<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.4 not getting radius username in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3698851#M497049</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am using ISE 2.4, ASA and Network monitor tool.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For user authentication from ASA and NM tool, Radius is used. Issue is ISE not getting username of Radius authentication in the radius logs.&lt;/P&gt;
&lt;P&gt;In the radius live log, there is no username in the column, it plainly shows username only.&amp;nbsp;PFA error screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have added ASA and NM tool as devices in the ISE and enabled Radius authentication. Any idea why this is happening?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Event&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;5405 RADIUS Request dropped&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Failure Reason&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;24616 RADIUS token identity store received timeout error&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;Check that the RADIUS token server is configured correctly. Check that the network connection is working. Try to ping the RADIUS token server to verify that it is available. Check that the RADIUS token server is enabled and running.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Root cause&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;RADIUS token identity store received timeout error&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 19:01:41 GMT</pubDate>
    <dc:creator>manvik</dc:creator>
    <dc:date>2020-02-21T19:01:41Z</dc:date>
    <item>
      <title>ISE 2.4 not getting radius username</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3698851#M497049</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am using ISE 2.4, ASA and Network monitor tool.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For user authentication from ASA and NM tool, Radius is used. Issue is ISE not getting username of Radius authentication in the radius logs.&lt;/P&gt;
&lt;P&gt;In the radius live log, there is no username in the column, it plainly shows username only.&amp;nbsp;PFA error screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have added ASA and NM tool as devices in the ISE and enabled Radius authentication. Any idea why this is happening?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Event&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;5405 RADIUS Request dropped&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Failure Reason&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;24616 RADIUS token identity store received timeout error&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;Check that the RADIUS token server is configured correctly. Check that the network connection is working. Try to ping the RADIUS token server to verify that it is available. Check that the RADIUS token server is enabled and running.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Root cause&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-weight: 400;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: 400;"&gt;RADIUS token identity store received timeout error&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3698851#M497049</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2020-02-21T19:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 not getting radius username</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3698930#M497050</link>
      <description>&lt;P&gt;Your PingFederate Token Server does not appear to be responding in a timely manner when ISE passes it the token for authentication and therefore the whole RADIUS transaction times out. It should be returning a failure response immediately for USERNAME:TOKEN. This is an entirely separate issue from passing the correct USERNAME to the token server in the first place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the &amp;lt;USERNAME&amp;gt; problem, I suggest you compare your ASA RADIUS configuration to one of our guides like&amp;nbsp; &lt;A href="http://cs.co/ise-guides" target="_blank" rel="nofollow noopener noreferrer"&gt;ISE Design &amp;amp; Integration Guides&lt;/A&gt; &amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/ise-design-amp-integration-guides/ta-p/3621164#toc-hId-1282659010" rel="nofollow noopener noreferrer" target="_blank"&gt;Cisco Adaptive Security Appliance (ASA)&lt;/A&gt; &amp;gt; &lt;A href="https://community.cisco.com/t5/security-documents/how-to-configure-posture-with-anyconnect-compliance-module-and/ta-p/3647768" target="_blank"&gt;How To Configure Posture with AnyConnect Compliance Module and ISE 2.0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For deeper troubleshooting, I suggest you call TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 19:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3698930#M497050</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2018-08-31T19:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 not getting radius username</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3699114#M497051</link>
      <description>Thank You Thomas,&lt;BR /&gt;You are right, PingFederate  is not responding. We tested it with a working NAC server.&lt;BR /&gt;We need to figure our the USERNAME problem still.</description>
      <pubDate>Sat, 01 Sep 2018 07:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3699114#M497051</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2018-09-01T07:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 not getting radius username</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3699190#M497052</link>
      <description>&lt;P&gt;ISE 2.4 is masking username for most of the failed authentications to meet one of&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/about/security-center/security-programs/secure-development-lifecycle/sdl-process.html#psr" target="_blank"&gt;Product Security Requirements&lt;/A&gt;. We have an existing enhancement request --&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CSCvh91118&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 17:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3699190#M497052</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-01T17:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 not getting radius username</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3700202#M497053</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;We are using pingfederate as external server for radius authentication. Logs in pingfederate we are getting is "Ignoring packet from unknown client". ISE IP is added in pingfederate.&lt;/P&gt;
&lt;P&gt;In ISE, pingfederate IP is added as external radius server and a radius server sequence is called in the ISE policy set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 08:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-not-getting-radius-username/m-p/3700202#M497053</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2018-09-04T08:41:28Z</dc:date>
    </item>
  </channel>
</rss>

