<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5405 RADIUS Request Dropped in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579471#M517952</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be not same issue with me because my RADIUS shared secret just common character.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 08 Jul 2018 06:12:00 GMT</pubDate>
    <dc:creator>Nitipat Dilokwattanakoon</dc:creator>
    <dc:date>2018-07-08T06:12:00Z</dc:date>
    <item>
      <title>5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579466#M517947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I am pulling my hair out (well I really don't have hair left) on an issue that I am sure I am missing something obvious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;I am testing wireless SSIDs against ISE, something I have done 100s of times.&amp;nbsp; I have a guest SSID working just fine against the deployment but on my 802.1x SSIDs I am getting the following in the logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;11001 Received RADIUS Access-Request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp; 11017 RADIUS created a new session&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&amp;nbsp; 5405 RADIUS Request dropped&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;There is no reason for the request being dropped.&amp;nbsp; It is not even trying to match one of my policy sets, just dropping the RADIUS request.&amp;nbsp; I know because the guest SSID works on the same controller the Shared Secrets and ISE network device &lt;/SPAN&gt;definitions are working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure I am missing something obvious, but can't see it.&amp;nbsp; I saw the same thing with the customer on their APIC-EM RADIUS authentications being dropped with no apparent reason why.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 20:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579466#M517947</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-02-08T20:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579467#M517948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The built-in Cisco NAD profile does not check password for MAB so it possible to work with wrong shared secret. Other than that, we need Runtime-AAA in DEBUG and check prrt-server.log.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-02-08 at 5.50.47 PM.png" class="image-1 jive-image" height="235" src="/legacyfs/online/fusion/115113_Screen Shot 2018-02-08 at 5.50.47 PM.png" style="height: 235.16129032258064px; width: 324px;" width="324" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 01:53:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579467#M517948</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-09T01:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: 5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579468#M517949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow there is nothing more in the log files either at debug mode.  At least nothing I see obvious.  I am fighting two RADIUS request dropped issues.   The one I can easily reproduce remotely is APIC-EM RADIUS authentication for GUI access.  No matter what I try I get RADIUS request drops.  ISE shows all the details of the network device in the details of the record so I know it is matching the right network device.  I tried putting in the wrong shared secret in purpose and it still just says RADIUS request drop.  The prrt server logs don’t show much detail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AcsLogs,2018-02-08 21:35:39,442,DEBUG,0x7fc23c60b700,cntx=0000252715,sesn=MASV-ISE-PSN/307501790/27367,Formatter got 1676 attributes,MessageFormatter.cpp:150&lt;/P&gt;&lt;P&gt;AcsLogs,2018-02-08 21:35:39,442,DEBUG,0x7fc23c60b700,cntx=0000252715,sesn=MASV-ISE-PSN/307501790/27367,Duplicate pair: attr = NetworkDeviceName value = MAS-APIC-EM,MessageFormatter.cpp:394&lt;/P&gt;&lt;P&gt;AcsLogs,2018-02-08 21:35:39,442,DEBUG,0x7fc23c60b700,cntx=0000252715,sesn=MASV-ISE-PSN/307501790/27367,Log_Message=[2018-02-08 21:35:39.442 -05:00 0000437894 5405 NOTICE Failed-Attempt: RADIUS Request dropped, ConfigVersionId=13, Device IP Address=10.201.41.0, Device Port=33585, DestinationIPAddress=10.201.9.10, DestinationPort=1812, Protocol=Radius, NetworkDeviceName=MAS-APIC-EM, User-Name=phaferman, NAS-Identifier=b1c6c99d-d1da-493f-a693-60d77239fbd5, NetworkDeviceProfileName=Dart_Cisco_Customized, NetworkDeviceProfileId=f0628b3b-95af-4db4-b4ca-e72657d38595, AcsSessionID=MASV-ISE-PSN/307501790/27367, Step=11001, Step=11017, Step=5405, NetworkDeviceGroups=Location#All Locations#Mason DC, NetworkDeviceGroups=Device Type#All Device Types#Servers#APIC-EM, NetworkDeviceGroups=IPSEC#Is IPSEC Device#No, NetworkDeviceGroups=ISE Phase#ISE Phase#Auth, DTLSSupport=Unknown, Network Device Profile=Dart_Cisco_Customized, Location=Location#All Locations#Mason DC, Device Type=Device Type#All Device Types#Servers#APIC-EM, IPSEC=IPSEC#Is IPSEC Device#No, ISE Phase=ISE Phase#ISE Phase#Auth, ],MessageFormatter.cpp:94&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put a customized device profile to see if turning off some of the attributes would help, but so far it hasn’t.  I guess I will have to open a TAC case and see if they can get more data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the feedback Hsing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 02:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579468#M517949</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-02-09T02:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579469#M517950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you find anything from TAC?&lt;/P&gt;&lt;P&gt;I got same problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 02:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579469#M517950</guid>
      <dc:creator>Nitipat Dilokwattanakoon</dc:creator>
      <dc:date>2018-07-08T02:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: 5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579470#M517951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think if I remember right it was odd characters in the RADIUS shared secret that caused some devices to not work correctly.&amp;nbsp; Are you just having the issue from APIC-EM or from something else?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 05:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579470#M517951</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-07-08T05:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: 5405 RADIUS Request Dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579471#M517952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be not same issue with me because my RADIUS shared secret just common character.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 06:12:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/5405-radius-request-dropped/m-p/3579471#M517952</guid>
      <dc:creator>Nitipat Dilokwattanakoon</dc:creator>
      <dc:date>2018-07-08T06:12:00Z</dc:date>
    </item>
  </channel>
</rss>

