802.1X TEAP Authentication with Cisco ISE Troubleshooting

Mike Moss 5 Reputation points
2024-03-02T04:12:31.0533333+00:00

I am in the process of deploying wired network authentication using 802.1X. The tools in use are:

  • RADIUS Server: Cisco ISE
  • Supplicant: Windows 11 Native Supplicant
  • Protocols: TEAP / EAP-TLS with EAP-Chaining.
  • MS Intune

I have created a network profile and exported and put it into MS Intune and begin testing. Testing for the most part went well. Few minor things to fix, but overall was good. I started with a small group of 5 people, then slowly expanded the testing from 5 > 20 > 50 users. All had no issues. So i began phased rollouts. Did 100 people, then a few days later, 100 more. I have almost 300 users now fully on 802.1X. Just recently problems started to arise. About 15 or so users are failing 802.1X authentication and rolling over to MAB. < This is not good. All these endpoints are the same. Same hardware, same AD OU's/Groups, Same 802.1X settings, etc. They all have the proper machine and user certificates + Root CA. (Cert chain is good).

It seems these end points stop responding to ISE/ EAP authentication requests. I have a Cisco TAC support case open as well. But i think the issue is with Windows so i dont think Cisco is going to be able to help much.

Has anyone else deployed this config and know how to troubleshoot it? I've looked at the EAP logs, Wired AutoConfig logs, etc - no help there.

Any help is appreciated.

Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
779 questions
{count} vote

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.