MnT Failure Reasons
Usage
# All failure reasons
netapi ise mnt failure-reasons
# Search for specific reason
netapi ise mnt failure-reasons | grep -i "certificate"
Common Failure Reasons
| Code | Description | Common Cause |
|---|---|---|
11007 |
Could not locate machine/user in external identity store |
User not in AD, typo in username |
12308 |
Client rejected EAP-TLS request |
Certificate issues on endpoint |
22056 |
Subject not found in LDAP |
AD connectivity, wrong identity store |
22058 |
User/Machine is disabled in Active Directory |
Account disabled |
24408 |
User authentication against external identity store failed |
Wrong password, locked account |
24415 |
Client certificate chain does not terminate at a trusted CA |
CA certificate not imported to ISE |