<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iPSK not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937932#M456579</link>
    <description>&lt;P&gt;In your authorization policy, you are looking for a calling-station-id of the MAC address with colons ":" and capital letters.&amp;nbsp; If you look at the failure details, the attribute for calling-station-id uses dashes "-" and lower-case letters.&amp;nbsp; That is why you aren't matching on an authorization rule and falling down to the default of deny access.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 14:12:35 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2019-10-09T14:12:35Z</dc:date>
    <item>
      <title>iPSK not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937905#M456578</link>
      <description>&lt;P&gt;Just testing iPSK, I've followed the official Cisco links and several other people who have set this up, but I must be missing something simple.&lt;/P&gt;&lt;P&gt;The WLC is running 8.5.140, ISE is 2.2 Patch 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you will see on the policy set picture I've tried to setup using End Point Groups and calling station id = mac address, with permit all and psk just to get the b&lt;SPAN&gt;asic connect working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;2 Endpoint Groups IPSK-Phone630 , IPSK-Phone681, both have at least 1 mac address for testing.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;All Auth Profiles Access &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;Type = ACCESS_ACCEPT&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;cisco-av-pair = psk=mode=asci&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;cisco-av-pair = psk=abc12345&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;Have attached the RADIUS failure.&amp;nbsp; The WLC is configured correctly, have tippled checked all configs but something not just there, just need a fresh set of eyes&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" color="#000000"&gt;cheers&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy set.JPG" style="width: 785px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46493i1E81EBC09230DF05/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy set.JPG" alt="policy set.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 13:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937905#M456578</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2019-10-09T13:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937932#M456579</link>
      <description>&lt;P&gt;In your authorization policy, you are looking for a calling-station-id of the MAC address with colons ":" and capital letters.&amp;nbsp; If you look at the failure details, the attribute for calling-station-id uses dashes "-" and lower-case letters.&amp;nbsp; That is why you aren't matching on an authorization rule and falling down to the default of deny access.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937932#M456579</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-10-09T14:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: iPSK not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937944#M456581</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see what you are saying, the ISE changes the "-" to ":", even when entering on adding devices to Endpoints and creating Policy's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Radius Live Logs appears as ":"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ipsk-not-working/m-p/3937944#M456581</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2019-10-09T14:27:11Z</dc:date>
    </item>
  </channel>
</rss>

