<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client Authentication issues with multipule PSN nodes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387012#M566747</link>
    <description>&lt;P&gt;Hi Marcelo&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To note. We are running patch 13 on version 2.4. I did see this bug when researching so thought it would be fixed in patch 13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Apr 2021 18:38:52 GMT</pubDate>
    <dc:creator>bernards</dc:creator>
    <dc:date>2021-04-14T18:38:52Z</dc:date>
    <item>
      <title>Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386116#M566708</link>
      <description>&lt;P&gt;We have 2 PSN nodes for client auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All works on PSN1. When PSN1 is offline auth is directed to PSN2. All clients then fail to authentication with the following error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cisco endpoint started new session while the packet of the previous session is being processed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE is 2.24 patch 13. All information for above error seems to be bug related in previous versions. Anyone else had a similar issue that can shed any light on the matter?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 11:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386116#M566708</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-13T11:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386156#M566710</link>
      <description>&lt;P&gt;I did not run into a similar issue on older versions of ISE.&amp;nbsp; IMO it may not be a bad idea to plan on upgrading.&amp;nbsp; As of today the suggested release is 2.7.&amp;nbsp; At a minimum if you do not want to make a massive jump I would suggest upgrading at least to the latest patch for 2.2 (patch17).&amp;nbsp; Something else to consider are the 2.2 EOL notices.&amp;nbsp; See here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-743180.html" target="_blank"&gt;Cisco Identity Services Engine Software Version 2.2/2.2.1 Product Bulletin - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 12:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386156#M566710</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-13T12:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386649#M566729</link>
      <description>&lt;P&gt;Thanks for the reply Mike.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE is 2.4 patch 13 not 2.2. Above was a typo. We have the issue when 2.4 was patch 12 so upgraded to patch 13 with no success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we are planning to jump to version 3.0. soon. However the above is causing major issues currently from a failover point if view currently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 06:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386649#M566729</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-14T06:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386748#M566738</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256646"&gt;@bernards&lt;/a&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;your issue is happening when a particular &lt;STRONG&gt;PSN&lt;/STRONG&gt; goes offline or not (for example: the same issue happens if &lt;STRONG&gt;PSN2&lt;/STRONG&gt; goes offline)?&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: although it's fixed on &lt;STRONG&gt;2.4 P11&lt;/STRONG&gt;, please take a look at:&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr70581" target="_blank" rel="noopener"&gt;CSCvr70581 Called-Station-ID missing in RADIUS Authentication detail report&lt;/A&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 09:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4386748#M566738</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-14T09:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387011#M566746</link>
      <description>&lt;P&gt;Hi Marcelo&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue happens when PSN1 goes offline and clients then try to Auth with PSN2. When PSN1 comes back online clients Auth ok. So issue only happens when PSN1 is offline and PSN2 is live.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN1 is primary Auth node and PSN2 secondary for redundancy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have a look at the link provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 18:35:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387011#M566746</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-14T18:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387012#M566747</link>
      <description>&lt;P&gt;Hi Marcelo&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To note. We are running patch 13 on version 2.4. I did see this bug when researching so thought it would be fixed in patch 13.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 18:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387012#M566747</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-14T18:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387078#M566748</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256646"&gt;@bernards&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;are you able to test &lt;STRONG&gt;PSN2&lt;/STRONG&gt; as a &lt;U&gt;primary&lt;/U&gt; for a group of your &lt;STRONG&gt;Endpoints&lt;/STRONG&gt;, just to double check if the issue is happening only on your &lt;STRONG&gt;PSN1&lt;/STRONG&gt; or on both &lt;STRONG&gt;PSNs&lt;/STRONG&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 20:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387078#M566748</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-14T20:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387169#M566750</link>
      <description>&lt;P&gt;The error you referenced, "&lt;SPAN&gt;cisco endpoint started new session while the packet of the previous session is being processed", is most often seen during EAP authentication when the endpoints/client devices don't trust the server and/or certificate. Is it the EAP/dot1x authentication failing, and if so, do you use two the same EAP certificate on both nodes of the deployment? On the client supplicant config, it there a trusted server list set that only include PSN 1?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 00:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387169#M566750</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-04-15T00:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387752#M566759</link>
      <description>&lt;P&gt;Hi Marcelo&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue only happens on the secondary PSN. All clients authenticate fine on the primary PSN.&lt;/P&gt;&lt;P&gt;When we flip over to test redundancy the issue with the error message happens to all clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 19:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387752#M566759</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-15T19:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387756#M566760</link>
      <description>&lt;P&gt;Hi Damien&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes EAP clients are effected. Both PSN have correct EAP cert&amp;nbsp;installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client supplicant has correct trusted servers etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strange thing is when we revert back to primary PSN all clients work. Firewall rules have been double checked and are the same within both DMZ locations. For some reason when we force clients to use the secondary PSN the issue is present.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 19:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4387756#M566760</guid>
      <dc:creator>bernards</dc:creator>
      <dc:date>2021-04-15T19:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication issues with multipule PSN nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4389839#M566809</link>
      <description>&lt;P&gt;Sounds like a good problem to call TAC about.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 05:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-issues-with-multipule-psn-nodes/m-p/4389839#M566809</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-04-20T05:22:43Z</dc:date>
    </item>
  </channel>
</rss>

