<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE1.1.3 failover problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156150#M137365</link>
    <description>&lt;P&gt;Hi guys&lt;BR /&gt;&lt;BR /&gt; I am going to write a short story and will try to explain the problem I have.&lt;BR /&gt;&lt;BR /&gt;Here is my setup. I have two ISE servers running I. Primary and secondary mode. Ise1 and ise2. Everything is configured and sync is complete. My access switch is a 2960 which has dot1x enabled and radius defined in the Config. It's using ISE 1 as primary and ise2 as secondary point of authentication. There are phones connected to switch and PCM behind the phone.&lt;BR /&gt;&lt;BR /&gt;The phones and pc authenticate using EAP-TLS which works fines when both servers are up and running. Printers use mab and video end points use EAP-PEAP. All good till here.&lt;BR /&gt;&lt;BR /&gt;When I shut down my primary server , phones printers and video endpoints authenticate without any problem. Pc is having issue and I am getting error message saying EAP timeout after120 seconds.&lt;BR /&gt;&lt;BR /&gt;Today just to test that ise servers are configured properly. I removed the primary server from 2960 Config. Now switch has only one radius server listed for authentication. Which is ISE 2. The authentication works fine. All of them. Then I shut down ise1 just for the sake of it. At this step I have ise2 running and 2960 switch has only one radius configured. Everything works fine here.&lt;BR /&gt;&lt;BR /&gt;The minute I add ISE 1 as primary radius server pc authentication fails and I get EAP time out message.&lt;BR /&gt;&lt;BR /&gt;Looks like I have to tweak some configuration on 2960 so that it failover to backup ISE ASAP. Has anyone seen that ?&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:19:21 GMT</pubDate>
    <dc:creator>Amit Singh2000</dc:creator>
    <dc:date>2019-03-11T03:19:21Z</dc:date>
    <item>
      <title>ISE1.1.3 failover problems</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156150#M137365</link>
      <description>&lt;P&gt;Hi guys&lt;BR /&gt;&lt;BR /&gt; I am going to write a short story and will try to explain the problem I have.&lt;BR /&gt;&lt;BR /&gt;Here is my setup. I have two ISE servers running I. Primary and secondary mode. Ise1 and ise2. Everything is configured and sync is complete. My access switch is a 2960 which has dot1x enabled and radius defined in the Config. It's using ISE 1 as primary and ise2 as secondary point of authentication. There are phones connected to switch and PCM behind the phone.&lt;BR /&gt;&lt;BR /&gt;The phones and pc authenticate using EAP-TLS which works fines when both servers are up and running. Printers use mab and video end points use EAP-PEAP. All good till here.&lt;BR /&gt;&lt;BR /&gt;When I shut down my primary server , phones printers and video endpoints authenticate without any problem. Pc is having issue and I am getting error message saying EAP timeout after120 seconds.&lt;BR /&gt;&lt;BR /&gt;Today just to test that ise servers are configured properly. I removed the primary server from 2960 Config. Now switch has only one radius server listed for authentication. Which is ISE 2. The authentication works fine. All of them. Then I shut down ise1 just for the sake of it. At this step I have ise2 running and 2960 switch has only one radius configured. Everything works fine here.&lt;BR /&gt;&lt;BR /&gt;The minute I add ISE 1 as primary radius server pc authentication fails and I get EAP time out message.&lt;BR /&gt;&lt;BR /&gt;Looks like I have to tweak some configuration on 2960 so that it failover to backup ISE ASAP. Has anyone seen that ?&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156150#M137365</guid>
      <dc:creator>Amit Singh2000</dc:creator>
      <dc:date>2019-03-11T03:19:21Z</dc:date>
    </item>
    <item>
      <title>ISE1.1.3 failover problems</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156151#M137376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have the radius-server commands put in, the switch should just rotate through the servers if they're not available. But, there are radius server groups and the traditional radius-server host commands. Could just be something was overlooked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, this does seem to be a problem with switch configuration. Can you provide the config of the 2960?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 13:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156151#M137376</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2013-04-17T13:52:07Z</dc:date>
    </item>
    <item>
      <title>ISE1.1.3 failover problems</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156152#M137395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have the following lines in your config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;&lt;P&gt;radius-server host &lt;SERVER&gt; auth-port 1812 acct-port 1813 test username radius-test key 7 &lt;HASH&gt;&lt;/HASH&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;radius-server host &lt;SERVER&gt; auth-port 1812 acct-port 1813 test username radius-test key 7 &lt;HASH&gt;&lt;/HASH&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could see a situation where you have the aaa server group configured, but not this, and your switch failed to identify the primary RADIUS server as down, forcing the issue of manual removal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-1-3-failover-problems/m-p/2156152#M137395</guid>
      <dc:creator>ryan.lambert</dc:creator>
      <dc:date>2013-04-17T14:41:48Z</dc:date>
    </item>
  </channel>
</rss>

