<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I get the generic &amp;quot;Connection in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760853#M57419</link>
    <description>&lt;P&gt;I get the generic "Connection Failed: Please check the connection parameters."&amp;nbsp; when I try to test.&amp;nbsp; I have logging turned up for MDM and when I take a look at the log (ise-psc.log), I see Java errors around connections being reset:&lt;/P&gt;&lt;P&gt;isco.cpm.mdm.util.MdmRESTClient -:ce139402:9843967F63C7331B896A1505F5F29711:::- Connection Failed:&lt;BR /&gt;java.net.SocketException: Connection reset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is consistent with the packet capture where you see the connection request attempt, then a "Change Cipher Spec" message, the a connection reset.&amp;nbsp; See the attached pic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2015 16:55:43 GMT</pubDate>
    <dc:creator>Wes Schochet</dc:creator>
    <dc:date>2015-09-24T16:55:43Z</dc:date>
    <item>
      <title>ISE and AirWatch MDM Integration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760850#M57397</link>
      <description>&lt;P&gt;I have been using ISE with the AirWatch integration for over a year.&amp;nbsp; Recently, it seems that AirWatch has updated their certs and now I cannot get ISE and AirWatch to communicate.&amp;nbsp; I can access the AirWatch API URLs through a browser and I see that the browser is using TLS 1.2. &amp;nbsp; &amp;nbsp; According to Cisco TAC, ISE does not support TLS 1.2.&amp;nbsp; I have cases open with both TACs, but have not found a resolution yet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have ISE / Airwatch integration working currently?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760850#M57397</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2019-03-11T06:05:35Z</dc:date>
    </item>
    <item>
      <title>Wes,I have a customer who</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760851#M57406</link>
      <description>&lt;P&gt;Wes,&lt;/P&gt;&lt;P&gt;I have a customer who experienced what sounds like the same issue.&amp;nbsp; It came down to AirWatch changing the host he was using. It was a long trek to get to the right answer but when AirWatch changed the host, things started working again.&amp;nbsp; It took him multiple calls with AirWatch before someone got the idea to make that change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 15:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760851#M57406</guid>
      <dc:creator>Tim Steele</dc:creator>
      <dc:date>2015-09-24T15:25:23Z</dc:date>
    </item>
    <item>
      <title>Actually, I have been testing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760852#M57411</link>
      <description>&lt;P&gt;Actually, I have been testing this integration recently and overcame a number of obstacles. What is the message you get when you test the integration?&lt;/P&gt;&lt;P&gt;Adminstration &amp;gt; (Network Resources) External MDM &amp;gt; select the entry and click the Edit button, click the Test Connection button.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 15:30:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760852#M57411</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2015-09-24T15:30:16Z</dc:date>
    </item>
    <item>
      <title>I get the generic "Connection</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760853#M57419</link>
      <description>&lt;P&gt;I get the generic "Connection Failed: Please check the connection parameters."&amp;nbsp; when I try to test.&amp;nbsp; I have logging turned up for MDM and when I take a look at the log (ise-psc.log), I see Java errors around connections being reset:&lt;/P&gt;&lt;P&gt;isco.cpm.mdm.util.MdmRESTClient -:ce139402:9843967F63C7331B896A1505F5F29711:::- Connection Failed:&lt;BR /&gt;java.net.SocketException: Connection reset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is consistent with the packet capture where you see the connection request attempt, then a "Change Cipher Spec" message, the a connection reset.&amp;nbsp; See the attached pic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 16:55:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760853#M57419</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2015-09-24T16:55:43Z</dc:date>
    </item>
    <item>
      <title>Just got a response from the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760854#M57421</link>
      <description>&lt;P&gt;Just got a response from the support engineer.&amp;nbsp;Try sending this to your AirWatch contact:&lt;/P&gt;&lt;P&gt;“It was basically an issue with the redirect. We configured the API URL to redirect to the necessary pool and it started working fine."&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 18:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760854#M57421</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2015-09-24T18:24:20Z</dc:date>
    </item>
    <item>
      <title>This looks very similar to a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760855#M57422</link>
      <description>&lt;P&gt;This looks very similar to a trace we had. The SSL handshake is successful actually, but as soon their webserver receives the GET request from ISE, it resets the connection.&amp;nbsp;The tech support guy I was working with had to communicate with his internal support organization to get it fixed, but I don't believe he ever game me a technical explanation of what they had to do. Let me reach out to him and get back to you.&lt;/P&gt;&lt;P&gt;Another thing you might want to try is test the connection with OpenSSL. You need to know the hostname of your endpoint, and the Base64-encoded username/password they provided you in the format &amp;lt;username&amp;gt;:&amp;lt;password&amp;gt;. There are lots of sites to encode this string -&amp;nbsp;http://www.motobit.com/util/base64-decoder-encoder.asp is one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With those two pieces of infomation, jump on a system with openssl and make the connection:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;openssl s_client -connect &amp;lt;FQDN&amp;nbsp;of&amp;nbsp;your AirWatch endpoint&amp;gt;:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If the connection was successful, you'll cursor will be sitting at a blank line waiting for input. Type in the HTTP request manually, like this:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;GET /ciscoise/mdminfo HTTP/1.1&lt;BR /&gt;Host: &amp;lt;FQDN of&amp;nbsp;your AirWatch endpoint&amp;gt;&lt;BR /&gt;Authorization: Basic &amp;lt;Base64&amp;nbsp;encoded AirWatch&amp;nbsp;credentials&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Then hit enter twice to send it. Look at the response code/headers,&amp;nbsp;and output data - it should be XML output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Edit - added more detail]&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 18:25:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-airwatch-mdm-integration/m-p/2760855#M57422</guid>
      <dc:creator>smp</dc:creator>
      <dc:date>2015-09-24T18:25:35Z</dc:date>
    </item>
  </channel>
</rss>

