<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: loadbalanced ISE - sharing persistence for RADIUS auth/acct VIPs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/loadbalanced-ise-sharing-persistence-for-radius-auth-acct-vips/m-p/3989393#M455422</link>
    <description>&lt;P&gt;"Persistency Groups" on the Netscaler look to be the equivalent of F5's "match across services" (used in cisco's ISE and F5 documentation) for persistence sharing between VIPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested this on the Netscaler by:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created a Persistency Group under &lt;STRONG&gt;Traffic Management &amp;gt; Load Balancing &amp;gt; Persistency Group&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Added persistence settings to the group:&lt;BR /&gt;Rule - CLIENT.UDP.RADIUS.ATTR_TYPE(31)+CLIENT.UDP.RADIUS.ATTR_TYPE(4)&lt;/LI&gt;&lt;LI&gt;Added the ISE RADIUS authentication and accounting VIPs to the Persistency Group.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to have solved the issue and now RADIUS authentication and accounting traffic are sent to the same psn for a given Calling-Station-Id.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;BR /&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ps to check the persistency group is working as expected on the Netscaler I used the command "&lt;STRONG&gt;show lb persistentSessions &amp;lt;NAME_OF_PERSISTENCY_GROUP&amp;gt;&lt;/STRONG&gt;" - this displays the Calling-Station-Ids and the mapped psn used for both RADIUS authentication and accounting&lt;/P&gt;</description>
    <pubDate>Tue, 26 Nov 2019 10:20:47 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2019-11-26T10:20:47Z</dc:date>
    <item>
      <title>loadbalanced ISE - sharing persistence for RADIUS auth/acct VIPs</title>
      <link>https://community.cisco.com/t5/network-access-control/loadbalanced-ise-sharing-persistence-for-radius-auth-acct-vips/m-p/3988855#M455421</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have ISE PSNs loadbalanced with a Citrix MPX - there are 2 VIPs (same IP) for RADIUS authentication and accounting. These VIPs have the same peristence rules (calling-id with a backup of nas-ip).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've noticed the following syslog messages in ISE RADIUS accounting for some clients:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Audit session was not found&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Accounting start was received for non-existing session&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought this may have something to do with some clients authenticating against one psn and the accounting traffic being sent to another. I confirmed this by modifying a NAD switch to use a particular PSN IP rather than the loadbalanced VIP for RADIUS. With this config in place, there were no more syslogs like the ones above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking at the netscaler documentation below to share persistent sessions between the 2 RADIUS auth/acct VIPs so that a client's auth/acct traffic always hits the same psn for both services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.citrix.com/en-us/netscaler/12/load-balancing/load-balancing-persistence/sharing-persistent-sessions.html" target="_blank"&gt;https://docs.citrix.com/en-us/netscaler/12/load-balancing/load-balancing-persistence/sharing-persistent-sessions.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else come across this issue and, if so, am I on the right track?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 12:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/loadbalanced-ise-sharing-persistence-for-radius-auth-acct-vips/m-p/3988855#M455421</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-11-25T12:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: loadbalanced ISE - sharing persistence for RADIUS auth/acct VIPs</title>
      <link>https://community.cisco.com/t5/network-access-control/loadbalanced-ise-sharing-persistence-for-radius-auth-acct-vips/m-p/3989393#M455422</link>
      <description>&lt;P&gt;"Persistency Groups" on the Netscaler look to be the equivalent of F5's "match across services" (used in cisco's ISE and F5 documentation) for persistence sharing between VIPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested this on the Netscaler by:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created a Persistency Group under &lt;STRONG&gt;Traffic Management &amp;gt; Load Balancing &amp;gt; Persistency Group&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Added persistence settings to the group:&lt;BR /&gt;Rule - CLIENT.UDP.RADIUS.ATTR_TYPE(31)+CLIENT.UDP.RADIUS.ATTR_TYPE(4)&lt;/LI&gt;&lt;LI&gt;Added the ISE RADIUS authentication and accounting VIPs to the Persistency Group.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to have solved the issue and now RADIUS authentication and accounting traffic are sent to the same psn for a given Calling-Station-Id.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;BR /&gt;Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ps to check the persistency group is working as expected on the Netscaler I used the command "&lt;STRONG&gt;show lb persistentSessions &amp;lt;NAME_OF_PERSISTENCY_GROUP&amp;gt;&lt;/STRONG&gt;" - this displays the Calling-Station-Ids and the mapped psn used for both RADIUS authentication and accounting&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 10:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/loadbalanced-ise-sharing-persistence-for-radius-auth-acct-vips/m-p/3989393#M455422</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-11-26T10:20:47Z</dc:date>
    </item>
  </channel>
</rss>

