<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4 in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4438134#M3757</link>
    <description>&lt;P&gt;Very helpful, thanks for posting&lt;/P&gt;</description>
    <pubDate>Sat, 24 Jul 2021 09:12:05 GMT</pubDate>
    <dc:creator>apanesar</dc:creator>
    <dc:date>2021-07-24T09:12:05Z</dc:date>
    <item>
      <title>Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4426071#M3691</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have RADIUS login for our DNA center via ISE. After we upgraded ISE to 2.7 patch 4 from 2.6 we are no longer able to login to DNA Center.&lt;/P&gt;
&lt;P&gt;We can see the RADIUS in ISE and everything looks OK. We see that ISE returns accept with &lt;STRONG&gt;cisco-av-pair Role=SUPER-ADMIN-ROLE&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;But DNA Center display:&amp;nbsp;&lt;STRONG&gt;Invalid Login Credentials.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can't login with the local admin account, same message in DNA:&amp;nbsp;&lt;STRONG&gt;Invalid Login Credentials&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;We have reset the admin password via&amp;nbsp;SSH to DNA Center &amp;gt; maglev &amp;gt;&amp;nbsp; magctl user password update admin TNT0.&lt;/P&gt;
&lt;P&gt;But with no luck, still&amp;nbsp;&lt;STRONG&gt;Invalid Login Credentials&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have also tesed with and ACL on the interface that connects the DNA to our network with deny to ISE-servers to stop any RADIUS traffic, but still can't access it with local admin account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before we upgraded Cisco ISE the login worked fine.&lt;/P&gt;
&lt;P&gt;Have any of you had the same problem or have any idea where to go from here?&lt;BR /&gt;We will try to open an TAC-case for this.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 22:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4426071#M3691</guid>
      <dc:creator>victor.mansson</dc:creator>
      <dc:date>2021-08-18T22:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4426688#M3700</link>
      <description>&lt;P&gt;I have found a solution for this.&amp;nbsp;&lt;BR /&gt;Im posting it here if anyone else get this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Cisco DNA realse&amp;nbsp;&lt;SPAN&gt;2.1.x and after fallback to local account is disabled.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I had to SSH in to DNA Center using maglev account.&lt;BR /&gt;Enter this command:&amp;nbsp;&lt;STRONG&gt;magctl rbac external_auth_fallback enable&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now I could login to DNA Center with the local admin account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To get RADIUS woring again I had to update from &lt;STRONG&gt;Cisco-av-pair&lt;/STRONG&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;Cisco-service-info&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;So in ISE I had to change the&amp;nbsp;Authorization Profile to:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access Type = ACCESS_ACCEPT&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;cisco-service-info = Role=SUPER-ADMIN-ROLE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in DNA I had to go to &lt;STRONG&gt;System &amp;gt; Users &amp;amp; Roles &amp;gt; External Authentication&lt;/STRONG&gt; and change the&amp;nbsp;&lt;STRONG&gt;AAA Attribute&lt;/STRONG&gt; to&amp;nbsp;&lt;STRONG&gt;cisco-service-info&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 12:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4426688#M3700</guid>
      <dc:creator>victor.mansson</dc:creator>
      <dc:date>2021-07-01T12:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4437858#M3756</link>
      <description>&lt;P&gt;Thanks for this. Can confirm I observed this issue on DNA-C 2.1.2.7 and ISE 2.6 Patch 4. This workaround fixes it and applies to both RADIUS and TACACS. Is their a Bug ID associated with it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 14:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4437858#M3756</guid>
      <dc:creator>jamessciortino0060</dc:creator>
      <dc:date>2021-07-23T14:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4438134#M3757</link>
      <description>&lt;P&gt;Very helpful, thanks for posting&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 09:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4438134#M3757</guid>
      <dc:creator>apanesar</dc:creator>
      <dc:date>2021-07-24T09:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4452159#M3899</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;Thanks for the info however this is not working for me. Our situation is slightly different however - it was working fine with 2.6 patch 7 but patch 9 introduced the issue. Unlike Op our local account still worked fine.&amp;nbsp;&lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRIKE&gt;Changing the AuthZ result to cisco-service-info and the DNAC "AAA Attribute" from "Cisco-AVPair" to "cisco-service-info" did not resolve the issue.&amp;nbsp;&lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working! I'm not sure why it didn't work the first time but I tried again today and it now works. We did not experience the issue of losing admin access to DNAC however, but otherwise saw exactly the same issue - now resolved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 02:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4452159#M3899</guid>
      <dc:creator>franklinb</dc:creator>
      <dc:date>2021-08-25T02:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login to DNAc after upgrading Cisco ISE 2.7 p4</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4453836#M3907</link>
      <description>&lt;P&gt;There are a couple of bugs relate to this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CSCvy56771&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CSCvu83230&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 22:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/unable-to-login-to-dnac-after-upgrading-cisco-ise-2-7-p4/m-p/4453836#M3907</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-23T22:28:47Z</dc:date>
    </item>
  </channel>
</rss>

