<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE error messages in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557663#M538550</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works with a different device. There is something filtering the message from reaching Fortinet.&lt;/P&gt;&lt;P&gt;Thanks for the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nimmi MP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jun 2016 09:59:00 GMT</pubDate>
    <dc:creator>nimmi.phasil</dc:creator>
    <dc:date>2016-06-23T09:59:00Z</dc:date>
    <item>
      <title>ISE error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557660#M538547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am authenticating Fortinet with ISE . While ISE successfully authenticates fortinet&amp;nbsp; ,the authentication reply is not reaching Fortinet firewall.&lt;/P&gt;&lt;P&gt;The firewall can ping ISE.&lt;/P&gt;&lt;P&gt;Following is the tcpdump messages. 210.18.5.70 is the fortinet firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background: yellow;"&gt;210.18.5.70.sify.net.blackjack &amp;gt; ISE.radius: RADIUS, length: 101&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Access Request (1), id: 0x5b, Authenticator: 2edd47c7cb141a1488ece685ed655f6e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; NAS ID Attribute (32), length: 18, Value: FGT60C3G11032050&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; Username Attribute (1), length: 10, Value: fortinet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; Password Attribute (2), length: 18, Value: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; Accounting Session ID Attribute (44), length: 10, Value: 2c4fc294&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; Connect Info Attribute (77), length: 13, Value: admin-login&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt; Vendor Specific Attribute (26), length: 12, Value: Vendor: Unknown (12356)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vendor Attribute: 3, Length: 4, Value: root&lt;/SPAN&gt;&lt;/P&gt;&lt;OL style="list-style-type: upper-roman;"&gt;&lt;LI&gt;&lt;SPAN style="background: yellow;"&gt;ISE.radius &amp;gt; 210.18.5.70.sify.net.blackjack:&lt;/SPAN&gt; RADIUS, length: 218&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Access Accept (2), id: 0x5b, Authenticator: 205dabbc626b00d9b8d58e3a7a9e5bc5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Username Attribute (1), length: 10, Value: fortinet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service Type Attribute (6), length: 6, Value: Login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State Attribute (24), length: 67, Value: ReauthSession:ac1f01092H_GB3Ax4qI/2pYtcAtlpw9f1j3REGu8rBwJbaJ_8Xs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class Attribute (25), length: 78, Value: CACS:ac1f01092H_GB3Ax4qI/2pYtcAtlpw9f1j3REGu8rBwJbaJ_8Xs:ISE/253643487/93219&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vendor Specific Attribute (26), length: 18, Value: Vendor: Unknown (12356)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vendor Attribute: 1, Length: 10, Value: test-group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vendor Specific Attribute (26), length: 19, Value: Vendor: Unknown (12356)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vendor Attribute: 6, Length: 11, Value: super_admin&lt;/P&gt;&lt;P&gt;09:45:49.178300 IP (tos 0x0, ttl 252, id 1838, offset 0, flags [none], proto ICMP (1), length 56)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="background: yellow;"&gt;segment-119-227.sify.net &amp;gt; ISE: ICMP host 210.18.5.70.sify.net unreachable - admin prohibited filter, length 36&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;ISE.radius &amp;gt; 210.18.5.70.sify.net.blackjack: [|radius]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;Nimmi&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2016 11:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557660#M538547</guid>
      <dc:creator>nimmi.phasil</dc:creator>
      <dc:date>2016-06-22T11:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557661#M538548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nimmi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said the firewall can ping ISE but the RADIUS response is still failing. This sounds like a firewall configuration problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see our &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/install_guide/b_ise_InstallationGuide21/b_ise_InstallationGuide21_appendix_0110.html"&gt;&lt;STRONG&gt;Cisco ISE Ports Reference&lt;/STRONG&gt;&lt;/A&gt; for the various ports that must be opened in the ISE architecture for different features/capabilities. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For RADIUS between ISE and your network access devices (assuming you do not change from the default ports) you will need to open:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;RADIUS Authentication: UDP/1645, 1812&lt;/LI&gt;&lt;LI&gt;RADIUS Accounting: UDP/1646, 1813&lt;/LI&gt;&lt;LI&gt;RADIUS Change of Authorization (CoA) Send: UDP/1700&lt;/LI&gt;&lt;LI&gt;RADIUS Change of Authorization (CoA) Listen/Relay: UDP/1700, 3799&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: UDP port 3799 is not configurable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you continue to have firewall/connectivity problems, you will need to call the TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2016 15:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557661#M538548</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-22T15:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557662#M538549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same ISE is doing radius authentication/authorization with other vendors like HP , Cisco . &lt;/P&gt;&lt;P&gt;Also , the authentication is successful in the ISE server. The problem is the response message is not reaching fortinet firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nimmi MP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2016 05:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557662#M538549</guid>
      <dc:creator>nimmi.phasil</dc:creator>
      <dc:date>2016-06-23T05:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557663#M538550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works with a different device. There is something filtering the message from reaching Fortinet.&lt;/P&gt;&lt;P&gt;Thanks for the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nimmi MP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2016 09:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557663#M538550</guid>
      <dc:creator>nimmi.phasil</dc:creator>
      <dc:date>2016-06-23T09:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE error messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557664#M538552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The response from ISE is being blocked by this device: segment-119-227.sify.net.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2016 19:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-error-messages/m-p/3557664#M538552</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2016-06-23T19:30:46Z</dc:date>
    </item>
  </channel>
</rss>

