<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE / CTS switch Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103228#M561214</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;Damien,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Out of curiosity I did a sh run | inc cts on one of the edge switches (9200-L).&lt;/P&gt;&lt;P&gt;Did not see the user name of&amp;nbsp;&lt;SPAN&gt;"CTS-Test-Server", in fact don't see any user name for CTS?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SW1# sh run all | inc cts&lt;BR /&gt;cts server deadtime 20&lt;BR /&gt;cts server test all enable&lt;BR /&gt;cts server test all idle-time 60&lt;BR /&gt;cts server test all deadtime 20&lt;BR /&gt;no cts server key-wrap enable&lt;BR /&gt;cts authorization list iselist&lt;BR /&gt;no cts logging verbose&lt;BR /&gt;no cts sg-epg translation&lt;BR /&gt;no cts sxp enable&lt;BR /&gt;cts sxp retry period 120&lt;BR /&gt;cts sxp reconciliation period 120&lt;BR /&gt;no cts sxp log binding-changes&lt;BR /&gt;cts sxp mapping network-map 0&lt;BR /&gt;cts sxp speaker hold-time 120&lt;BR /&gt;cts sxp listener hold-time 90 180&lt;BR /&gt;cts sxp node-id 0&lt;BR /&gt;no cts sxp filter-enable&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts manual&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts manual&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based sgt-map sgt 2&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;cts role-based enforcement vlan-list 1-4094&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jun 2020 11:02:53 GMT</pubDate>
    <dc:creator>Jay233</dc:creator>
    <dc:date>2020-06-15T11:02:53Z</dc:date>
    <item>
      <title>Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462#M561136</link>
      <description>&lt;DIV class="lia-message-subject lia-component-message-view-widget-subject"&gt;&lt;DIV class="MessageSubject"&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Recently noticed a strange issue with a few switches in our network.&lt;/P&gt;&lt;P&gt;Using SGT/CTS with ISE 2.4.&lt;/P&gt;&lt;P&gt;Switches are 9200 series, working ok until several switches started to show an error with CTS server info list I.E. marking the ISE servers as down?&lt;/P&gt;&lt;P&gt;2 switch outputs below (sw1 not working, sw2 working). The switches have the same config and in the same location, able to refresh env data and also PAC files on both switches without error.&lt;/P&gt;&lt;P&gt;The only difference I can see is info output for TAG 0:Unknown&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The working switch shows "status alive" with auto-test=false?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The none working switch shows&amp;nbsp;"status dead" with auto-test=true?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain this auto-test feature please.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Output for sw1 (error switch):&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV&gt;SW1#sh cts environment-data&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;SGT tag = 2-01:Infrastructure&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0004, 2 server(s):&lt;BR /&gt;&amp;nbsp;*Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = DEAD&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;&amp;nbsp;*Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = DEAD&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0-01:Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2-01:Infrastructure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3-00:Network_Services&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4-00:Employees&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Output for sw2 (working switch):&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;SW2#sh cts environment-data&lt;/STRONG&gt;&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;SGT tag = 2-01:Infrastructure&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0004, 2 server(s):&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = ALIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = FALSE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;Server: 10.X.X.X, port 1812, A-ID C5E76EXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Status = ALIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;auto-test = FALSE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0-03:Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2-01:Infrastructure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3-00:Network_Services&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;4-00:Employees&lt;/DIV&gt;&lt;DIV&gt;Appreciate any help on this, not sure if its a bug or not.&lt;/DIV&gt;&lt;DIV&gt;Cheers,&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Jun 2020 11:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462#M561136</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-11T11:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101478#M561137</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Quick update:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;After a reboot on sw1# (No config change at all) the switch is now marking the ISE servers as "alive" when I do sw1#show cts env data?&lt;/P&gt;&lt;P&gt;What is causing the switch to previously report the severs as "dead"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reboot and the issue disappears but for how long is the question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could this be an auth time type loop issue?&lt;/P&gt;&lt;P&gt;My radius servers are local PSN's while my CTS AAA is using the PAN and SPAN, I dont believe this makes any difference but should the ISE servers be the same targets for radius and CTS trusted AAA?&lt;/P&gt;&lt;P&gt;If anyone has a known working CTS switch config and willing to post that would be great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 11:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101478#M561137</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-11T11:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101906#M561153</link>
      <description>&lt;P&gt;The switch will mark the RADIUS servers as DEAD if it does not receive a response from the server within it's configured dead-criteria timers. See &lt;A href="https://community.cisco.com/t5/security-documents/group-based-policy-fundamentals/ta-p/3764433" target="_self"&gt;Demystifying RADIUS Server Configurations&lt;/A&gt; for more information. This could be due to either a misconfiguration or a network issue.&lt;/P&gt;
&lt;P&gt;As per your comment "my CTS AAA is using the PAN and SPAN", unless you have the PSN role enabled on the PAN nodes (not recommended in a distributed environment), this will not work. The CTS AAA servers should be your PSNs.&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://community.cisco.com/t5/security-documents/group-based-policy-fundamentals/ta-p/3764433" target="_blank" rel="noopener"&gt;Group Based Policy Fundamentals&lt;/A&gt; for more info and example configurations.&lt;/P&gt;
&lt;P&gt;You might also have a look at the TrustSec lab examples available on &lt;A href="http://www.labminutes.com/video/sec" target="_blank" rel="noopener"&gt;LabMinutes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 23:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101906#M561153</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-06-11T23:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101926#M561155</link>
      <description>I can't speak for all switch types and software versions, but the ones I am familiar with have auto test enabled by default when you enable CTS and you cannot configure the user. It won't show up in the config, but you can see it with a "show run all | inc cts". While it doesn't appear to be related to your issue, the test comes through with the user as "CTS-Test-Server", and if you strip down your policy sets and disable the defaults, you can sometimes have to define this user in the local identities store to get a radius response.  &lt;BR /&gt;&lt;BR /&gt;cts server test all enable&lt;BR /&gt;cts server test all idle-time 60&lt;BR /&gt;cts server test all deadtime 20&lt;BR /&gt;&lt;BR /&gt;Out of curiosity, what version IOS and platform were you having this issue on?  I've had good results with TrustSec on 16.9.5 with 3k/9k platforms.</description>
      <pubDate>Fri, 12 Jun 2020 01:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101926#M561155</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-12T01:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102173#M561157</link>
      <description>&lt;P&gt;Hi Damien,&lt;/P&gt;&lt;P&gt;Many thanks for the reply.&lt;/P&gt;&lt;P&gt;As requested:&lt;/P&gt;&lt;P&gt;Switch Ports Model SW Version SW Image Mode&lt;BR /&gt;------ ----- ----- ---------- ---------- --------&lt;BR /&gt;* 1 52 C9200L-48PXG-4X 16.12.1 CAT9K_LITE_IOSXE INSTALL&lt;BR /&gt;2 52 C9200L-48P-4X 16.12.1 CAT9K_LITE_IOSXE INSTALL&lt;/P&gt;&lt;P&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;So do I need a positive ISE (AAA server) response to&amp;nbsp;&lt;SPAN&gt;"CTS-Test-Server" username for the auto server check to work?&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont see&amp;nbsp;&lt;SPAN&gt;"CTS-Test-Server" username but do see&amp;nbsp;&lt;STRONG&gt;username = #CTSREQUEST# &lt;/STRONG&gt;when I debug CTS env data, is this correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW1#debug cts environment-data all&lt;BR /&gt;All cts environment data debugging is on&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SW1#cts refresh environment-data&lt;BR /&gt;Environment data download in progress&lt;BR /&gt;SW1#&lt;BR /&gt;May 21 08:52:24.467: CTS env-data: Force environment-data refresh&lt;BR /&gt;May 21 08:52:24.467: CTS env-data: download transport-type = CTS_TRANSPORT_IP_UDP&lt;BR /&gt;May 21 08:52:24.467: cts_env_data COMPLETE: during state env_data_complete, got event 0(env_data_request)&lt;BR /&gt;May 21 08:52:24.467: @@@ cts_env_data COMPLETE: env_data_complete -&amp;gt; env_data_waiting_rsp&lt;BR /&gt;May 21 08:52:24.467: env_data_waiting_rsp_enter: state = WAITING_RESPONSE&lt;BR /&gt;May 21 08:52:24.467: cts_aaa_is_fragmented: (CTS env-data SM)NOT-FRAG attr_q(0)&lt;BR /&gt;May 21 08:52:24.467: env_data_request_action: state = WAITING_RESPONSE&lt;BR /&gt;May 21 08:52:24.467: cts_env_data_is_complete: FALSE, req(x0), rec(x0)&lt;BR /&gt;May 21 08:52:24.467: FALSE, req(x0), rec(x0), expect(x81), complete1(x85), complete2(xB5), complete3(x1485), complete4(x18085)complete5(xC0085), complete6(x600085)&lt;BR /&gt;May 21 08:52:24.467: env_data_request_action: state = WAITING_RESPONSE, received = 0x0 request = 0x0&lt;/P&gt;&lt;P&gt;May 21 08:52:24.467: cts_env_data_aaa_req_setup : aaa_id = 11&lt;BR /&gt;May 21 08:52:24.467: cts_aaa_req_setup: (CTS env-data SM)Private group appears DEAD, attempt public group&lt;BR /&gt;May 21 08:52:24.467: cts_aaa_req_setup: (CTS env-data SM)CTS_TRANSPORT_IP_UDP&lt;BR /&gt;May 21 08:52:24.467: cts_aaa_req_setup: (CTS env-data SM)AAA req(x4EEB07D8)&lt;BR /&gt;May 21 08:52:24.468: cts_aaa_attr_add: AAA req(0x4EEB07D8)&lt;BR /&gt;May 21 08:52:24.468: &lt;STRONG&gt;username = #CTSREQUEST#&lt;/STRONG&gt;&lt;BR /&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 11:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102173#M561157</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-12T11:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102213#M561159</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;Thank you for the reply, confused a little on "&lt;SPAN&gt;configured dead-criteria timers" as I assumed this was for general radius communications? When I do a #show aaa servers all severs are showing as up? So are you saying that the CTS aaa server function is using the dead-criteria? Is this the problem that I'm targeting different server IP's? (PSN and direct to PAN)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is the below CTS dead server group/global time based on?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CTS Server Radius Load Balance = DISABLED&lt;BR /&gt;Server Group Deadtime = 20 secs (default)&lt;BR /&gt;Global Server Liveness Automated Test Deadtime = 20 secs&lt;BR /&gt;Global Server Liveness Automated Test Idle Time = 60 mins&lt;BR /&gt;Global Server Liveness Automated Test = ENABLED (default)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another suggestion&amp;nbsp;I have seen is to separate general radius and CTS communications&amp;nbsp;using 2 groups and different ports (1812, 1645)? Is this a valid solution?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Configure RADIUS server for TrustSec but use different ports to avoid conflict"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What conflicts do we see?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 12:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4102213#M561159</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-12T12:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103018#M561199</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Another suggestion I have seen is to separate general radius and CTS communications using 2 groups and different ports (1812, 1645)? Is this a valid solution?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This is a common approach to workaround the known behaviour with RADIUS Accounting referenced in &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtw56571" target="_blank" rel="noopener"&gt;CSCtw56571&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;So do I need a positive ISE (AAA server) response to "CTS-Test-Server" username for the auto server check to work?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;As long as the switch receives a response to the test keepalives (accept or reject) it knows the RADIUS server is alive. You can also hide the fail logs using a Collection Filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The debug logs appear to indicate that the environment data request is not getting a response. This could result in the CTS server being marked DEAD. If you're pointing to the PAN for the CTS server, that is likely at least part of the problem. The CTS server is still your RADIUS server (plus the PAC that is negotiated), so it must be using your PSNs.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 23:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103018#M561199</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-06-14T23:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103157#M561209</link>
      <description>&lt;P&gt;Cheers Greg really helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 08:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103157#M561209</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-15T08:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE / CTS switch Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103228#M561214</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;Damien,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Out of curiosity I did a sh run | inc cts on one of the edge switches (9200-L).&lt;/P&gt;&lt;P&gt;Did not see the user name of&amp;nbsp;&lt;SPAN&gt;"CTS-Test-Server", in fact don't see any user name for CTS?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SW1# sh run all | inc cts&lt;BR /&gt;cts server deadtime 20&lt;BR /&gt;cts server test all enable&lt;BR /&gt;cts server test all idle-time 60&lt;BR /&gt;cts server test all deadtime 20&lt;BR /&gt;no cts server key-wrap enable&lt;BR /&gt;cts authorization list iselist&lt;BR /&gt;no cts logging verbose&lt;BR /&gt;no cts sg-epg translation&lt;BR /&gt;no cts sxp enable&lt;BR /&gt;cts sxp retry period 120&lt;BR /&gt;cts sxp reconciliation period 120&lt;BR /&gt;no cts sxp log binding-changes&lt;BR /&gt;cts sxp mapping network-map 0&lt;BR /&gt;cts sxp speaker hold-time 120&lt;BR /&gt;cts sxp listener hold-time 90 180&lt;BR /&gt;cts sxp node-id 0&lt;BR /&gt;no cts sxp filter-enable&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts manual&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts manual&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;ip redirects&lt;BR /&gt;ipv6 redirects&lt;BR /&gt;cts role-based sgt-map sgt 2&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;cts role-based enforcement vlan-list 1-4094&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 11:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4103228#M561214</guid>
      <dc:creator>Jay233</dc:creator>
      <dc:date>2020-06-15T11:02:53Z</dc:date>
    </item>
  </channel>
</rss>

