<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius timing out to ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695634#M494854</link>
    <description>&lt;P&gt;Yes I definitely have, and enabled radius authentication settings with shared secret&lt;/P&gt;</description>
    <pubDate>Mon, 27 Aug 2018 16:09:17 GMT</pubDate>
    <dc:creator>Madura Malwatte</dc:creator>
    <dc:date>2018-08-27T16:09:17Z</dc:date>
    <item>
      <title>Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695629#M494852</link>
      <description>&lt;P&gt;I am testing RADIUS connectivity to ISE PSN and not seeing any radius packets on the ISE side. This is using the "test aaa" command.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PSN shows state as UP, does this mean the switch checked whether it can&amp;nbsp;connect to the PSN on the radius ports? How does it determine "UP" status?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see below,&amp;nbsp;&lt;SPAN&gt;request 48 and timeouts 48. Debugs on the switch show the same thing:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;*Aug 27 15:22:01.344: RADIUS(00000000): Sending a IPv4 Radius Packet&lt;BR /&gt;*Aug 27 15:22:01.344: RADIUS(00000000): Started 5 sec timeout&lt;BR /&gt;*Aug 27 15:22:06.380: RADIUS(00000000): Request timed out!&lt;BR /&gt;*Aug 27 15:22:06.380: RADIUS: Retransmit to (10.203.158.13:1812,1813) for id 1645/10&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch#show aaa servers&lt;/P&gt;
&lt;P&gt;RADIUS: id 1, priority 1, host 10.203.158.13, auth-port 1812, acct-port 1813&lt;BR /&gt; State: current UP, duration 1125s, previous duration 0s&lt;BR /&gt; Dead: total time 1257s, count 3&lt;BR /&gt; Quarantined: No&lt;BR /&gt; Authen: request 48, timeouts 48, failover 0, retransmission 36&lt;BR /&gt; Response: accept 0, reject 0, challenge 0&lt;BR /&gt; Response: unexpected 0, server error 0, incorrect 0, time 0ms&lt;BR /&gt; Transaction: success 0, failure 12&lt;BR /&gt; Throttled: transaction 0, timeout 0, failure 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have double checked the config on switch and on ISE. Radius live logs on ISE doesn't show anything. Besides packet capture is there anything else I&amp;nbsp;could check?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 15:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695629#M494852</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-08-27T15:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695632#M494853</link>
      <description>Hi,&lt;BR /&gt;Have you defined the switch as a Network Access Device in ISE?</description>
      <pubDate>Mon, 27 Aug 2018 16:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695632#M494853</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-27T16:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695634#M494854</link>
      <description>&lt;P&gt;Yes I definitely have, and enabled radius authentication settings with shared secret&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 16:09:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695634#M494854</guid>
      <dc:creator>Madura Malwatte</dc:creator>
      <dc:date>2018-08-27T16:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695637#M494855</link>
      <description>If you run tcpdump on ISE do you see the incoming radius request from the switch?</description>
      <pubDate>Mon, 27 Aug 2018 16:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695637#M494855</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-27T16:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695669#M494856</link>
      <description>&lt;P&gt;Unless you have the RADIUS on the switch configured to do proactive testing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;radius serve&amp;nbsp;&amp;lt;NAME&amp;gt;&lt;BR /&gt; address ipv4&amp;nbsp;&amp;lt;IP&amp;gt; auth-port 1812 acct-port 1813&lt;BR /&gt; key 0&amp;nbsp;&amp;lt;key&amp;gt;&lt;BR /&gt; automate-tester username SW-Radius-Test ignore-acct-port idle-time 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then the only way the switch will know it is down is for active authentication sessions.&amp;nbsp; If this is a test switch, do you have active authentications happening or just trying your test command?&amp;nbsp; The RADIUS settings determine failure and dead time:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server deadtime 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have those properly configured?&amp;nbsp; You can see from "show aaa servers" that the switch did mark it dead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dead: total time 1257s, count 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am guessing you don't have your deadtime cranked up to 10 minutes like I show above.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 17:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695669#M494856</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-27T17:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Radius timing out to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695786#M494857</link>
      <description>&lt;P&gt;If ISE LiveLogs are showing nothing then you have a more fundamental reachability issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you ping the ISE PSN(s) from the switch using the same IP configured as the RADIUS source IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If ping works, is there still a firewall blocking ports 1812/1813?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is no firewall, I suggest calling TAC for deeper troubleshooting.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 20:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-timing-out-to-ise/m-p/3695786#M494857</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2018-08-27T20:14:10Z</dc:date>
    </item>
  </channel>
</rss>

