaunchApplication: INFORMATION: executable completed. Result code = 1

    VMware: Srm::Installation:VMUnregisterSrmService: ERROR: LaunchApplication() failed. Executable = D:\Program Files\VMware\VMware vCenter Site Recovery Manager\bin\vmware-dr.exe, parameters = u 'D:\Program VMware vCenter Site Recovery Manager\config\vmware-dr.xml', Code = 1

    VMware: Srm::Installation:Utility:LaunchApplication: INFORMATION: launch executable. Command line = 'D:\Program VMware vCenter Site Recovery Manager\bin\vmware-dr.exe' - r 'D:\Program VMware vCenter Site Recovery Manager\config\vmware-dr.xml.

    VMware: Srm::Installation:Utility:LaunchApplication: INFORMATION: waiting for the child process to complete

    VMware: Srm::Installation: 'anonymous namespace': ReadFileCompleted: INFORMATION: asynchronous callback status: 109

    VMware: Srm::Installation: 'anonymous namespace': ReadFileCompleted: INFORMATION: asynchronous callback status: 109

    VMware: Srm::Installation:Utility:LaunchApplication: INFORMATION: child process stdout:

    I tried to get the result code = 1 but without success.  Certain sections of the KB speak the DSN system, but it is 32 bit and the connection test is successful.

    I have the same problem in both the DC SRM and DR DC SRM Production.

    Any ideas gratefully received!

    Hello

    You must create the 64-bit DSN for the SRM 5.1.

    Michael.

  • Secure ACS Authentication and Authorization with SecurID

    I am able to authenticate connection attempts using an external database (RSA SecurID).  The problem is that everyone with a token is authorized to connect on any switch with priv15 or whatever I put (but no way to control who gets what access).  How can I allow users based on a certain type of belonging to a group?  The SecurID server is already integrated with LDAP, it only checks to see if the user exists in the database.

    I need to create two groups, or even only allow a single group and deny everyone, but anyone in the organization with a token is allowed to connect.  I can't find guides who do anything beyond authentication when you use a SecurID token.

    Thank you.

    Hello

    Have routers and switches, you given the command "authorization exec default group aaa GANYMEDE", it seems that you have only defined authentication on devices. When the control is in place, user access privileges may be governed by the ACS. In network administrator access by default policy (if you are using the default strategy for GANYMEDE), to set the authorization rule to verify membership in a user group and provide the appropriate profile of shell. Make the default rule to give DenyAccess shell profile to other users.

  • Computer stops when the wireless switch is turned on

    I have a Toshiba Satellite M-35 S456 with Windows XP Home Edition.  When I turn on the switch on the bottom of my laptop wireless, the screen flashes blue with a message and then stops.  The computer tries to restart, but during the process of the blue screen flashes again and it stops.  If I switch the switch wireless to the computer will restart.  I am trying to connect to the internet via a router which is already set up and running.  All solutions?

    Hi MartinLaMarr,

    ·         What is the Blue error screen that you are talking about?

    ·         If so, have you noticed the blue screen error message?

    Check to see if the following is useful.

    Method 1: Unplug non-essential devices from the computer and restart the computer.

    Method 2: Try to select disable automatic system failure reboot since the options of start menu advanced to know the Blue error screen.

    a. restart your computer and start pressing F8 on your keyboard. On a computer that is configured to start to multiple operating systems, you can press the F8 key when the Boot Menu appears.

    b. use the arrows to choose to turn off the automatic restart in the event of system failure in the Advanced Options of Windows Start Menu and press ENTER.

    Method 3: Updated with the latest wireless drivers and other drivers of devices from the portable computer. Log in the Web of Toshiba site to do.

    Content Page Model - Toshiba Satellite M-35 S456

  • HTTP Session with module GemFire-CS does not work if the session stickiness is not enabled and with spring security

    Hi I have a configured tcServer 2 (Server4, Server5 jvmRoute names) with module gemfire http session, listening to the same gemfire Locator service both with the same name in the region - gemfire_modules_sessions and region attribute id

    I also configured vFabric Web server with Http balancer as a front-end for the HTTP request without activating the rigidity of the session as shown below: I couldn't realize the no session affinity

    <Proxy balancer://tpa-balancer>
         BalancerMember http://localhost:8087 route=Server4 loadfactor=1
         BalancerMember http://localhost:8088 route=Server5 loadfactor=1
         ProxySet lbmethod=bybusyness scolonpathdelim=On
    </Proxy>
    ProxyPass /insurance balancer://tpa-balancer/insurance
    ProxyPassReverse /insurance http://localhost:8087/insurance
    ProxyPassReverse /insurance http://localhost:8088/insurance
    
    

    and I'm using spring security 3.0 for authentication and the flow of the web page is as shown below:

    page connection - "login.htm" and once submitted, it uses ' / j_spring_security_check ' and after successful authentication app redirects to ' / http://www.sigling.is/IMO/imofishing/home.htm '.

    Initially when hits 'login.htm' and anonymousUser user logon is id: 6B21CB15838B2AC1E46F66C0CC7272BE. Server5 and when the form is sent to /j_spring_security_check that the same session id is used and after authentication httpsessionsecuritycontextrepository stores SecurityContext in HttpSession as shown below:

    [09/12/2012-02:00:14][DEBUG][HttpSessionSecurityContextRepository]SecurityContext stored to HttpSession: 
    'org.springframework.security.core.context.SecurityContextImpl@b70b1ef5: 
    Authentication: org.springframework.security.authentication.UsernamePasswordAuthenticationToken@b70b1ef5: 
    Principal: com.csc.ace.insurance.security.vo.UserProfile@e26fa325: Username: [email protected]; P
    assword: [PROTECTED]; Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: 
    true; 
    Granted Authorities: ADMINISTRATOR,CREATE_CUSTOMER,CREATE_USER_ACCT,DELETE_CUSTOMER,DELETE_USER_ACCT,
    MODIFY_CUSTOMER, MODIFY_USER_ACCT,VIEW_CLAIMS,VIEW_CUSTOMER,VIEW_PAYMENTS,VIEW_POLICIES; 
    Credentials: [PROTECTED]; 
    Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@255f8: 
    RemoteIpAddress: 127.0.0.1; SessionId: 6B21CB15838B2AC1E46F66C0CC7272BE.Server5; 
    Granted Authorities: ADMINISTRATOR, CREATE_CUSTOMER, CREATE_USER_ACCT, DELETE_CUSTOMER, DELETE_USER_ACCT, 
    MODIFY_CUSTOMER, MODIFY_USER_ACCT, VIEW_CLAIMS, VIEW_CUSTOMER, VIEW_PAYMENTS, VIEW_POLICIES'
    

    and when the redirect to http://www.sigling.is/IMO/imofishing/home.htm, it shows HttpSessionSecurityContextRepository: HttpSession returned null for SPRING_SECURITY_CONTEXT object

    com.gemstone.gemfire.modules.session.catalina.DeltaSessionFacade creates a new session with the session id: 6B21CB15838B2AC1E46F66C0CC7272BE. Server4, ideally redirect to the home page go to another server. I have attached the full log file

    I believed that session affinity is not needed when the GemFire Session module is used without local cache and I could see B21CB15838B2AC1E46F66C0CC7272BE. Server5 entry is created in the gemfire_modules_sessions region.

    So why is - this HttpSessionSecurityContextRepository could not get the gemfire session the region object using the id: 6B21CB15838B2AC1E46F66C0CC7272BE. Server5 and directs gemfire DeltaSessionFacade to create a new session

    [09/12/2012-02:00:14][DEBUG][FilterChainProxy]Converted URL to lowercase, from: '/home.htm'; to: '/home.htm'
    [09/12/2012-02:00:14][DEBUG][FilterChainProxy]Candidate is: '/home.htm'; pattern is /**; matched=true
    [09/12/2012-02:00:14][DEBUG][FilterChainProxy]/home.htm at position 1 of 7 in additional filter chain; 
    firing Filter: 'SecurityContextPersistenceFilter'
    [09/12/2012-02:00:14][DEBUG][HttpSessionSecurityContextRepository]No SecurityContext was available from the 
    HttpSession: com.gemstone.gemfire.modules.session.catalina.DeltaSessionFacade@5cca548b. 
    A new one will be created.
    [09/12/2012-02:00:14][DEBUG][FilterChainProxy]/home.htm at position 2 of 7 in additional filter chain; 
    firing Filter: 'UsernamePasswordAuthenticationFilter'
    [09/12/2012-02:00:14][DEBUG][FilterChainProxy]/home.htm at position 3 of 7 in additional filter chain; 
    firing Filter: 'AnonymousAuthenticationFilter'
    [09/12/2012-02:00:14][DEBUG][AnonymousAuthenticationFilter]
    Populated SecurityContextHolder with anonymous token: 
    'org.springframework.security.authentication.AnonymousAuthenticationToken@9054b1a2: 
    Principal: anonymousUser; Credentials: [PROTECTED]; Authenticated: true; 
    Details: org.springframework.security.web.authentication.WebAuthenticationDetails@1c07a: 
    RemoteIpAddress: 127.0.0.1; SessionId: 6B21CB15838B2AC1E46F66C0CC7272BE.Server4; 
    Granted Authorities: ROLE_ANONYMOUS'
    

    Thanks for the additional info.

    Although, in theory, by using sessions not may work for some applications, you will have less sessions unexpected behavior. Any page you visit will result in 10 seconds of additional applications, go to the server. If they are not sticky and bounce between servers, the session will constantly be failed back between the servers. A 'problem' with modern browsers is that they appear simultaneous requests, so you can have the same session failover, at the same time on different servers, that wouldn't be good.

    I'd be curious to know why you choose to have sessions in the first place.

    Nevertheless, it still seems like there is a problem when you have enabled, sessions, so I'll continue to watch it.

    -Jens

Maybe you are looking for