<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Persistence of failed endpoints/abandoned eap session between PSNs of the same Node group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479800#M526062</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are seeing this error on the second PSN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105106_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Mar 2017 15:44:50 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2017-03-03T15:44:50Z</dc:date>
    <item>
      <title>Persistence of failed endpoints/abandoned eap session between PSNs of the same Node group</title>
      <link>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479799#M526061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are doing some testing with F5 and PSNs.&lt;/P&gt;&lt;P&gt;Endpoint is abandoning eap sessions on one PSNs.&lt;/P&gt;&lt;P&gt;We clear the endpoint sessions on ISE Live sessions and also the persistence record on the PSN.&lt;/P&gt;&lt;P&gt;The F5 now sends the radius requests to the second on the same node group.&lt;/P&gt;&lt;P&gt;It seems that there is some stale entry on the PSNs in the same node group and the new PSN is rejecting this new radius request thinking that it already has a session. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Mar 2017 15:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479799#M526061</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-03T15:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Persistence of failed endpoints/abandoned eap session between PSNs of the same Node group</title>
      <link>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479800#M526062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are seeing this error on the second PSN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105106_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Mar 2017 15:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479800#M526062</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-03-03T15:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Persistence of failed endpoints/abandoned eap session between PSNs of the same Node group</title>
      <link>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479801#M526063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please ensure the sessions also cleared on the NAD. Then, enable the debug as recommended in the resolution. It would also help to perform packet captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a new RADIUS auth request comes into ISE, it has no Class attribute. Once ISE processes it, it gives Class attribute in the response and then NAD will use it subsequently as a means to tell ISE to continue with the same conversation. If ISE receives a RADIUS request with Class attribute but it does not have the session, it would respond with this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE node groups are used for the sessions in pending state (e.g. CWA or Posture) and ISE profiling. They have no influence on this matter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Mar 2017 17:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479801#M526063</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-03-06T17:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Persistence of failed endpoints/abandoned eap session between PSNs of the same Node group</title>
      <link>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479802#M526064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is perfect, thanks for your post. @&lt;SPAN class="font-color-meta" style="padding: 0 0 5px; font-size: 1.2em; font-family: arial; color: #8b8b8b;"&gt;&lt;SPAN class="replyToName" style="font-weight: inherit; font-style: inherit; font-size: 14.4px; font-family: inherit;"&gt;hslai &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Mar 2017 06:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/persistence-of-failed-endpoints-abandoned-eap-session-between/m-p/3479802#M526064</guid>
      <dc:creator>sofitapaul</dc:creator>
      <dc:date>2017-03-09T06:34:58Z</dc:date>
    </item>
  </channel>
</rss>

