<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Auth Issues after upgrading to 2.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903992#M470849</link>
    <description>&lt;P&gt;The cert did not change, and I have had clients forget, and accept the cert again anyways.&amp;nbsp; At this time, it appears this issue may be related to the radius timeout setting on the WLC default at 2 secs.&amp;nbsp; We are increasing this to 10.&amp;nbsp; Not a lot of evidence yet to back this up, but looking at the logs it appears that maybe this is the cause of the EAP retransmits.&amp;nbsp; Is anyone aware of increased latency being introduced in 2.4?&amp;nbsp; We were previously on 2.1 without any issues.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2019 17:28:56 GMT</pubDate>
    <dc:creator>awatson20</dc:creator>
    <dc:date>2019-08-06T17:28:56Z</dc:date>
    <item>
      <title>ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901523#M470817</link>
      <description>&lt;P&gt;We recently upgraded from ISE 2.1 to 2.4, and since we have been seeing more random client auth issues.&amp;nbsp; We are using ISE mainly for authentications using PEAP on a wireless network.&amp;nbsp; Since the upgrade, clients are reporting issues and in the ISE logs we are mainly seeing this error.&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;5440 Endpoint abandoned EAP session and started new&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have seen this error before, but it is more related now to clients actually having connection issues.&amp;nbsp; We have not applied the patches yet, as we were waiting a couple of weeks to let the upgrade burn in.&amp;nbsp; Any ideas or suggestions, or known issues with this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 14:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901523#M470817</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2019-08-01T14:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901582#M470822</link>
      <description>I would definitely patch the deployment immediately following upgrading, there are about 500 known bugs if you run unpatched, it could be any number of them.</description>
      <pubDate>Thu, 01 Aug 2019 16:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901582#M470822</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-08-01T16:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901871#M470830</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Or let your Intranet&lt;FONT color="#FF0000"&gt; burn out&lt;/FONT&gt; ? Bear me I don't want to get into simple bashing towards Cisco. I believe CISCO ISE is a &lt;U&gt;&lt;FONT color="#008000"&gt;marvelous product&lt;/FONT&gt; &lt;/U&gt;with a &lt;STRONG&gt;&lt;FONT color="#008000"&gt;vast number&lt;/FONT&gt;&lt;/STRONG&gt; of possibilities BUT as many people have experienced before : due to it's complexity (configuration and the different-nodes-complexity) AND It being &lt;STRONG&gt;mission critical&lt;/STRONG&gt; on the Intranet it is simply not designed for upgrading production nodes. Many people therefore build a second/new environment in place to replace the old-versioned-ISE setup. I used to have a script witch could switch radius servers(PSN Nodes)&amp;nbsp; on the millisecond in the running config of a switch using the CISCO-CONFIG-MIB.&amp;nbsp; Sometimes for new major version it's even better then to re-enter the policies from scratch to take advantage of new features in the most optimal way. Consider following these practices when upgrading to new ISE versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 08:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3901871#M470830</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2019-08-02T08:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3902164#M470836</link>
      <description>&lt;P&gt;upgrade the patch as suggested. Also, are these Windows clients? any event log which can be seen ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 15:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3902164#M470836</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2019-08-02T15:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903876#M470842</link>
      <description>&lt;P&gt;We applied the 2.4 Patch 9, and this seemed to make auth issues better at first, but we are continuing to see problems.&amp;nbsp; Most of our endpoints are mobile iphones or android devices.&amp;nbsp; From the client perspective, it appears that they cannot connect to the SSID.&amp;nbsp; ISE shows the client constantly abandoning and establishing a new EAP session.&amp;nbsp; The wireless controller shows the client authenticated.&amp;nbsp; A debug basically shows the client going through the EAP process over and over.&amp;nbsp; This all started after upgrading to 2.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See a lot of these errors in ISE:&lt;/P&gt;&lt;P&gt;5440 Endpoint abandoned EAP session and started new&lt;/P&gt;&lt;P&gt;12934 Supplicant stopped responding to ISE during PEAP tunnel establishment&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 14:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903876#M470842</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2019-08-06T14:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903935#M470844</link>
      <description>&lt;P&gt;- As an additional debug-resource you may also involve the &lt;STRONG&gt;Wireless Debug Analyzer&lt;/STRONG&gt; , which can be found from the link below&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://developer.cisco.com/docs/wireless-troubleshooting-tools/" target="_blank"&gt;https://developer.cisco.com/docs/wireless-troubleshooting-tools/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 16:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903935#M470844</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2019-08-06T16:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903964#M470847</link>
      <description>A common cause of this is when iphones don't trust the certificate.  Did the ISE cert change?</description>
      <pubDate>Tue, 06 Aug 2019 16:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903964#M470847</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-08-06T16:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903992#M470849</link>
      <description>&lt;P&gt;The cert did not change, and I have had clients forget, and accept the cert again anyways.&amp;nbsp; At this time, it appears this issue may be related to the radius timeout setting on the WLC default at 2 secs.&amp;nbsp; We are increasing this to 10.&amp;nbsp; Not a lot of evidence yet to back this up, but looking at the logs it appears that maybe this is the cause of the EAP retransmits.&amp;nbsp; Is anyone aware of increased latency being introduced in 2.4?&amp;nbsp; We were previously on 2.1 without any issues.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 17:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3903992#M470849</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2019-08-06T17:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3904790#M470851</link>
      <description>No known issues as such but would recommend you get it checked with TAC if you are facing this regularly.</description>
      <pubDate>Wed, 07 Aug 2019 18:30:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/3904790#M470851</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-08-07T18:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/4019794#M470852</link>
      <description>Hello awatson20 ,&lt;BR /&gt;Did it work to change the timeout setting on the WLC?</description>
      <pubDate>Tue, 28 Jan 2020 20:03:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/4019794#M470852</guid>
      <dc:creator>Sp@wn</dc:creator>
      <dc:date>2020-01-28T20:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Auth Issues after upgrading to 2.4</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/4019858#M470853</link>
      <description>Yes, it did.&lt;BR /&gt;</description>
      <pubDate>Tue, 28 Jan 2020 21:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-auth-issues-after-upgrading-to-2-4/m-p/4019858#M470853</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2020-01-28T21:13:21Z</dc:date>
    </item>
  </channel>
</rss>

