<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Weird error in profile download during onbording in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518619#M505056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;I am configuring BYOD flow in my lab with the following details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Wired scenario (the flow and everything was working well with previous version of ISE, so I assume the switch configuration is ok.&lt;/P&gt;&lt;P&gt;2) I have upgraded to ISE 2.4 and rebuilding the configuration there&lt;/P&gt;&lt;P&gt;3) My ISE is dual homed. Admin access on eth0, and RADIUS on eth1.&lt;/P&gt;&lt;P&gt;4) User is logging on guest portal with AD account and from there redirected to onboarding&lt;/P&gt;&lt;P&gt;5) I have enabled all the portals only on eth1&lt;/P&gt;&lt;P&gt;6) When I go through the flow I get to run the NSA portal fine, but then I have a message that I fail downloading the profile, and it seems that the problem is in setting up the https connection from the message I have on the client log file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="debug.jpg" class="image-1 jive-image" height="84" src="https://community.cisco.com/legacyfs/online/fusion/117028_debug.jpg" style="height: 84.862px; width: 818px;" width="817" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried with IP address and FWDN in the redirection, and both have issues.&lt;/P&gt;&lt;P&gt;I have imported the root CA signing the ISE cert in the client trust store&lt;/P&gt;&lt;P&gt;The time client to ISE is in sync.&lt;/P&gt;&lt;P&gt;The PSN Certificates contains the FQDN and and IP address i the SAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea on how to proceed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2018 14:52:45 GMT</pubDate>
    <dc:creator>martucci</dc:creator>
    <dc:date>2018-05-11T14:52:45Z</dc:date>
    <item>
      <title>Weird error in profile download during onbording</title>
      <link>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518619#M505056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;I am configuring BYOD flow in my lab with the following details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Wired scenario (the flow and everything was working well with previous version of ISE, so I assume the switch configuration is ok.&lt;/P&gt;&lt;P&gt;2) I have upgraded to ISE 2.4 and rebuilding the configuration there&lt;/P&gt;&lt;P&gt;3) My ISE is dual homed. Admin access on eth0, and RADIUS on eth1.&lt;/P&gt;&lt;P&gt;4) User is logging on guest portal with AD account and from there redirected to onboarding&lt;/P&gt;&lt;P&gt;5) I have enabled all the portals only on eth1&lt;/P&gt;&lt;P&gt;6) When I go through the flow I get to run the NSA portal fine, but then I have a message that I fail downloading the profile, and it seems that the problem is in setting up the https connection from the message I have on the client log file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="debug.jpg" class="image-1 jive-image" height="84" src="https://community.cisco.com/legacyfs/online/fusion/117028_debug.jpg" style="height: 84.862px; width: 818px;" width="817" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried with IP address and FWDN in the redirection, and both have issues.&lt;/P&gt;&lt;P&gt;I have imported the root CA signing the ISE cert in the client trust store&lt;/P&gt;&lt;P&gt;The time client to ISE is in sync.&lt;/P&gt;&lt;P&gt;The PSN Certificates contains the FQDN and and IP address i the SAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea on how to proceed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 14:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518619#M505056</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2018-05-11T14:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Weird error in profile download during onbording</title>
      <link>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518620#M505058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can think of two things you might try to get more info:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;WireShark packet captures to ensure the TLS exchanges happening correctly.&lt;/LI&gt;&lt;LI&gt;DEBUG on ISE PSN and check the log files on the PSN.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 16:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518620#M505058</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-11T16:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Weird error in profile download during onbording</title>
      <link>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518621#M505060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please try restarting ISE services and trying it again. If it works, then it seems hitting CSCvj42833.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 02:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518621#M505060</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-14T02:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Weird error in profile download during onbording</title>
      <link>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518622#M505062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai, &lt;/P&gt;&lt;P&gt;thanks a lot.&lt;/P&gt;&lt;P&gt;At the end I found out that the problem was that my IE was configured to nly work with TLS 1.0 and not 1.1 or 1.2. Once I enabled them the profile was downloaded fine.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 09:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/weird-error-in-profile-download-during-onbording/m-p/3518622#M505062</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2018-05-14T09:34:48Z</dc:date>
    </item>
  </channel>
</rss>

