<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I am experiencing the exact in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852567#M39903</link>
    <description>&lt;P&gt;I am experiencing the exact same error. &amp;nbsp;I am running the same Version and HF as well. &amp;nbsp;Did you ever find a solution to this? &amp;nbsp;Looking to something to track down and the Live Radius Logs are showing it.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2016 14:22:11 GMT</pubDate>
    <dc:creator>Jeff Okragly</dc:creator>
    <dc:date>2016-08-01T14:22:11Z</dc:date>
    <item>
      <title>[ 400 ] Bad Request,The request is invalid due to malformed syntax or invalid data.</title>
      <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852566#M39902</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Cisco ise giving the following error&amp;nbsp;when users are trying to connect guest portal page&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Possible cause is unknown, invalid, or terminated RADIUS session ID. Please advise the System Admin to consult the logs and ensure that the RADIUS session was not generated by a different PSN or due to a deny access policy match ."&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine&lt;BR /&gt;---------------------------------------------&lt;BR /&gt;Version : 2.0.0.306&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Engine patch version 3.0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How to solve this issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852566#M39902</guid>
      <dc:creator>moosas001</dc:creator>
      <dc:date>2019-03-11T06:46:22Z</dc:date>
    </item>
    <item>
      <title>I am experiencing the exact</title>
      <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852567#M39903</link>
      <description>&lt;P&gt;I am experiencing the exact same error. &amp;nbsp;I am running the same Version and HF as well. &amp;nbsp;Did you ever find a solution to this? &amp;nbsp;Looking to something to track down and the Live Radius Logs are showing it.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 14:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852567#M39903</guid>
      <dc:creator>Jeff Okragly</dc:creator>
      <dc:date>2016-08-01T14:22:11Z</dc:date>
    </item>
    <item>
      <title>Not sure if this will help...</title>
      <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852568#M39904</link>
      <description>&lt;P&gt;Not sure if this will help...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We were having the same issue when guest users were redirected to the quest portal. &amp;nbsp;What was happening in our environment was that we implemented a wildcard SSL certificate so that user's wouldn't get the "unsecure connection" warning when they were presented with our internal CA certificates.&lt;/P&gt;
&lt;P&gt;In order to do this, we had to change the URL presented to users; which was different than the FQDN of the ISE hosts (2 different domains). &amp;nbsp;At first we were doing Round Robin DNS to perform this.&lt;/P&gt;
&lt;P&gt;This was our issue. &amp;nbsp;Upon the guest user's first connection&amp;nbsp;to the open SSID, the WLC and ISE would talk between each other (WLC &amp;lt;--&amp;gt; PSN 1). &amp;nbsp;However, when user's were authorized and redirected to the portal it would be a different node (User &amp;lt;--&amp;gt; PSN 3). &amp;nbsp;This meant the session IDs were different and thus user's would get that error.&lt;/P&gt;
&lt;P&gt;This is what TAC had us perform to fix the issue:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/117620-configure-ISE-00.html&lt;/P&gt;
&lt;P&gt;The only down side is that the PSNs aren't really "load balanced" all clients will be directed to a single PSN until that PSN goes down. &amp;nbsp;Then all requests will go to the next PSN in the cluster.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 14:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852568#M39904</guid>
      <dc:creator>James Johnston</dc:creator>
      <dc:date>2016-08-01T14:57:41Z</dc:date>
    </item>
    <item>
      <title>This is interesting.  I to</title>
      <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852569#M39905</link>
      <description>&lt;P&gt;This is interesting.&amp;nbsp; I to have a public wildcard&amp;nbsp;SSL Cert applied so that users don't get the cert error page.&amp;nbsp; However I am not load balancing via DNS, I am simply calling the hostname.&lt;/P&gt;
&lt;P&gt;xxx@123.com and yyy@123.com&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My WLC SSID is set to use authentication and accounting of PSN1 and PSN2 is slotted as backup just how my deployment is on my ISE Nodes as well.&amp;nbsp; I am hoping all traffic is hitting just one of the PSN and the other is just idol stanby.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 18:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852569#M39905</guid>
      <dc:creator>Jeff Okragly</dc:creator>
      <dc:date>2016-08-01T18:20:08Z</dc:date>
    </item>
    <item>
      <title>Your issue may be different</title>
      <link>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852570#M39908</link>
      <description>&lt;P&gt;Your issue may be different than mine; but one thing you may try is shutting down your second PSN and taking it out of the WLC. &amp;nbsp;Then maybe have users try authenticating?&lt;/P&gt;
&lt;P&gt;We just implemented ISE in our environment with the help of an IT consultant. &amp;nbsp;So not sure what else could be going on.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2016 23:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/400-bad-request-the-request-is-invalid-due-to-malformed-syntax/m-p/2852570#M39908</guid>
      <dc:creator>James Johnston</dc:creator>
      <dc:date>2016-08-01T23:08:25Z</dc:date>
    </item>
  </channel>
</rss>

