<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE: 5436 RADIUS packet already in the process in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4506591#M571166</link>
    <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;I am facing an issue with my ISE server, relative to the event "&lt;SPAN&gt;5436 RADIUS packet already in the process".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Indeed, I manage the network access (autentication &amp;amp; authorisation) of my wireless Guest network through an ISE server (radius). All the the wifi guest clients connect to Light Weight Access Point which are centrally managed by Cisco Controllers (WLC).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The WLC redirects client to the ISE server portal in order to create himself his credentials for the first time. Once done and every time the client will be authenticated, the ISE server sends the "change of authorisation" to WLC in order to grant him network access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since a while, a lot wifi Guest clients can't access to the wifi Guess network because they can't submit again the network access request due to the error message "5436 RADIUS packet already in the process" find out in the ISE Work Centers Reports.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone can help me ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Nov 2021 14:37:56 GMT</pubDate>
    <dc:creator>chrisathe.atitung</dc:creator>
    <dc:date>2021-11-22T14:37:56Z</dc:date>
    <item>
      <title>ISE: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4506591#M571166</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;I am facing an issue with my ISE server, relative to the event "&lt;SPAN&gt;5436 RADIUS packet already in the process".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Indeed, I manage the network access (autentication &amp;amp; authorisation) of my wireless Guest network through an ISE server (radius). All the the wifi guest clients connect to Light Weight Access Point which are centrally managed by Cisco Controllers (WLC).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The WLC redirects client to the ISE server portal in order to create himself his credentials for the first time. Once done and every time the client will be authenticated, the ISE server sends the "change of authorisation" to WLC in order to grant him network access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Since a while, a lot wifi Guest clients can't access to the wifi Guess network because they can't submit again the network access request due to the error message "5436 RADIUS packet already in the process" find out in the ISE Work Centers Reports.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone can help me ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 14:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4506591#M571166</guid>
      <dc:creator>chrisathe.atitung</dc:creator>
      <dc:date>2021-11-22T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4506846#M571170</link>
      <description>&lt;P&gt;There are various reasons you could be seeing the 5436 events. It could be related to bugID &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt34876?rfs=iqvred" target="_blank" rel="noopener"&gt;CSCvt34876&lt;/A&gt;, but there is not enough information to provide much meaningful assistance.&lt;/P&gt;
&lt;P&gt;You mention CoA... are you seeing any CoA failure logs? Have you confirmed that CoA (RFC-3576) is enabled on the controller?&lt;/P&gt;
&lt;P&gt;What has happened "since a while"? ISE or WLC software updates, changes, etc?&lt;/P&gt;
&lt;P&gt;Please see &lt;STRONG&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank" rel="noopener"&gt;How to Ask the Community for Help&lt;/A&gt; &lt;/STRONG&gt;and open a TAC case if this an urgent issue.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 22:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4506846#M571170</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-11-22T22:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4507297#M571187</link>
      <description>&lt;P&gt;Dear Greg,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;The issue started without any network changes, no upgrade.&lt;/P&gt;&lt;P&gt;The CoA is indeed enabled on my ISE server.&lt;/P&gt;&lt;P&gt;But when checking Radius live logs of failed authentications, I am not seeing any log of CoA.&lt;/P&gt;&lt;P&gt;When looking at Operations/Reports/Diagnostics/ISE counters, I saw this counter relative to the CoA :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Counter Attribute Threshold =&amp;gt; TC-NAC: CoA Issued&amp;nbsp; |&amp;nbsp; UCS_SMALL | 250&lt;/P&gt;&lt;P&gt;When looking at Operations/Reports/Diagnostics/Misconfigured NAS, I saw the following messages several times for different endpoints. I showed below for only one endpoint device but there are some in xlsx file in attchment :&lt;/P&gt;&lt;P&gt;Message =&amp;gt; NAS conducted several failed authentications of the same scenario,&lt;/P&gt;&lt;P&gt;Failure Reason : 12929 NAS sends RADIUS accounting update messages too frequently&lt;/P&gt;&lt;P&gt;Details :&amp;nbsp;&lt;/P&gt;&lt;P&gt;ConfigVersionId=67,Device IP Address=x.x.x.x,Device Port=32772,DestinationIPAddress=y.y.y.12,DestinationPort=1813,RadiusPacketType=AccountingRequest,UserName=48-FD-A3-B3-E6-F2,Protocol=Radius,RequestLatency=1,NetworkDeviceName=WLC1,User-Name=48-FD-A3-B3-E6-F2,NAS-Port=1,Framed-IP-Address=w.w.5.63,Class=CACS:03025d0a007a7d007c189d61:ISE_1/426340496/4488658,Called-Station-ID=64-9e-f3-65-b1-80,NAS-Identifier=WLC1,Acct-Status-Type=Interim-Update,Acct-Delay-Time=0,Acct-Input-Octets=19016,Acct-Output-Octets=18845,Acct-Session-Id=619d187c/48:fd:a3:b3:e6:f2/8064786,Acct-Authentic=RADIUS,Acct-Session-Time=434,Acct-Input-Packets=123,Acct-Output-Packets=93,Acct-Input-Gigawords=0,Acct-Output-Gigawords=0,Event-Timestamp=1637685806,NAS-Port-Type=Wireless - IEEE 802.11,Tunnel-Type=(tag=0) VLAN,Tunnel-Medium-Type=(tag=0) 802,Tunnel-Private-Group-ID=(tag=0) 921,cisco-av-pair=audit-session-id=03025d0a007a7d007c189d61,Airespace-Wlan-Id=7,NetworkDeviceProfileName=Cisco,NetworkDeviceProfileId=730d45ba-a3d3-49a8-9e07-a20ca3dae75b,IsThirdPartyDeviceFlow=false,SSID=64-9e-f3-65-b1-80,AcsSessionID=ISE_1/426340496/4492143,SelectedAccessService=Wireless_Protocols,Step=11004,Step=11017,Step=15049,Step=15008,Step=15004,Step=22094,Step=11005,Step=12929,Step=5435,NetworkDeviceGroups=Location#All Locations#All Wireless Location,NetworkDeviceGroups=Device Type#All Device Types#Wireless,CPMSessionID=03025d0a007a7d007c189d61,EndPointMACAddress=48-FD-A3-B3-E6-F2,ISEPolicySetName=Wireless,AllowedProtocolMatchedRule=MAB,StepData=4=MAB,DTLSSupport=Unknown,RadiusFlowType=WirelessMAB,Network Device Profile=Cisco,Model Name=AIR-CT8510-K9,Software Version=7.6.130.21,Location=Location#All Locations#All Wireless Location,Device Type=Device Type#All Device Types#Wireless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this give you more details ? If you need specific informations, I can provide it.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 17:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4507297#M571187</guid>
      <dc:creator>chrisathe.atitung</dc:creator>
      <dc:date>2021-11-23T17:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: 5436 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4510807#M571311</link>
      <description>&lt;P class="p"&gt;As Greg said, we are missing any real details. I suggest you create a TAC case if Guests are unable to get network access and you may need to do a packet capture to understand the exact packet flow from the WLC.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Message Code: &lt;/STRONG&gt;5436&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Severity: &lt;/STRONG&gt;WARN&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Message Text: &lt;/STRONG&gt;RADIUS packet already in the process&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Message Description: &lt;/STRONG&gt;Ignoring this request because it is a duplicate of another packet that is currently being processed&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Local Target Message Format: &lt;/STRONG&gt;&amp;lt;timestamp&amp;gt; &amp;lt;seq_num&amp;gt; 5436 WARN RADIUS: RADIUS packet already in the process, &amp;lt;log details&amp;gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG class="ph b"&gt;Remote Target Message Format: &lt;/STRONG&gt;&amp;lt;pri_num&amp;gt; &amp;lt;timestamp&amp;gt; &amp;lt;IP address/hostname&amp;gt; &amp;lt;CISE_logging category&amp;gt; &amp;lt;msg_id&amp;gt; &amp;lt;total seg&amp;gt; &amp;lt;seg num&amp;gt;&amp;lt;timestamp&amp;gt; &amp;lt;seq_num&amp;gt; 5436 WARN RADIUS: RADIUS packet already in the process, &amp;lt;log details&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 20:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-5436-radius-packet-already-in-the-process/m-p/4510807#M571311</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-11-30T20:51:54Z</dc:date>
    </item>
  </channel>
</rss>

