How to troubleshoot ise failed authentications & authorizations
Содержание:
SPAN
One of the most useful tools for debugging 802.1X failures on the authenticator is the Switched Port Analyzer (SPAN). SPAN allows you to mirror all the EAP traffic sent and received on one port to a different port where it can be analyzed by a sniffer. By sniffing the actual EAP packets that are exchanged between the authenticator and the client, you can diagnose some failures that are not visible from the Cisco ISE.
To configure a Cisco Catalyst 3000 Series Switch to mirror all the traffic from one port (the source port) to another (the destination port), use the following Cisco IOS commands in configuration mode:
(config)# monitor session 1 source interface Gigabit 0/1(config)# monitor session 1 destination interface Gigabit 0/2 encapsulation replicate
To configure a Cisco Catalyst 4500 Series Switch to mirror all the traffic from one port (the source port) to another (the destination port), use the following Cisco IOS commands in configuration mode:
(config)# monitor session 1 source interface Gigabit 1/1(config)# monitor session 1 destination interface Gigabit 1/2
No special configuration options are required to use SPAN on Layer 2 frames on the Cisco Catalyst 4500 Series switch, since the Cisco Catalyst 4500 monitors all Layer 2 frames with the default SPAN configuration shown above.
Detailed Report
ISE can show authentication details showing a successful authentication of a machine using EAP-TLS.
The Authentication Summary shows the information that was available when viewed in the RADIUS Live Logs page:

The Related Events come from the syslog for the NAD that is relevant to this session. This is automatically correlated and included in the detailed report when the NAD sends the event to ISE MnT node.

To configure the switch to send the syslog to ISE, enter the following:
(config)# logging host {Primary_MnT} transport udp port 20514(config)# logging host {Backup_MnT} transport udp port 20514
In the figure below, the Authentication Details section shows other information produced during authentication:

The Steps section shows the detailed process that the session went through within ISE:

Validate the WLC or Switch Configuration
- Check that the Cisco Wireless LAN Controller (WLC) configuration or the switch OS platform and/or version is supported by the TrustSec version you are implementing.
- For the NAD to be able to authorize, it needs to have following entry in the configuration:
aaa authorization network radius
- For the dynamic VLAN (dVLAN), run the following from exec mode to check that the WLC or the switch VLAN database includes the VLAN that the ISE is trying to assign:
show vlan
- For dACL, validate that the ISE ACL syntax is correct by going to Policy > Policy Elements > Results > Authorization > Downloadable ACLs.
- For Catalyst switches, you can verify the configuration using the ISE Evaluate Configuration Validator tool. Go to Operations > Troubleshoot > Diagnostic Tools > General Tools :
12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate
| Applies to | EAP-TLS (AnyConnect Network Access Manager) |
|---|---|
| Possible Causes | The supplicant does not trust the ISE PSN certificate. |
| Resolution | Check whether the proper server certificate is installed and configured for EAP by going to the Local Certificates page(Administration > System > Certificates > Local Certificates ). Also ensure that the certificate authority that signed this server certificate is correctly installed in client’s supplicant. Check the previous steps in the log for this EAP-TLS conversation for a message indicating why the handshake failed. Check OpenSSLErrorMessage and OpenSSLErrorStack for more information. |
Communication with ISE PSN
There are three common reasons why the switch does not or cannot send RADIUS messages to the AAA server when a client attempts to authenticate:
- Lack of proper network connectivity
- RADIUS configuration on the switch
- Lack of response from the client
To verify network connectivity, ping the AAA server from the switch. Here is an example ping command:
Switch#Switch#ping 192.168.1.60Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 192.168.1.60, timeout is 2 seconds:!!!!!Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 msSwitch#
If the ping is not successful, or some packets are dropped, use standard routing and switching debugging techniques to establish reliable connectivity between the switch and the AAA server.
If the ISE PSN is pingable, it can useful to use the test aaa diagnostic command in this situation. The following example illustrates this command:
Switch#test aaa group radius testuser cisco123 new-codeUser successfully authenticatedSwitch#
The test aaa command causes the switch to send an Access Request to the AAA server for a PAP (clear-text) authentication for (in this example) the user testuser with password cisco123. The switch will attempt to authenticate to the server configured in the radius-server host command. Optionally, if you are using AAA groups instead of the default RADIUS group, you can specify a specific RADIUS group to test a specific server configured as part of the group.
If the result of the test aaa command is User successfully authenticated, as shown in the preceding code snippet, it means that three things are true: the switch is properly configured to communicate with the AAA server (correct shared key); the switch has network connectivity to the AAA server; and the username and password specified in the test command are valid. The ISE Live Authentication event will show this authentication:
Switch#test aaa group radius testuser cisco123 new-codeUser rejectedSwitch#
If the result of the test aaa command is User authentication request was rejected by server, you know that the switch configuration is working and network connectivity is validated, but the username and/or password provided in the test command are not valid. This failed authentication will show up in the ISE Live Authentication event. Another possibility is that the switch is not able to authenticate to the AAA server. Either the shared key does not match or there is no network connectivity to the AAA server. This could be the reason that the AAA server receives no RADIUS messages. Revalidating the configuration and/or verifying network connectivity will allow the switch to communicate with the AAA server during 802.1X authentications.
Переводы пользователей
Добавлены профессиональными переводчиками и компаниями и на основе веб-страниц и открытых баз переводов.
Ошибка доступа к серверу
Идентификация пользователя не выполнена.
Невозможно идентифицировать пользователя. special command completed
Authentication has failed.
VNC authentication failed.
Ошибка аутентификации в VNC.
Proxy Authentication Failed.
Ошибка идентификации на прокси- сервере.
Authentication to %1 failed
УкажиÑе паÑÐ¾Ð»Ñ Ð´Ð»Ñ Ð²Ð°Ñего лиÑного клÑÑа SSH.
попробуйте еще раз
Получите качественный перевод благодаря усилиям 4,401,923,520 пользователей
Сейчас пользователи ищут:
MyMemory — крупнейшая в мире память переводов. Она была создана на основе систем памяти переводов Европейского Союза, Организации Объединенных Наций и ведущих специализированных многоязычных сайтов из разных отраслей.
Мы относимся к Translated, так что, если вам нужны услуги профессионального перевода, посетите наш основной сайт.
Работать через FTP удобно и быстро. Этот протокол используют для обмена данными, файлами и папками. Особенно популярен этот стандарт среди вебмастеров, которые используют клиенты FTP для загрузки файлов на сервер. Но иногда случается так, что не удается подключиться к FTP-серверу на разных клиентах. В данной статье будет рассмотрена ошибка 530 login authentication failed, которая однажды может появится и у вашего клиента FileZilla при попытки войти на хост.
Reports
If the event happened more than 24 hours ago, it’s a historical event can be viewed by going to Operations Reports Catalog AAA Protocol RADIUS Authentication.
Configuration Validator
You can use the diagnostic tool to evaluate the configuration of a network device and identify any configuration problems. The Expert Troubleshooter compares the configuration of the device with the standard configuration. This shows the Evaluate Configuration Validator options:

- Go to Operations > Troubleshoot > Diagnostic Tools > Evaluate Configuration Validator.
- Enter the Network Device IP address of the device whose configuration you want to evaluate, and specify other options as necessary.
- Select configuration options to compare against the recommended template. A green check mark means the option is selected. Click the option again to deselect. Choose from the following:
- Web Authentication—Select this check box to compare the Web Authentication configuration for the device with the standard configuration.
- Profiler Configuration—Select this check box to compare the Profiler configuration for the device with the standard configuration.
- CTS—Select this check box if you want to compare Security Group Access configuration for the device with the standard configuration.
- 802.1X—Select this check box if you want to compare the 802.1X configuration for the device with the standard configuration. Then choose one of the following options:
- Open Authentication Mode
- Low-Impact Mode (Open Mode + ACL)
- High Security Mode (Closed Mode)
- Click Run. The Progress Details page appears, prompting you for additional input.
- Click User Input Required, and modify the fields as necessary. A new window appears, prompting you to select the interfaces for the configuration analysis.
- Check the check boxes next to the interfaces that you want to analyze, and click Submit. The Progress Details page is displayed again.
- Click Show Results Summary.
TCP Dump
The TCP Dump utility monitors the contents of packets on a network interface that match a given Boolean expression. You can use this utility to troubleshoot problems on your network. Cisco ISE troubleshooting diagnostic tools provide an intuitive user interface.
- Go to Operations > Troubleshoot > Diagnostic Tools > TCP Dump.
- Select a Network Interface to monitor from the drop-down menu. This is the interface upon which the network traffic is monitored, or sniffed.
- Set Promiscuous Mode to On or Off by clicking the radio button. The default is On.
- Promiscuous Mode is the default packet sniffing mode. It is recommended that you leave it set to On. In this mode, the network interface is passing all traffic to the system’s CPU.
- In the Filter field, enter a Boolean expression on which to filter. Standard TCP Dump filter expressions are supported, such as the following: host 10.0.2.1 and port 1812
- Click Start to begin monitoring the network.
- Click Stop when you have collected a sufficient amount of data, or wait for the process to conclude automatically after accumulating the maximum number of packets (500,000).
TrustSec authentications can fail for many reasons. These include an unknown user, bad credentials, expired credentials, missing certificates, misconfiguration, and so on. Many of these failures can be diagnosed using careful examination of the ISE logs. Common failures and their symptoms are explained below.
Check for Any Failed Authentication Attempts in the Log

- If the MAC address or username is known, use filters to view the events only from the specific endpoint.Note: Even for 802.1X authentications, it is helpful to filter with MAC address instead because: depending on where in the process the failure occurred, the endpoint user or computer name may not be known to ISE.
- The RADIUS Live Logs shows events up to past 24 hours, so make sure to look at the latest events.
- Successful events have status of with green background. A failed event will have with red background to clearly identify the status.
- Note the network device and device port before proceeding.
22056 Subject not found in the applicable identity store(s)
| Applies to | EAP-FAST, PEAP-MSCHAPv2, MAB |
|---|---|
| Possible Causes | User or device was not found in the configured identity store |
| Resolution |
Check whether the subject is present in any one of the chosen identity stores. Note that some identity stores may have been skipped if they do not support the current authentication protocol. Make sure the authentication policy points to correct identity store. For authentication in a Microsoft Windows network with multiple domains, make sure that the supplicant is appending the domain suffix (For users: administrator@example.com, for machines: winxp.example.com). |
Useful Cisco IOS show Commands
One of the most useful show commands on the Cisco Catalyst switch is show authentication sessions interface. The command output shows the current authentication status of the specified port. Other useful commands include show dot1x interface and show running-config interface.
Switch# show authentication sessions interface fastEthernet 0/1 Interface: FastEthernet0/1 MAC Address: 0016.d42e.e8ba IP Address: 192.168.1.78 User-Name: winxp.example.com Status: Authz Success Domain: DATA Security Policy: Should Secure Security Status: Unsecure Oper host mode: multi-domain Oper control dir: both Authorized By: Authentication Server Vlan Policy: 100 Session timeout: N/A Idle timeout: N/A Common Session ID: C0A8013C000006679C3F253D Acct Session ID: 0x00000C51 Handle: 0x68000667Runnable methods list: Method State dot1x Authc Success mab Not runSwitch#Switch#Switch#show dot1x interface fastEthernet 0/1Dot1x Info for FastEthernet0/1-----------------------------------PAE = AUTHENTICATORPortControl = AUTOControlDirection = BothHostMode = MULTI_DOMAINQuietPeriod = 60ServerTimeout = 0SuppTimeout = 30ReAuthMax = 2MaxReq = 2TxPeriod = 10Switch#Switch#Switch#show running-config interface fastEthernet 0/1Building configuration...Current configuration : 599 bytes!interface FastEthernet0/1description 802.1x Enabledswitchport access vlan 2switchport mode accessswitchport voice vlan 110authentication event fail action next-methodauthentication event no-response action authorize vlan 100authentication event server alive action reinitializeauthentication host-mode multi-domainauthentication port-control autoauthentication periodicauthentication timer reauthenticate serverauthentication timer inactivity serverauthentication violation restrictmabdot1x pae authenticatordot1x timeout tx-period 10spanning-tree portfastendSwitch#
Как исправить «Authentication token manipulation error»
1. Права доступа
Ошибка в работе утилиты может возникнуть, если установлены неправильные полномочия на файл /etc/shadow, в котором хранятся пароли. Смотрим текущие полномочия командой:

У вас чтение и запись должны быть выставлены как на снимке, если это не так, выполните такую команду:
2. Файловая система только для чтения
Если вы загрузились в режиме восстановления Ubuntu или подобном режиме другого дистрибутива, то по умолчанию файловая система будет находиться в режиме только для чтения, соответственно утилита не сможет ничего записать. Чтобы перемонтировать её для записи, используйте:

3. Модули аутентификации
Ещё одной причиной может быть неправильная настройка модулей аутентификации, из-за которой утилита не может сохранить пароль. Доступные модули можно посмотреть командой:

Запустить обновление настроек модулей можно, выполнив от имени суперпользователя:
На первом шаге надо нажать Ok:

Затем выбрать с помощью пробела и стрелок нужные модули, переключиться с помощью Tab на Ok и сохранить.

4. Свободное место на диске
Естественно, утилита не сможет изменить пароль, если на диске не будет свободного места. Убедитесь, что есть, как минимум, несколько сотен свободных мегабайт на корневом разделе. Это можно сделать с помощью команды:

А посмотреть, какие файлы занимают больше всего места, и удалить ненужное можно с помощью ncdu:

Если утилита не установлена, то её можно установить с помощью пакетного менеджера. Название пакета такое же как и у команды:
5. Ошибки файловой системы
Если файловая система была повреждена, то это тоже может стать причиной проблем с изменением пароля. Для проверки и восстановления файловой системы можно использоваться fsck. Но для работы утилиты файловая система должна быть отмонтирована.

Здесь вместо /dev/sda3 необходимо указать адрес вашего раздела жёсткого диска.
6. Другие решения
Ещё многие советуют перезагрузить систему, возможно, это поможет:
Также можно не изменять пароль, а сначала удалить старый такой командой:
А затем установить новый:
Удаление данных из Google Play Store
Чтобы удалить данные из Google Play Store, вам понадобится зайти в «Настройки», затем в «Приложения» и найти Google Play Store. Нажмите и прокрутите вниз до «Хранилища». Затем просто выберете «Очистить данные» (Вы также можете сначала попробовать почистить кэш, но удаление данных очищает его автоматически)

Если предыдущий пункт («Ручная синхронизация») не сработал, попробуйте его снова после удаления данных и чистки кэша – эти действия могут дать лучшие результаты.
Используйте браузер мобильного/стационарного устройства, чтобы установить приложение
Это обходной путь для полностью неисправного приложения Play Store. Зайдите в свой веб-браузер и перейдите на сайт Google Play Store. Попробуйте загрузить приложение напрямую оттуда, а не через приложение Google Play Store. Просто войдите в свою учетную запись Google через браузер и затем установите выбранное приложение.
Вы также можете сделать это через браузер своего компьютера. Вас попросят войти в учётную запись Google, затем выбрать на какое устройство вы бы хотели загрузить приложение. Как только ваш смартфон/планшет будут подключены к интернету, загрузка начнется незамедлительно.
Если после прохождения всех этих пунктов у вас остались проблемы, попробуйте пройти их еще раз в таком порядке, перезагружая телефон между пунктами: удалить учетную запись Google, перезагрузить, удалить обновления, установить новый Play Store, перезагрузить, добавить учетную запись и так далее. Просто пытайтесь до тех пор, пока ошибка не исчезнет.
5411 No response received during 120 seconds on last EAP message sent to the client
| Applies to | All EAP types |
|---|---|
| Possible Causes |
NAD or supplicant: Timeout for EAP may be too aggressive. Supplicant: Configured with certificate base authentication and the supplicant either does not have valid credentials or does not trust ISE certificate. Supplicant and user: Configured with password-based authentication and the user did not provide valid credentials. |
| Resolution | Verify that supplicant is configured properly to conduct a full EAP conversation with ISE. Verify that NAS is configured properly to transfer EAP messages to or from supplicant. Verify that supplicant or network access server (NAS) does not have a short timeout for EAP conversations. Check the network that connects the NAS to ISE. If the external ID store is used for the authentication, it may be not responding fast enough for current timeouts. |
Validate Endpoint-to-NAD Communication
- For Catalyst switches, enable 802.1X debugging by running the following in exec mode:
debug dot1x
- Validate that client is sending EAP over LAN (EAPoL) Start message by checking the debug log.
- For devices using MAC Authentication Bypass (MAB), validate that the device is sending traffic.
If the interface is configured with the settings for order and timers that are recommended for Cisco TrustSec 2.1, it will take 30 seconds before the switch will accept and use the traffic from the endpoint to send a MAB request. This is typically not an issue for chatty devices, such as Windows PC devices; however, some printers may take a while to go through the MAB. If you are experiencing long delays to successfully MAB a device, like a printer, consider running the interface-specific command authentication control-direction in to allow traffic from the network to the endpoint prior to authentication, which could accelerate the MAB process.
Откуда может появится ошибка 530 incorrect login
Эта не ошибка с загрузкой файлов через FileZilla и не сбой подключения к Интернету, а проблема, которая возникла в момент, когда вы попытались подключиться к серверу. Некоторые, не выдержав возникшей трудности, сразу бросаются к другим клиентам. Однако, не стоит этого делать, потому что со временем вы поймете, что лучше чем FileZilla сложно найти что-либо, ведь программы, которые наравне, стоят денег, а этот клиент распространяется бесплатно. Чтобы определить суть ошибки, вам следует обратиться к логам внутри клиента, которые покажут в какой конкретный момент подключение пошло не так.
В случае, если вы еще ни разу не заходили на сервер, попробуйте заново зарегистрироваться. От этого вы ничего не потеряете, ведь еще не использовали свой аккаунт. Если же раньше у вас нормально получалось заходить на FTP-сервер через FileZilla, а сегодня появилась ошибка 530 login authentication failed, значит что-то вы сделали не так.
Но причина возникновения сбоя подключения не всегда такая простая и очевидная. Иногда из-за невнимательности пользователи пытаются зайти не на тот сервер, после чего на экране появляется надпись 530 login authentication failed — сбой авторизации. В таком случае причина неполадки банальна — на сервере, который вы пытаетесь посетить, нет такого логина, под которым вы хотите зайти. Чтобы быть уверенным, что причина кроется не в этом, сотрите все данные подключения и введите еще раз. Также уточните у админа сервера, быть может он сменил номер порта на какой-то нестандартный, а старый порт уже занял другой хост. Потому-то у вас и не получается зайти, хоть данные кажутся в порядке.
Часто пользователи из лени и нежелания тратить время не запоминают пароли от аккаунтов. Они их записывают где-то, а затем берут оттуда и копируют их в соответственное поле. Так делать категорически неправильно, ведь вы рискуете всеми своими аккаунтами, пароли которых содержатся в том или ином файле на компьютере или в Интернете. Однажды придет какой-нибудь недоброжелатель и воспользуется вашей памяткой в собственных целях. В результате вся важная информация будет украдена, в том числе и при помощи FileZilla с сервера. Кроме того, вы можете ненароком скопировать пароль неправильно и вставить уже не ту комбинацию символов, которая не пустит вас на хост. Так что записывайте такую информацию вручную и не храните ее на компьютере.
С другой стороны, проблема может быть внутри FileZilla. Возможно, ошибка 530 login authentication failed возникает из-за того, что у вас активирован какой-то неподходящий режим шифрования в настройках. Вспомните, может во время последнего сеанса вы изменяли настройки ради интереса и любопытства, что в итоге появляется надпись 530 incorrect login. Тогда зайдите в настройки в раздел «Шифрование» и установите «Использовать простой FTP». И хоть это не совсем правильно в плане безопасности, но лучше так, чем вообще не зайти на сервер.
Иногда так бывает, что ради интереса люди загружают к себе на компьютер сразу много программ, наподобие FileZilla. И если вы тоже так сделали, и создали сервер у себя на компьютере, а теперь не можете к нему подключиться, то лучше проверьте, а не установили ли вы все программы одновременно? Хотя достаточно запустить два сервера вместе, чтобы ни один из них не работал и при подключении у вас появлялась надпись: 530 login authentication failed. Устранить эту проблему очень легко: определитесь, какой сервер вам понравился больше и удалите все остальные. Как правило, многие оставляют FileZilla server, а остальные удаляют.
Также часто случается, что пользователи абсолютно не понимают, какой логин и пароль от них требуется. Особенно часто это случается с начинающими вебмастерами, которые не знают, как подключить FileZilla к хосту. В таком случае вам нужно зайти в аккаунт на хостинг-провайдер, а там вы найдете пароль от FTP, а вместе с ним и логин. Сохраните его к себе, а еще лучше запомните, и теперь попробуйте войти. Кроме того, некоторые пытаются войти на сервер под аккаунтом анонима, используя логин anonymous и скрытый пароль, но не все хосты это разрешают. Если появилась ошибка 530 login authentication failed, значит придется ввести реальный логин и пароль пользователя сервера.
RADIUS Live Logs
The RADIUS Live Logs in ISE lists all the authentications that have reached ISE. If there is no entry for the user in this screen, the authentication request has not been received by ISE.
You can look at the RADIUS Live Logs by logging in to ISE primary PAN and going to Operations > RADIUS > Live Logs. Doing so will bring up a screen similar to the one shown in Figure 11.
Note: The Live Logs screen is provided by Primary MnT node. The same information is also available on backup MnT node. Access to the Live Logs is also available by logging in to the secondary PAN and also logging in directly to either MnT node.
The RADIUS Live Logs has several important pieces of information that are critical to determining who is on the network, when and where they connected, and how they were authenticated.

The RADIUS Live Logs viewer
Note: Some of the columns listed described here are visible only by using the Add/Remove Columns feature. To make these columns visible, right-click on the header row.
| Column | Description |
| Time | Shows the time that the log was received by the collection agent. This column is required and cannot be deselected. |
| Status | Shows if the authentication was successful or failed. This column is required and cannot be deselected. |
| Details | Brings up a report when you click the magnifying glass icon, allowing you to drill down to view more detailed information on the selected authentication scenario. This column is required and cannot be deselected. |
| Repeat Count | The number of times the same message was received. |
| Identity | Shows the username that is associated with the authentication. |
| Endpoint ID | Shows the unique identifier for an endpoint, usually a MAC or IP address. |
| Endpoint Profile | The matching endpoint profile for this endpoint. |
| Authentication Policy | Which Policy Set and Authentication Policy Rule was matched |
| Authorization Policy | Which Policy Set and Authorization Policy Rule was matched |
| Authorization Profiles | Shows an authorization profile that was applied based on the Authorization Policy. |
| IP Address | Shows the IP address of the endpoint device. |
| Network Device | Shows the IP address of the network access device. |
| Device Port | Shows the port number at which the endpoint is connected. |
| Identity Group | Shows the identity group that is assigned to the user or endpoint, for which the log was generated. |
| Posture Status | Shows the status of the posture validation and details on the authentication. |
| Server | Indicates the policy service node (PSN) from which the log was generated. |
| MDM Server Name | Name of the MDM used, if any. |
| Optional | You may choose to show the following fields using the dropdown option |
| Event | Shows the event status. |
| Failure Reason | Shows a detailed reason for failure, if the authentication failed. |
| Auth Method | Shows the authentication method that is used by the RADIUS protocol, such as Microsoft Challenge Handshake Authentication Protocol version 2 (MSCHAPv2), IEE 802.1x, or dot1x, and so on. |
| Authentication Protocol | Shows the authentication protocol used, such as Protected Extensible Authentication Protocol (PEAP), Extensible Authentication Protocol (EAP), and the like. |
| Security Group | Shows the group that is identified by the authentication log. |
| Session ID | Shows the session ID. |