<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSN not Authenticating Radius and TACACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3736549#M489080</link>
    <description>&lt;P&gt;thank you to all that have contributed. As promised, the issue was a firewall filter blocking network traffic to my PAN and PSN. Once i added the route, everything started working perfectly as designed. Much appreciated Cisco Forum &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 15:04:42 GMT</pubDate>
    <dc:creator>mpbaker82</dc:creator>
    <dc:date>2018-10-31T15:04:42Z</dc:date>
    <item>
      <title>PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734077#M489006</link>
      <description>&lt;P&gt;I have a ISE distributed deployment:&lt;/P&gt;
&lt;P&gt;1 PAN (admin, monitor, and psn) geographic location 1 (primary)&lt;/P&gt;
&lt;P&gt;1 SAN (admin, monitor, and psn) geographic location 2 (backup to primary)&lt;/P&gt;
&lt;P&gt;5 PSN ( psn persona only) geographic location 3-5 (the only service running on these psn's is the "enable device admin". Everything else is deselected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No node groups are created&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm able to point any device on my network regardless of the geographic location to my primary PAN and the device authenticates using the polices i have setup (radius/tacacs). However, when i attempt to point a device to its local ISE psn node, it fails. In my Admin&amp;gt;System&amp;gt;Deployment screen, all my nodes give a status of connected.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried to use some logs to verify the sync, and to see if the psn's are even seeing the authentication attempt. but im not seeing no such thing. its possible im not even looking at the right log.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas as to why? I'm hoping the great people on this forum can be of more assistance then the TAC support team. I can honesty say I've have three separate and individual experiences with TAC and its much less desirable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 04:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734077#M489006</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-27T04:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734162#M489007</link>
      <description>&lt;P&gt;So you are testing with TACACS only right now?&amp;nbsp; Your title says RADIUS and TACACS but you said you have turned off RADIUS and only have Device Admin enabled under Policy Service.&amp;nbsp; You can go to the debug menu and do packet captures on any of the nodes to verify packets are being received on the PSN you are testing against.&amp;nbsp; You could also force a sync on the PSNs from the deployment screen, but if you are testing TACACS you should see attempts even if the PSNs are out of sync.&amp;nbsp; Also make sure you are looking at the TACACS live logs and not the RADIUS live logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also run TACACS debugs on the network device.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 11:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734162#M489007</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-27T11:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734176#M489008</link>
      <description>&lt;P&gt;Paul,&lt;/P&gt;
&lt;P&gt;Thanks for your help&lt;/P&gt;
&lt;P&gt;Which service runs Radius?&lt;/P&gt;
&lt;P&gt;Enable Device Admin = TACACS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;? = Radius&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My secondary admin node has every service enabled that the primary admin node does but when i point my radius device to that san, it still doesn't authenticate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As i mention before, we have several geographically separated areas which hold their own ISE. Devices in those locations will point their their respective ISE nodes. It just so happens that two of those locations run the PAN and SAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 13:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734176#M489008</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-27T13:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734192#M489009</link>
      <description>Session Services = RADIUS&lt;BR /&gt;&lt;BR /&gt;Profiling goes with Session Services if you are planning to use the profiling feature for MAB devices&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734192#M489009</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-27T15:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734196#M489010</link>
      <description>&lt;P&gt;Hmm, thats odd because we are only using ISE for network devices. i.e. switches, routers, firewalls, etc. We dont have end users devices authenticating with ISE. Its more of a network device management over the oob connection.&lt;/P&gt;
&lt;P&gt;I dont have session services enabled on on the pan ise node and im able to point a test switch to the pan and it authenticates with both tacacs and radius on the pan node. if i take that same test switch and point it to the san or even a psn, it fails. no workie.&lt;/P&gt;
&lt;P&gt;I dont have node groups enabled because im not looking for the failover between psn's. In my network devices, i have the local psn node 1st, then my pan as 2nd should the local ise node fail or become disconnected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I mean we are talking about the same session service setting right? Admin&amp;gt; system &amp;gt; deployment &amp;gt; Policy &amp;gt; Session Service&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you, you've been a great help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734196#M489010</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-27T15:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734198#M489011</link>
      <description>&lt;P&gt;This is happening even after you resolved &lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/non-responsive-cisco-ise/m-p/3725020" target="_blank"&gt;Non Responsive Cisco ISE&lt;/A&gt;. Correct?!&lt;/P&gt;
&lt;P&gt;Like Paul mentioned, you may turn some debug on the network device (NAD) to check the communication. Or, use TCPdump or similar packet capture tool to verify packet flows between NAD and PSN. Once that verified, we may go further in debugging on the ISE side.&lt;/P&gt;
&lt;P&gt;Sorry to hear your less-than-desirable experience with TAC. If this happens again, please ask to speak to the duty TAC manager.&lt;/P&gt;
&lt;P&gt;RADIUS is part of the core of ISE policy services so it's probably got turned ON as soon as one of the policy services enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 16:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734198#M489011</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-27T16:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734199#M489012</link>
      <description>&lt;P&gt;Thank you hslai, I will def be contacting the duty tac manager for sure. I didnt know there was such a thing but now that i do, i hope to get some more help moving forward.&lt;/P&gt;
&lt;P&gt;im unable to provide any debug information due to the sensitivity of my environment but ill follow your instructions and see what else i can figure out. Ill keep this thread posted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 16:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734199#M489012</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-27T16:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734262#M489013</link>
      <description>&lt;P&gt;So I have no reason to believe that this is the cause of your issue, but just a general comment on the design.&amp;nbsp; With the PAN and MNT's collocated in a hybrid deployment, you should really only have sessions services enabled on the 5 dedicated PSNs, not all 7 nodes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 00:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734262#M489013</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-28T00:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734400#M489014</link>
      <description>&lt;P&gt;Thanks damien&lt;/P&gt;
&lt;P&gt;However, Im not quite following your comment. however, im very interested. The ISE deployment is new to me so i'm still learning as i go. trial by fire i guess.&lt;/P&gt;
&lt;P&gt;are you saying that the pan and san would not have radius services enabled? assuming from a previous comment that session services enable radius, while device admin services enable tacacs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 15:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734400#M489014</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-28T15:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734405#M489015</link>
      <description>Please provide few detail. I will try to help you here.&lt;BR /&gt;&lt;BR /&gt;Output of  "show version" command&lt;BR /&gt;&lt;BR /&gt;What do you seen in tacacs live logs?&lt;BR /&gt;Operations&amp;gt;TACACS&amp;gt; live logs&amp;gt; try to click on details report (a small icon under details column) Try to authentication and then see the logs for that authentication.&lt;BR /&gt;</description>
      <pubDate>Sun, 28 Oct 2018 15:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734405#M489015</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-28T15:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734409#M489016</link>
      <description>&lt;P&gt;Cisco Identity Services Engine&lt;/P&gt;
&lt;P&gt;Version = 2.4.0.357&lt;/P&gt;
&lt;P&gt;Build Date = Mar 22 2018&lt;/P&gt;
&lt;P&gt;Install Date Oct 23 2018&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine Patch&lt;/P&gt;
&lt;P&gt;Version 3&lt;/P&gt;
&lt;P&gt;Install Date Oct 24 2018&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the details report, i know what your talking about but there isnt any logs coming through if I point the radius device to the psn. If i point it to the pan, i can authenticate all day for both radius and tacacs. Im wondering if the psn nodes truly replicated to the pan. The node statue says complete but it doesn't make sense that they would preform like this if they did.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there a log i can check out to verify the completion status of the SAN and PSNs? if im remembering right, we used show logging application.log tail command on each of the nodes to see the status. does this ring true with anyone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know the devices are configured correctly for authentication, they wouldn't authenticate with the pan if they weren't. So to make the change to the san or one of the psn's, i just go in and point the device at the new aaa server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 15:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734409#M489016</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-28T15:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734412#M489017</link>
      <description>&lt;P&gt;Are you facing issue with RADIUS or TACACS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1&amp;gt; Enable debugs. Administration&amp;gt; system &amp;gt; logging&amp;gt; debug log configuration &amp;gt; select the psn and enable runtime-aaa to debug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2&amp;gt; Point one of the device to the affected PSN and then open two SSH session to the affect PSN and tail following two logs then authenticate:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show logging application prrt-server.log tail&lt;/P&gt;
&lt;P&gt;show logging application localStore/iseLocalStore.log tail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also take tcpdump operations&amp;gt;diagnostic tools&amp;gt; tcpdump&amp;gt; select the psn and then give "ip host x.x.x.x" in filter and see what do you see there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If possible share the logs of the above two logs.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 16:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734412#M489017</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-28T16:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734420#M489018</link>
      <description>&lt;P&gt;Im facing an issue with both if i point the device to one of the PSN or the SAN node. I have no issues if i point the device to the pan node. I can authenticate using both tacacs and radius all day. the problem occurs only when i point the device to its local ise node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you again for the help&lt;/P&gt;
&lt;P&gt;ill run the commands as mention. However, i am unable to share any log information. if there is something of particular interest, i can filter just that and remove any thing that needs to be removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 16:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734420#M489018</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-28T16:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734422#M489065</link>
      <description>I have updated my reply so please check again. &lt;BR /&gt;&lt;BR /&gt;In logs check what you see for the authentication request, it will show why it is failing. For TACACS you need device admin license.</description>
      <pubDate>Sun, 28 Oct 2018 16:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734422#M489065</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-28T16:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734449#M489068</link>
      <description>&lt;P&gt;So I did your test. i did it twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(radius) Device to PAN&lt;/P&gt;
&lt;P&gt;once to the pan to get base line of what i should be seeing. Everything worked great. i seen the data coming in on the 2 logs you pointed me to and i seen tcp dump information as warranted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then again,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(radius) Device to Local ISE node PSN&lt;/P&gt;
&lt;P&gt;No authentication, nothing in the logs. Its like it didnt even see the device. I also did a TCP dump on the psn node filtering for my ip host 10.x.x.x and attempted to authenticate twice and NOTHING.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;im going to look at the comm between my psn's and the pan. Ill put in a tac ticket on Monday to see what else i can get going.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i finally figure this out, ill post back with the update&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 17:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734449#M489068</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-28T17:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734453#M489077</link>
      <description>&lt;P&gt;&lt;A id="link_75" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/488930" target="_self"&gt;&lt;SPAN class=""&gt;pan&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;brought out an interesting point on Device Admin licensing. That in ISE 2.4 is done per ISE node that enabled for device admin.&lt;/P&gt;
&lt;P&gt;If you are going to watch iseLocalStore.log, please the option of "Local Logging" for Passed Authentications.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2018-10-28 at 10.18.16 AM.png" style="width: 721px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/21443i86A99C3893A220C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2018-10-28 at 10.18.16 AM.png" alt="Screen Shot 2018-10-28 at 10.18.16 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 17:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734453#M489077</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-28T17:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734454#M489078</link>
      <description>&lt;BLOCKQUOTE&gt;... I also did a TCP dump on the psn node filtering for my ip host 10.x.x.x and attempted to authenticate twice and NOTHING.
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If your ip host 10.x.x.x is the PSN and nothing in TCPDUMP, then that means your network device is not making requests to the PSN at all.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 17:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734454#M489078</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-28T17:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734547#M489079</link>
      <description>No need to engage TAC, Looks like network blockage. &lt;BR /&gt;&lt;BR /&gt;You need to make sure your network is not blocking following ports. &lt;BR /&gt;For RADIUS:  udp 1645,1646, 1812, 1813 traffic &lt;BR /&gt;For TACACS: tcp 49 traffic&lt;BR /&gt;&lt;BR /&gt;Check if there is any firewall blocking this traffic?</description>
      <pubDate>Mon, 29 Oct 2018 00:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3734547#M489079</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2018-10-29T00:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: PSN not Authenticating Radius and TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3736549#M489080</link>
      <description>&lt;P&gt;thank you to all that have contributed. As promised, the issue was a firewall filter blocking network traffic to my PAN and PSN. Once i added the route, everything started working perfectly as designed. Much appreciated Cisco Forum &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 15:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-not-authenticating-radius-and-tacacs/m-p/3736549#M489080</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-10-31T15:04:42Z</dc:date>
    </item>
  </channel>
</rss>

