<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA Device Administration is not working with Policy node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724152#M495243</link>
    <description>&lt;P&gt;Good Morning,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I encountered the following problem with my ISE 2.3 installation regarding Device Administration. When ich configure the primary or secondary node for AAA everything works fine, Tacacs Auth, aso. When I replace the primary and/or secondary node with a policy node no AAA is working any more.&lt;/P&gt;
&lt;P&gt;My first guess was ACL and/or Firewall, but none of them. I place a plain switch with only AAA on it in the same network where a policy node is located and it worked with the primary and/or secondary node. But again not with the policy node. I even can't see anything on the TACACS live log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current installation is based on five physical ISE servers in a distributed deployment. The machines are installed and configure like this (see attached Files):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SFLAISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Administration, Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SFLAISE02&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Administration, Monitoring, Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SCPHISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHAMISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHAISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A Device Administration licence is availabled (see attached file)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've no idea why the policy node is not handling AAA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any help.&lt;/P&gt;
&lt;P&gt;Kai&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Oct 2018 06:44:58 GMT</pubDate>
    <dc:creator>kai.onken</dc:creator>
    <dc:date>2018-10-12T06:44:58Z</dc:date>
    <item>
      <title>AAA Device Administration is not working with Policy node</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724152#M495243</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I encountered the following problem with my ISE 2.3 installation regarding Device Administration. When ich configure the primary or secondary node for AAA everything works fine, Tacacs Auth, aso. When I replace the primary and/or secondary node with a policy node no AAA is working any more.&lt;/P&gt;
&lt;P&gt;My first guess was ACL and/or Firewall, but none of them. I place a plain switch with only AAA on it in the same network where a policy node is located and it worked with the primary and/or secondary node. But again not with the policy node. I even can't see anything on the TACACS live log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The current installation is based on five physical ISE servers in a distributed deployment. The machines are installed and configure like this (see attached Files):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SFLAISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Administration, Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SFLAISE02&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Administration, Monitoring, Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SCPHISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHAMISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SHAISE01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Service with Session and Device Administration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A Device Administration licence is availabled (see attached file)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've no idea why the policy node is not handling AAA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any help.&lt;/P&gt;
&lt;P&gt;Kai&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 06:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724152#M495243</guid>
      <dc:creator>kai.onken</dc:creator>
      <dc:date>2018-10-12T06:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Device Administration is not working with Policy node</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724292#M495244</link>
      <description>&lt;P&gt;make sure you have the following setup correctly:&lt;/P&gt;
&lt;P&gt;on devices you are point to PSN ip addresses and not the PANs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are using mgmt interfaces these will be in a vrf. you need to use&amp;nbsp;ip vrf forwarding Mgmt-vrf under aaa group server&lt;/P&gt;
&lt;P&gt;You have correctly setup NADs on the ISE with TACACS ticked and matching key.&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 11:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724292#M495244</guid>
      <dc:creator>tasneemjan</dc:creator>
      <dc:date>2018-10-12T11:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Device Administration is not working with Policy node</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724294#M495245</link>
      <description>&lt;P&gt;Hello Tasneemjan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to your topics:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure you have the following setup correctly:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1. On devices you are point to PSN ip addresses and not the PANs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; When I use the PAN IP's it works&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; When I use the PSN IP's its not working&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. If you are using mgmt interfaces these will be in a vrf. You need to use&amp;nbsp;ip vrf forwarding Mgmt-vrf under aaa group server&lt;/P&gt;
&lt;P&gt;&amp;nbsp; You are right, but I'm using in bound management&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. You have correctly setup NADs on the ISE with TACACS ticked and matching key.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Please see Topic 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Kai&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 11:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3724294#M495245</guid>
      <dc:creator>kai.onken</dc:creator>
      <dc:date>2018-10-12T11:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Device Administration is not working with Policy node</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3732859#M495246</link>
      <description>&lt;P&gt;A couple of things you may try:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check whether the PSNs are listening on port 49 by CLI "show port" and from another machine "telnet &amp;lt;PSN-IP&amp;gt; 49"&lt;/LI&gt;
&lt;LI&gt;Take packet capture between NAD and PSN&lt;/LI&gt;
&lt;LI&gt;Enable DEBUG on Runtime-AAA and check debug log prrt-server.log&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If that not giving any clues, please engage Cisco TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 15:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-device-administration-is-not-working-with-policy-node/m-p/3732859#M495246</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-25T15:29:52Z</dc:date>
    </item>
  </channel>
</rss>

