<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC Reauthentication Failure vs Cisco WLC: End_System_move in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-reauthentication-failure-vs-cisco-wlc-end-system-move/m-p/29808#M406</link>
    <description>Hi ,&lt;BR /&gt;
&lt;BR /&gt;
we have to check this issue step by step.&lt;BR /&gt;
&lt;BR /&gt;
Please check below article and let me know if it works.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-common-tcpdump-commands-used-for-isolating-issue" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-common-tcpdump-co...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Open a GTAC case if you still have the same issue.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;
Suresh.B&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 16 Aug 2016 12:06:00 GMT</pubDate>
    <dc:creator>Bharathiraja__S</dc:creator>
    <dc:date>2016-08-16T12:06:00Z</dc:date>
    <item>
      <title>NAC Reauthentication Failure vs Cisco WLC: End_System_move</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-reauthentication-failure-vs-cisco-wlc-end-system-move/m-p/29807#M405</link>
      <description>Hi,&lt;BR /&gt;
four Cisco WirelessLanControllers Type 4404 are using two of our NACs as RADIUS Server. Switch settings in appliance group are as follows:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Switch type: layer 2 Radius only 
&lt;/LI&gt;&lt;LI&gt;Auth Access Type: Manual RADIUS Configuration 
&lt;/LI&gt;&lt;LI&gt;Gateway RADIUS Attributes to send: none 
&lt;/LI&gt;&lt;LI&gt;RADIUS Accounting: Disabled 
&lt;/LI&gt;&lt;/UL&gt;NAC determines Clients IP by DHCP packets which we redirect to NAC. When a client gets another IP address than he had before, NAC seems to trigger a reauthentication because of that address change. This reauthentication fails:&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;DEBUG [ReauthTask] ESDMAC:71-5F-62,ESDIP:141.45.214.55 The re-authentication request is being processed because the reauth reason: "END_SYSTEM_MOVE" is not for a data change.&lt;BR /&gt;
DEBUG [ReauthTask] ESDMAC:71-5F-62,ESDIP:141.45.214.55 Re-authentication running for Switch: 192.168.2.6, Port : 29, Port Name : null, Port Alias: null, MAC: D0-33-11-71-5F-62, Reason: END_SYSTEM_MOVE&lt;BR /&gt;
INFO [ReauthSnmpTask] ESDMAC:71-5F-62 Executing Reauth for MAC: D0-33-11-71-5F-62, IP: x.y.214.55 for NAS switch 192.168.2.6 switchPort 29 reason: END_SYSTEM_MOVE all sessions&lt;BR /&gt;
DEBUG [ReauthSnmpTask] ESDMAC:71-5F-62 Not using toggle link for session: AUTH_8021X =&amp;gt; Rejected: false shouldToggleLinkForRejectedEapTlsOnReauth: true ID: 1056617341&lt;BR /&gt;
INFO [ToggleLinkReauthenticationSnmpWorker] ESDMAC:71-5F-62 Starting ToggleLink Reauthentication for: D0-33-11-71-5F-62 on port: 29&lt;BR /&gt;
INFO [ToggleLinkReauthenticationSnmpWorker] ESDMAC:71-5F-62 Reauthenticating using Toggle Link for port: 29&lt;BR /&gt;
DEBUG [ToggleLinkReauthenticationSnmpWorker] ESDMAC:71-5F-62 using ToggleLinkSnmpWorker: IfAdminStatusToggleLinkSnmpWorker&lt;BR /&gt;
DEBUG [ToggleLinkReauthenticationSnmpWorker] ESDMAC:71-5F-62 The toggle link worker said that we should not toggle the port, skipping...&lt;BR /&gt;
DEBUG [ToggleLinkReauthenticationSnmpWorker] ESDMAC:71-5F-62 Reauthentication was: *NOT* successful&lt;BR /&gt;
DEBUG [ReauthTask] ESDMAC:71-5F-62,ESDIP:141.45.214.55 Re-authentication failed. Switch: 192.168.2.6, Port : 29, Port Name : null, Port Alias: null, MAC: D0-33-11-71-5F-62, Reason: END_SYSTEM_MOVE&lt;/BLOCKQUOTE&gt;Can I disable reauthentication when a client moves from one IP to another? It seems unneccessary since NAC was already asked for authentication some milliseconds before otherwise the wireless client couldnt have connected to the Cisco WLC.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 01 Aug 2016 14:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-reauthentication-failure-vs-cisco-wlc-end-system-move/m-p/29807#M405</guid>
      <dc:creator>htw</dc:creator>
      <dc:date>2016-08-01T14:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Reauthentication Failure vs Cisco WLC: End_System_move</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-reauthentication-failure-vs-cisco-wlc-end-system-move/m-p/29808#M406</link>
      <description>Hi ,&lt;BR /&gt;
&lt;BR /&gt;
we have to check this issue step by step.&lt;BR /&gt;
&lt;BR /&gt;
Please check below article and let me know if it works.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-common-tcpdump-commands-used-for-isolating-issue" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-common-tcpdump-co...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Open a GTAC case if you still have the same issue.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;
Suresh.B&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Aug 2016 12:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-reauthentication-failure-vs-cisco-wlc-end-system-move/m-p/29808#M406</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2016-08-16T12:06:00Z</dc:date>
    </item>
  </channel>
</rss>

