mnt auth-status

Synopsis

netapi ise mnt auth-status <MAC_ADDRESS> [OPTIONS]

Description

Retrieves authentication history for a specific endpoint. Critical for troubleshooting failed authentications or intermittent connectivity.

Arguments

Argument Description Required

MAC_ADDRESS

Endpoint MAC address

Yes

Options

Option Description Default

--hours

History duration in hours

24

--count

Maximum records to return

10

--format

Output format: table, json

table

Examples

# Last 24 hours, 10 records
netapi ise mnt auth-status 00:50:C2:39:F0:F7

# Last 1 hour, 50 records (troubleshooting flapping)
netapi ise mnt auth-status 00:50:C2:39:F0:F7 --hours 1 --count 50

# JSON for analysis
netapi ise mnt auth-status 00:50:C2:39:F0:F7 --format json | jq '.[] | select(.passed == false)'

Sample Output

Authentication History: 00:50:C2:39:F0:F7
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  Timestamp              Method    Result    Reason
  ────────────────────  ────────  ────────  ─────────────────────
  2026-01-23 10:45:12   mab       PASSED    -
  2026-01-23 10:44:58   dot1x     FAILED    EAP timeout
  2026-01-23 10:44:45   dot1x     FAILED    EAP timeout
  2026-01-23 09:15:32   mab       PASSED    -

Common Failure Reasons

Reason Action

EAP timeout

Device doesn’t support 802.1X - configure MAB fallback

Authentication failed

Check credentials, certificate, or identity store

Authorization failed

Check authorization policy conditions

RADIUS request dropped

Check NAD connectivity to ISE

Endpoint rejected

Release from rejected state: netapi ise release-rejected <MAC>

Troubleshooting Pattern

# [CHECK] Get auth history
netapi ise mnt auth-status 00:50:C2:39:F0:F7 --hours 1 --count 20

# [PATTERN] dot1x failures followed by mab success = device doesn't do 802.1X
# This is NORMAL for IoT/MAB devices - dot1x times out, falls back to MAB

# [PATTERN] Repeated failures = actual problem
# Check failure reason and investigate