<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Blocked On:  AAA Not Ready&amp;quot; Status on Switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459854#M528384</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kashyap,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What is the switch platform and software version?&lt;/LI&gt;&lt;LI&gt;What does the 'show aaa servers' command show? &lt;/LI&gt;&lt;LI&gt;*92.92ea endpoint on Gi 1/0/12 seems to be authenticated successfully, don't you see it under ISE live sessions?&lt;/LI&gt;&lt;LI&gt;Do you have TAC case open for this?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jul 2017 00:01:07 GMT</pubDate>
    <dc:creator>hariholla</dc:creator>
    <dc:date>2017-07-20T00:01:07Z</dc:date>
    <item>
      <title>"Blocked On:  AAA Not Ready" Status on Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459853#M528383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing authentication unknown status in swithc for some ports on a switch. The ISE server is up and on 2.1 version. See the screenshot below,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="191" src="https://community.cisco.com/legacyfs/online/fusion/109438_pastedImage_0.png" style="width: 427px; height: 191.461px;" width="427" /&gt;&lt;/P&gt;&lt;P&gt;when I check for the auth session details for one of the ports, it displyas "Blocked on: AAA Not Ready" error. and on ISE I am seeing logs only for port g1/0/10. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jive-image image-2" height="418" src="https://community.cisco.com/legacyfs/online/fusion/109439_pastedImage_1.png" style="width: 350px; height: 417.742px;" width="350" /&gt;&lt;/P&gt;&lt;P&gt;As this switch is in production so I can not bounce the port without a request and approval.&lt;/P&gt;&lt;P&gt;Therefore what would be the possible reason for this error and how to resolve it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help on this is highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kashyap&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jul 2017 18:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459853#M528383</guid>
      <dc:creator>kachavda</dc:creator>
      <dc:date>2017-07-19T18:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: "Blocked On:  AAA Not Ready" Status on Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459854#M528384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kashyap,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;What is the switch platform and software version?&lt;/LI&gt;&lt;LI&gt;What does the 'show aaa servers' command show? &lt;/LI&gt;&lt;LI&gt;*92.92ea endpoint on Gi 1/0/12 seems to be authenticated successfully, don't you see it under ISE live sessions?&lt;/LI&gt;&lt;LI&gt;Do you have TAC case open for this?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jul 2017 00:01:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459854#M528384</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2017-07-20T00:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: "Blocked On:  AAA Not Ready" Status on Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459855#M528385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hari, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see my answers below,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1. What is the switch platform and software version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The switch platform is "WS-C3850-24P" and a version is 03.07.00E. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2. What does the 'show aaa servers' command show?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="249" src="https://community.cisco.com/legacyfs/online/fusion/109571_pastedImage_8.png" style="width: 317px; height: 248.998px;" width="317" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3. *92.92ea endpoint on Gi 1/0/12 seems to be authenticated successfully, don't you see it under ISE live sessions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I could see a session on port g1/0/12 for *92.92ea MAC. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4. Do you have TAC case open for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have not opened up a case yet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kashyap Chavda &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jul 2017 16:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459855#M528385</guid>
      <dc:creator>kachavda</dc:creator>
      <dc:date>2017-07-20T16:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: "Blocked On:  AAA Not Ready" Status on Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459856#M528386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kashyap,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I shared this case with a friend of mine who is a developer, and he said you seem to be running in to CSCuu66531 (internal defect). The defect details are not publicly available now, since it is not release-noted or associated to a TAC case. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AAA not ready state is potentially a memory leak issue which happens on some random trigger, thats unknown. The issue however is fixed in the 03.07.03E version or later. The only workaround known for now (apart from a switch reload) is to disable aaa system accounting with the “aaa accounting system” global command. Note, this does not disable dot1x/mab accounting for endpoints, however will disable system level aaa accounting that appears during a switch boot up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I suggest you open a Cisco TAC case, so that you get formal instructions on how to proceed on this issue. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jul 2017 03:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459856#M528386</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2017-07-21T03:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: "Blocked On:  AAA Not Ready" Status on Switch</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459857#M528387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hari for helping on this issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jul 2017 14:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-blocked-on-aaa-not-ready-quot-status-on-switch/m-p/3459857#M528387</guid>
      <dc:creator>kachavda</dc:creator>
      <dc:date>2017-07-21T14:21:13Z</dc:date>
    </item>
  </channel>
</rss>

