<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE / CTS switch Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103019#M561200</link>
    <description>&lt;P&gt;See this duplicate post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462" target="_self"&gt;https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jun 2020 23:13:11 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-06-14T23:13:11Z</dc:date>
    <item>
      <title>Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4100387#M561083</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Recently noticed a strange issue with a few switches in our network.&lt;/P&gt;&lt;P&gt;Using SGT/CTS with ISE 2.4.&lt;/P&gt;&lt;P&gt;Switches are 9200 series, working ok until several switches started to show an error with CTS server info list I.E. marking the ISE servers as down?&lt;/P&gt;&lt;P&gt;2 switch outputs below (sw1 not working, sw2 working). The switches have the same config and in the same location, able to refresh env data and also PAC files on both switches without error.&lt;/P&gt;&lt;P&gt;The only difference I can see is info output for TAG 0:Unknown&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The working switch shows "status alive" with auto-test=false?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The none working switch shows&amp;nbsp;"status dead" with auto-test=true?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain this auto-test feature please.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Output for sw1 (error switch):&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;SW1#sh cts environment-data&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;SGT tag = 2-01:Infrastructure&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0004, 2 server(s):&lt;BR /&gt;&amp;nbsp;*Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = DEAD&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;&amp;nbsp;*Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = DEAD&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0-01:Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2-01:Infrastructure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3-00:Network_Services&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4-00:Employees&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Output for sw2 (working switch):&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;SW2#sh cts environment-data&lt;/STRONG&gt;&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;SGT tag = 2-01:Infrastructure&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0004, 2 server(s):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = ALIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = FALSE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = ALIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = FALSE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0-03:Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2-01:Infrastructure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3-00:Network_Services&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4-00:Employees&lt;/DIV&gt;&lt;DIV&gt;Appreciate any help on this, not sure if its a bug or not.&lt;/DIV&gt;&lt;DIV&gt;Cheers,&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 20:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4100387#M561083</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-09T20:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4100388#M561084</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Quick update:&lt;/STRONG&gt; After a reboot on sw1# (No config change at all) the switch is now making the ISE servers as "alive" when I do sw1#show cts env data?&lt;/P&gt;&lt;P&gt;What is causing the switch to previously report the severs as "dead"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reboot and the issue disappears but for how long is the question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could this be an auth time type loop issue?&lt;/P&gt;&lt;P&gt;If anyone has a working CTS config and willing to post that would be great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 21:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4100388#M561084</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-09T21:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102528#M561173</link>
      <description>&lt;P&gt;Sounds like a switch bug since a reboot fixed it.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 22:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102528#M561173</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-06-12T22:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103019#M561200</link>
      <description>&lt;P&gt;See this duplicate post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462" target="_self"&gt;https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 23:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103019#M561200</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-06-14T23:13:11Z</dc:date>
    </item>
  </channel>
</rss>

