<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Trustsec with 6500 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241807#M182943</link>
    <description>&lt;P&gt;I've &lt;STRONG&gt;ISE v1.1.2.145&lt;/STRONG&gt; and &lt;STRONG&gt;Cat 6500 IOS ADVENTERPRISEK9-M, Version 15.0(1)SY2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm trying to add 6500 in the trustsec group with ISE and followed the trustsec 2.1 documentation. After configuring it keeps on giving me error in the ISE logs below with the subject &lt;STRONG&gt;#CTSREQUEST#&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: red; margin-top: 0pt;"&gt;11302 Received Secure RADIUS request without a cts-pac-opaque cisco-av-pair attribute&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the steps:&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11001&amp;nbsp; Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11017&amp;nbsp; RADIUS created a new session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15012&amp;nbsp; Selected Access Service - NDAC_SGT_Service&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11302&amp;nbsp; Received Secure RADIUS request without a cts-pac-opaque cisco-av-pair attribute&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also after i configure cts credentials and radius-server pac command in 6500, it starts giving me log messages that radius is down and the next moment it comes up again. It is continously doing that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Zohaib&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:22:10 GMT</pubDate>
    <dc:creator>Zohaib Hussain</dc:creator>
    <dc:date>2019-03-11T03:22:10Z</dc:date>
    <item>
      <title>ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241807#M182943</link>
      <description>&lt;P&gt;I've &lt;STRONG&gt;ISE v1.1.2.145&lt;/STRONG&gt; and &lt;STRONG&gt;Cat 6500 IOS ADVENTERPRISEK9-M, Version 15.0(1)SY2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm trying to add 6500 in the trustsec group with ISE and followed the trustsec 2.1 documentation. After configuring it keeps on giving me error in the ISE logs below with the subject &lt;STRONG&gt;#CTSREQUEST#&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: red; margin-top: 0pt;"&gt;11302 Received Secure RADIUS request without a cts-pac-opaque cisco-av-pair attribute&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the steps:&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11001&amp;nbsp; Received RADIUS Access-Request&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11017&amp;nbsp; RADIUS created a new session&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;15012&amp;nbsp; Selected Access Service - NDAC_SGT_Service&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="font-weight: normal; color: #000000; padding: 1pt 2pt; border-top: thin none #8499a2; border-right: thin solid #8499a2; border-bottom: thin none #8499a2; border-left: thin solid #8499a2;" valign="middle"&gt;&lt;TD style="padding: 2pt 4pt;" valign="middle"&gt;&lt;P style="margin-top: 0pt;"&gt;11302&amp;nbsp; Received Secure RADIUS request without a cts-pac-opaque cisco-av-pair attribute&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also after i configure cts credentials and radius-server pac command in 6500, it starts giving me log messages that radius is down and the next moment it comes up again. It is continously doing that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Zohaib&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241807#M182943</guid>
      <dc:creator>Zohaib Hussain</dc:creator>
      <dc:date>2019-03-11T03:22:10Z</dc:date>
    </item>
    <item>
      <title>ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241808#M182962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Zohaib,&lt;/P&gt;&lt;P&gt;You may find the following of help in solving the problem.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; Configuring EAP-FAST Settings&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_auth_pol.html#wp1146184"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_auth_pol.html#wp1146184&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Configuring Security Group Access Settings &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_sga_pol.html#wp1102430"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/user_guide/ise_sga_pol.html#wp1102430&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_net_acc_flows.html#wp1135510"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_net_acc_flows.html#wp1135510&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; EAP-FAST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/wireless/ps5679/ps5861/prod_qas09186a00802030dc_ps430_Products_Q_and_A_Item.html"&gt;http://www.cisco.com/en/US/prod/collateral/wireless/ps5679/ps5861/prod_qas09186a00802030dc_ps430_Products_Q_and_A_Item.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 19:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241808#M182962</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-05-02T19:28:48Z</dc:date>
    </item>
    <item>
      <title>ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241809#M183003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've already opened a TAC case and the engineer said every thing is configured fine. Will send some debugs to them. I'll update here once the case is solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Zohaib&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 May 2013 07:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241809#M183003</guid>
      <dc:creator>Zohaib Hussain</dc:creator>
      <dc:date>2013-05-04T07:03:17Z</dc:date>
    </item>
    <item>
      <title>Hi Zohaib</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241810#M183047</link>
      <description>&lt;P&gt;Hi Zohaib&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've been facing the same error-messages and you, and found a pritty good "Step by Step guide" which helped me out:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/116498-configure-cts-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/identity-based-networking-service/116498-configure-cts-00.html&lt;/A&gt;&lt;P&gt;&lt;/P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Jarle&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 13:56:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/2241810#M183047</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2016-05-27T13:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773871#M183082</link>
      <description>&lt;P&gt;Hi Zohaib,&lt;/P&gt;
&lt;P&gt;could you solve this issue? I have the same problem to authenticate 3850 core switches in ISE.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 05:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773871#M183082</guid>
      <dc:creator>Sdiana</dc:creator>
      <dc:date>2019-01-07T05:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773916#M183128</link>
      <description>Sam, &lt;BR /&gt;&lt;BR /&gt;Are you receiving a cts pac on any switches or are you setting up a new trustsec environment, making this is the first one and it doesn't work?  There are a few reasons this log can appear. Some basic things to check when you are having issues with trustsec switches.&lt;BR /&gt;&lt;BR /&gt;The Simple scenarios&lt;BR /&gt;1. Missing cts credential ID and password. The credentials don't show up in running config, run "sh cts credentials" will display what was configured. You will not see the password configured, only the ID.&lt;BR /&gt;2. Cts device credentials do not match. Similar to scenario 1, the same CTS ID and password has to be configured in for the NAD in ISE and on the NAD itself.&lt;BR /&gt;3. Radius pac keys are misconfigured either on the switch or in ISE&lt;BR /&gt;4. Dynamic author keys are misconfigured. &lt;BR /&gt;&lt;BR /&gt;More complex scenarios&lt;BR /&gt;5. The cts request on a 3850 does not include a calling station id in the radius packets.  If you are using load balancers then the CTS provisioning process breaks until magic happens and all the packets hit the same PSN. Need to tweak the load balancing algorithm if only using calling station ID. &lt;BR /&gt;6. MTU issues.  Either via some ugly bugs in early code, or a simple misconfiguration like missing cts manual on one side of a link. You can end up dropping packets before 1500 bytes.  An easy test it to source a ping from the management interface at the configured MTU size.</description>
      <pubDate>Mon, 07 Jan 2019 06:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773916#M183128</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-01-07T06:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773934#M183172</link>
      <description>&lt;P&gt;Please check the whether the credentials configured at the NAD is matching the credentials configured in ISE for the respective NAD.&lt;/P&gt;
&lt;P&gt;You can refer this&amp;nbsp;&lt;A href="https://community.cisco.com/t5/policy-and-access/failure-reason-received-secure-radius-request-without-a-cts-pac/m-p/3773847/highlight/false#M72153" target="_self"&gt;link&lt;/A&gt;&amp;nbsp;to check the credentials at ISE end.&lt;/P&gt;
&lt;P&gt;Use this command to configure cts credentials at NAD&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;cts credentials id &amp;lt;device id&amp;gt; password &amp;lt;password&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After that check whether pac is generated at the NAD using show cts pacs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Aravind&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 07:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3773934#M183172</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2019-01-07T07:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Trustsec with 6500</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3774008#M183222</link>
      <description>&lt;P&gt;had a similar issue the one you having.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just make sure you have right config. which i assume you do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group ISE&lt;/P&gt;&lt;P&gt;aaa authorization default group ISE&lt;/P&gt;&lt;P&gt;aaa authorization ISE group ISE&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group ISE&lt;/P&gt;&lt;P&gt;aaa group radius server ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;radius server CISCO&lt;/P&gt;&lt;P&gt;aaa server radius dynamic author&lt;/P&gt;&lt;P&gt;&amp;nbsp;client X.X.X.X. serverkey cisco&lt;/P&gt;&lt;P&gt;radius server CISCO&lt;/P&gt;&lt;P&gt;&amp;nbsp;addres ipv4 x.x.x.x auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;&amp;nbsp;pac key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on&lt;/P&gt;&lt;P&gt;radius-server attribute 8&lt;/P&gt;&lt;P&gt;radius-server attribute 25&lt;/P&gt;&lt;P&gt;radius-server vsa sent auth&lt;/P&gt;&lt;P&gt;radius-server vsa sent account&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;cts authorization list ISE&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;cts credentials id &amp;lt;device id&amp;gt; password &amp;lt;password&amp;gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;give it 5 to 10 min. it will download it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also make sure to use the port 1812 1813.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 09:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-with-6500/m-p/3774008#M183222</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-07T09:41:24Z</dc:date>
    </item>
  </channel>
</rss>

