<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Stewart - Did you ever in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965216#M38344</link>
    <description>&lt;P&gt;Hi Stewart - Did you ever resolve this issue? I have a similar issue, where the ISE installation matches the rule for external RADIUS sequence, but we never see the traffic towards the external RADIUS servers coming out of any of the ISE boxes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We also see the "&lt;SPAN&gt;Failure Reason 11353 No more external RADIUS servers; can't perform failover", and we're running 2.0.1 in a 4 node setup (admin, monitor, and 2 PSN)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2017 14:26:59 GMT</pubDate>
    <dc:creator>Backendsupport</dc:creator>
    <dc:date>2017-03-01T14:26:59Z</dc:date>
    <item>
      <title>Cisco ISE Radius Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965206#M38313</link>
      <description>&lt;P&gt;Hello, I'm trying to setup our ISE cluster so (in addition to what it already does) it can act as a radius proxy. I have read a number of guides and have:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1) Defined the external Radius server&lt;/P&gt;
&lt;P&gt;2) Created an Radius Server Sequence&lt;/P&gt;
&lt;P&gt;3) Defined the Radius Server Sequence in a policy (where you usually select allowed protocols).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When using a radius client to test the access, I can confirm it is matching the authentication policy that has the radius server sequence. checking the logs I can see an error stating:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Event 5405 RADIUS Request dropped&lt;BR /&gt;Failure Reason 11353 No more external RADIUS servers; can't perform failover&lt;/P&gt;
&lt;P&gt;It sounds like an issue between the ISE and the radius servers defined right? I have done packet captures on the radius servers and there is no traffic from the ISE's whatsoever. They simply are not forwarding these requests.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&lt;/P&gt;
&lt;P&gt;We are running&amp;nbsp;2.0.1.130. 2 nodes as admin, 2 as policy.&lt;/P&gt;
&lt;P&gt;Any help or suggestions would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965206#M38313</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2019-03-11T07:04:49Z</dc:date>
    </item>
    <item>
      <title>Firewalls between your ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965207#M38315</link>
      <description>&lt;P&gt;Firewalls between your ISE servers and the other radius servers? Routing issues? NAT'ing?&lt;/P&gt;
&lt;P&gt;Are you running old style ports 1645 or 1812?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 20:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965207#M38315</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-09-15T20:50:24Z</dc:date>
    </item>
    <item>
      <title>No firewalls or NAT. ISE,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965208#M38322</link>
      <description>&lt;P style="text-align: left;"&gt;No firewalls or NAT. ISE, Radius Proxy, and Radius Client are all in our LAN environment. Routing verified by the fact that each system can ping each other.&lt;/P&gt;
&lt;P style="text-align: left;"&gt;I tried both the old and new ports and this doesn't make any difference.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 21:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965208#M38322</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2016-09-15T21:25:01Z</dc:date>
    </item>
    <item>
      <title>Ok, Actually from looking in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965209#M38326</link>
      <description>&lt;P&gt;Ok, Actually from looking in the log you attached it looks like ISE is actually getting a response, but it's invalid. Maybe try to use the ISE servers tcpdump function, see what ISE thinks is going on. Also double check secret keys in both ends.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 22:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965209#M38326</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-09-15T22:12:55Z</dc:date>
    </item>
    <item>
      <title>I agree with Jan.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965210#M38329</link>
      <description>&lt;P&gt;I agree with Jan.&lt;/P&gt;
&lt;P&gt;The two RADIUS servers are talking - just not establishing a valid connection which is a prerequisite for any authentication. A packet capture should highlight the specific issue.&lt;/P&gt;
&lt;P&gt;Have you contacted the admin of the external RADIUS server to check what they are seeing?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 00:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965210#M38329</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-16T00:34:04Z</dc:date>
    </item>
    <item>
      <title>I'm the admin of the servers,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965211#M38334</link>
      <description>&lt;P&gt;I'm the admin of the servers, and my initial post stated that I have already done packet captures. The only time I see traffic on the external radius server is when I run a ping - I see icmp packets straight away. Otherwise, there is no traffic from ISE - not during creation of the external radius server object or moments where it should be forwarding these. Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 04:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965211#M38334</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2016-09-16T04:48:46Z</dc:date>
    </item>
    <item>
      <title>It's not possible that ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965212#M38336</link>
      <description>&lt;P&gt;It's not possible that ISE has received a response, certainly not from the external radius server anyway (because I have done packet captures and the external radius box receives no requests). I wasn't aware that there was tcpdump on the ISE itself so I will give this a go to see what it sees. I will let you know how I get on. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 04:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965212#M38336</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2016-09-16T04:51:52Z</dc:date>
    </item>
    <item>
      <title>I've done that tcpdump from</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965213#M38338</link>
      <description>&lt;P&gt;I've done that tcpdump from the ISE node and as I'd presumed, the ISE is not forwarding the radius request to the external radius server.&lt;/P&gt;
&lt;P&gt;So the question is why is is not even attempting to forward these requests?&lt;/P&gt;
&lt;P&gt;I have tried several radius sources to rule out the source of the first radius packet as being the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 08:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965213#M38338</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2016-09-16T08:28:24Z</dc:date>
    </item>
    <item>
      <title>When you captured from ISE,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965214#M38340</link>
      <description>&lt;P&gt;When you captured from ISE, did you specify the PSN as the node from which to capture?&lt;/P&gt;
&lt;P&gt;If the PSN isn't sending the requests, I'd recommend a TAC case to have them look at your setup interactively.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I can verify that the feature of external RADIUS servers works. I have used it for several edu deployments that use the eduroam service.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 15:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965214#M38340</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-16T15:06:57Z</dc:date>
    </item>
    <item>
      <title>I have also used the radius</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965215#M38342</link>
      <description>&lt;P&gt;I have also used the radius proxy but on earlier versions of ISE. I have raised a TAC case through our provider and are hoping they will be able to get this working for me.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 10:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965215#M38342</guid>
      <dc:creator>stewartgray</dc:creator>
      <dc:date>2016-09-19T10:16:36Z</dc:date>
    </item>
    <item>
      <title>Hi Stewart - Did you ever</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965216#M38344</link>
      <description>&lt;P&gt;Hi Stewart - Did you ever resolve this issue? I have a similar issue, where the ISE installation matches the rule for external RADIUS sequence, but we never see the traffic towards the external RADIUS servers coming out of any of the ISE boxes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We also see the "&lt;SPAN&gt;Failure Reason 11353 No more external RADIUS servers; can't perform failover", and we're running 2.0.1 in a 4 node setup (admin, monitor, and 2 PSN)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 14:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965216#M38344</guid>
      <dc:creator>Backendsupport</dc:creator>
      <dc:date>2017-03-01T14:26:59Z</dc:date>
    </item>
    <item>
      <title>This is kind of obvious but</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965217#M38348</link>
      <description>&lt;P&gt;This is kind of obvious but when you define radius server sequence do you select the server under *Selected&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965217#M38348</guid>
      <dc:creator>sdoherty</dc:creator>
      <dc:date>2017-03-01T19:29:38Z</dc:date>
    </item>
    <item>
      <title>sdoherty - I can see why you</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965218#M38352</link>
      <description>&lt;P&gt;sdoherty - I can see why you ask since it could be forgotten, but yes, this is already done.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 07:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965218#M38352</guid>
      <dc:creator>Backendsupport</dc:creator>
      <dc:date>2017-03-02T07:07:07Z</dc:date>
    </item>
    <item>
      <title>I have configured ISE as</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965219#M38354</link>
      <description>&lt;P&gt;I&amp;nbsp;have configured ISE as radius proxy but it is not working. ISE is proxying radius request to Microsoft MFA. Attached the error. Could anybody help on this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ise_error_2.jpg" alt="ISE Error" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-proxy/m-p/2965219#M38354</guid>
      <dc:creator>Om Om</dc:creator>
      <dc:date>2017-06-06T14:15:54Z</dc:date>
    </item>
  </channel>
</rss>

