<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - TrustSec errors in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3944445#M496959</link>
    <description>Please work through tac&lt;BR /&gt;</description>
    <pubDate>Mon, 21 Oct 2019 10:36:38 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-10-21T10:36:38Z</dc:date>
    <item>
      <title>ISE - TrustSec errors</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3940375#M496938</link>
      <description>&lt;DIV class="sn-card-component sn-card-component_first sn-card-component_meta sn-card-component_meta_sibling"&gt;&lt;DIV class="sn-card-component-avatar sn-avatar_xs sn-avatar_v2"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="sn-card-component sn-card-component_first sn-card-component_meta"&gt;&lt;DIV class="date-calendar"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="sn-card-component sn-card-component_summary sn-card-component_summary_spacing"&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&lt;SPAN class="sn-widget-textblock-body sn-widget-textblock-body_formatted"&gt;Last week we had one of our 6807XL crash on Thursday 10/10 (case # SR 687680740). As we were troubleshooting the issue with the 6807XL, we noticed some issues with ISE and WLC cluster not coming back up correctly after the crash.&amp;nbsp;We have noticed event logs that are showing TrustSec errors communicating back to ISE. Can anyone advise on how to troubleshoot these specific errors? Any assistance would be greatly appreciated&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="sn-widget sn-widget-textblock state-expanded"&gt;&lt;SPAN class="sn-widget-textblock-body sn-widget-textblock-body_formatted"&gt;&lt;BR /&gt;Oct 14 13:37:16.181: %CTS-SW2-3-SXP_CONN_STATE_CHG_OFF: Connection &amp;lt;10.11.1.240, 10.99.3.2&amp;gt;-1 state changed from Pending_On to Off.&lt;BR /&gt;Oct 14 13:39:16.182: %CTS-SW2-3-SXP_CONN_STATE_CHG_OFF: Connection &amp;lt;10.11.1.240, 10.99.3.2&amp;gt;-1 state changed from Pending_On to Off.&lt;BR /&gt;Oct 14 13:41:16.183: %CTS-SW2-3-SXP_CONN_STATE_CHG_OFF: Connection &amp;lt;10.11.1.240, 10.99.3.2&amp;gt;-1 state changed from Pending_On to Off.&lt;BR /&gt;Oct 14 13:43:16.235: %CTS-SW2-3-SXP_CONN_STATE_CHG_OFF: Connection &amp;lt;10.11.1.240, 10.99.3.2&amp;gt;-1 state changed from Pending_On to Off.&lt;BR /&gt;&lt;BR /&gt;There is ALSO errors on 67 DHCP on the core…this may need digging into as well…the SGTs change with these errors:&lt;BR /&gt;permit udp 67&lt;BR /&gt;^&lt;BR /&gt;% Invalid input detected at '^' marker.&lt;BR /&gt;&lt;BR /&gt;Oct 14 13:48:54.738: %RBM-SW2-3-RBM_PARSE_ACE: Could not parse command for adding ACE 'permit udp 67' to IP Role-Based Access List 'Deny_All-80'&lt;BR /&gt;Oct 14 13:48:54.738: %CTS-SW2-3-AUTHZ_POLICY_SGACL_ACE_FAILED: Failed to install IP SGACL 'Deny_All-80' for SGT=292:EW189 due to ACE 'permit udp 67' error&lt;BR /&gt;Oct 14 13:48:54.785: %RBM-SW1_STBY-3-RBM_PARSE_CMD: Could not parse command. See command output and errors below&lt;BR /&gt;&lt;BR /&gt;permit udp 67&lt;BR /&gt;^&lt;BR /&gt;% Invalid input detected at '^' marker.&lt;BR /&gt;&lt;BR /&gt;Oct 14 13:48:54.785: %RBM-SW1_STBY-3-RBM_PARSE_ACE: Could not parse command for adding ACE 'permit udp 67' to IP Role-Based Access List 'Deny_All-80'&lt;BR /&gt;Oct 14 13:48:54.785: %CTS-SW1_STBY-3-AUTHZ_POLICY_SGACL_ACE_FAILED: Failed to install IP SGACL 'Deny_All-80' for SGT=292:EW189 due to ACE 'permit udp 67' error&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:10:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3940375#M496938</guid>
      <dc:creator>Quintin.Mayo</dc:creator>
      <dc:date>2020-02-21T19:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - TrustSec errors</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3940857#M496946</link>
      <description>For the DHCP SGACL try changing the syntax to: permit udp dst eq 67&lt;BR /&gt;For the sxp connection error, has anything changed in regard to comms between ISE and your device? Firewall? SVI ACL?&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Oct 2019 12:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3940857#M496946</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-10-15T12:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - TrustSec errors</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3944445#M496959</link>
      <description>Please work through tac&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Oct 2019 10:36:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-trustsec-errors/m-p/3944445#M496959</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-10-21T10:36:38Z</dc:date>
    </item>
  </channel>
</rss>

