<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE rected network device in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3177847#M554972</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I hope somebody can help.&lt;/P&gt;&lt;P&gt;We use Cisco ISE 2.1.&lt;/P&gt;&lt;P&gt;Normally new newtwork devices are simple created (IP, Name, Shared Secret, Group) and it works.&lt;/P&gt;&lt;P&gt;But our new Citrix Netscaler makes some problems.&lt;/P&gt;&lt;P&gt;The netscaler does not send any requests to ISE.&lt;/P&gt;&lt;P&gt;The netscaler hat a function called test, in a packet tracer I can see that ISE sends a reject back.&lt;/P&gt;&lt;P&gt;But citrix netscaler says sucessfully.&lt;/P&gt;&lt;P&gt;Is this normal that ISE sends a recect back in test szenario whout any username?&lt;/P&gt;&lt;P&gt;If the netscaler sends a request with username, ISE does not get any packet.&amp;nbsp;Citrix says&amp;nbsp;radius server does not support authentication functionality.&lt;/P&gt;&lt;P&gt;Can anybody help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks and greetings&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:33:10 GMT</pubDate>
    <dc:creator>Marco Serato</dc:creator>
    <dc:date>2020-02-21T18:33:10Z</dc:date>
    <item>
      <title>Cisco ISE rected network device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3177847#M554972</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I hope somebody can help.&lt;/P&gt;&lt;P&gt;We use Cisco ISE 2.1.&lt;/P&gt;&lt;P&gt;Normally new newtwork devices are simple created (IP, Name, Shared Secret, Group) and it works.&lt;/P&gt;&lt;P&gt;But our new Citrix Netscaler makes some problems.&lt;/P&gt;&lt;P&gt;The netscaler does not send any requests to ISE.&lt;/P&gt;&lt;P&gt;The netscaler hat a function called test, in a packet tracer I can see that ISE sends a reject back.&lt;/P&gt;&lt;P&gt;But citrix netscaler says sucessfully.&lt;/P&gt;&lt;P&gt;Is this normal that ISE sends a recect back in test szenario whout any username?&lt;/P&gt;&lt;P&gt;If the netscaler sends a request with username, ISE does not get any packet.&amp;nbsp;Citrix says&amp;nbsp;radius server does not support authentication functionality.&lt;/P&gt;&lt;P&gt;Can anybody help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks and greetings&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3177847#M554972</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2020-02-21T18:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE rected network device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3178186#M554973</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best thing to do here is to go to your ISE PAN node and perform a TCPDump and then share it with this forum. A packet capture says a thousand words!!!&amp;nbsp; Be sure to perform the TCPDump on the PSN node that the Netscaler is talking to, and taking care of which interface on the PSN (if&amp;nbsp;if have enable more than one interface)&lt;/P&gt;&lt;P&gt;Operations &amp;gt; Troubleshoot &amp;gt; Diagnostic Tools &amp;gt; TCP Dump&lt;/P&gt;&lt;P&gt;By default ISE will send an Access-Reject if the authentication didn't succeed.&amp;nbsp; This is just a setting and it makes logical sense.&amp;nbsp; There are cases where you want to send an Access-Accept in the case of a failed authentication (e.g. MAC auth for Guest WebAuth).&amp;nbsp; But I don't know what your use case it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE is probably sending back Access-Reject because the radius request was malformed.&amp;nbsp; i.e. it didn't contain a User-Name attribute (if I understand your problem?)&amp;nbsp;&amp;nbsp; I am a bit confused by your description.&lt;/P&gt;&lt;P&gt;Are you trying to implement a health monitor (health check) for the Netscaler?&amp;nbsp; What does the Access-Request from the Netscaler look like (please send us a wireshark of the conversation)&lt;/P&gt;&lt;P&gt;ISE needs to have the Netscaler configured as a NAD and of course Source IP of the Netscaler has to match (not the NAS-IP Address!!! The Netscaler's UDP packets'&amp;nbsp;&lt;STRONG&gt;Source IP&lt;/STRONG&gt; address !!!) - then of course usual stuff like shared secret have to match between Netscaler and ISE.&lt;/P&gt;&lt;P&gt;If it's a PAP authentication then make sure PAP is allowed protocol.&lt;/P&gt;&lt;P&gt;And then it's a matter of building an auth policy to validate the User-Name and Password from internal users perhaps?&lt;/P&gt;&lt;P&gt;And then create an Authorization Policy to send either Access-Accept or Access-Reject based on the AuthN that just passed.&amp;nbsp; All depends on what Netscaler expects as its preferred result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 23:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3178186#M554973</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-08-30T23:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE rected network device</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3178779#M554974</link>
      <description>&lt;P&gt;A trace was very helpful.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;Within the package it was seen that&lt;/SPAN&gt;&lt;/SPAN&gt; a not defined username was used. The username is fix in the test szenario an can not be changed (&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;not really useful&lt;/SPAN&gt;&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;In the ISE log this was not visible &lt;SPAN class="short_text"&gt;&lt;SPAN&gt;because of too many request.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;´Can I filter the ISE log field Network Device by IP Address?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;In our case I can only filter by device name like H_SWITCH.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 05:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-rected-network-device/m-p/3178779#M554974</guid>
      <dc:creator>Marco Serato</dc:creator>
      <dc:date>2017-09-01T05:10:55Z</dc:date>
    </item>
  </channel>
</rss>

