<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 - Radius requests on a different interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673391#M576823</link>
    <description>&lt;P&gt;You are so so welcome&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 14:17:05 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-08-22T14:17:05Z</dc:date>
    <item>
      <title>ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672992#M576798</link>
      <description>&lt;P&gt;Hello I am using ISE 2.6 in a VM setup. I have two interfaces:&lt;/P&gt;&lt;P&gt;G0: Meant to be for management purpose to login to the UI&lt;/P&gt;&lt;P&gt;G2: Exposed to the network where Radius AAA requests incoming. Its a requirement to use this G2 interface only and not respond to the Radius AAA requests on G0.&amp;nbsp; The G2 interface was added afterwards and I put a static route pointing to the G2 GW for the NADs IP subnet where the auth requests are generated from. So IP reachability is there but we discovered that interface G2 is not responding to the Radius requests. How do we make it to work (besides fixing the IP route for return packets which I already did)?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 14:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672992#M576798</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-21T14:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672994#M576799</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/41089"&gt;@tsuthar&lt;/a&gt; ISE listens for RADIUS requests on all interfaces as default.&lt;/P&gt;
&lt;P&gt;I assume you can ping the G2 IP address from the NADs?&lt;/P&gt;
&lt;P&gt;The RADIUS server configuration on the NADs points to the G2 IP address?&lt;/P&gt;
&lt;P&gt;If you run "show aaa server" is the RADIUS server UP?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:10:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672994#M576799</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-21T15:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672995#M576800</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Yes the G2 IP is reachable by the NADs. And the AAA configuration is done to point to the G2 IP. We ran traces and the AAA requests are sent from the NADs but there is no response coming back. To test and isolate the issue - I put freerad (in the same subnet as the ISE VM) as an alternative and it is able to authenticate/authorize without any problem. So that tells me somehow ISE is not responding to the AAA requests. Looks like some configuration needs to happen which I am trying to figure out.&lt;/P&gt;&lt;P&gt;Appreciate any help.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672995#M576800</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-21T15:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672996#M576801</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/41089"&gt;@tsuthar&lt;/a&gt; ok so you can ping the G2 interface, but does the NAD confirm the NAD is UP - "show aaa server"?&lt;/P&gt;
&lt;P&gt;Run tcpdump on ISE to confirm the packets reach ISE.&lt;/P&gt;
&lt;P&gt;I assume you've defined the NADs in ISE with the correct shared secret? If not there will be no logs.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4672996#M576801</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-21T15:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673002#M576802</link>
      <description>&lt;P&gt;Yes all those basic config is not an issue. Just to add to what tests we ran another test here: I moved one of the NADs to a different network which can reach the G0 interface (even though its not allowed by policy but for testing purpose I managed to do it).&amp;nbsp; I changed the NAD AAA config to point to the G0 IP , the AAA is working just fine. So that tells me G2 is not able to serve the AAA requests.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673002#M576802</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-21T15:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673004#M576803</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/41089"&gt;@tsuthar&lt;/a&gt; well ISE listens for RADIUS on all interfaces, perhaps there is a bug for your patch version of ISE, have you checked?&lt;/P&gt;
&lt;P&gt;Did you confirm whether ISE receives the RADIUS requests destined to the G2 IP address by using tcpdump?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673004#M576803</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-21T15:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673015#M576804</link>
      <description>&lt;P&gt;Yes Rob. I see the radius requests coming in. See attached a snapshot.&lt;/P&gt;&lt;P&gt;You've mentioned about a possible bug - I have this patch applied:&amp;nbsp;ise-patchbundle-2.6.0.156-Patch10-21081000.SPA.x86_64.tar.gz&lt;/P&gt;&lt;P&gt;Here is the livelog:&lt;/P&gt;&lt;H3&gt;&lt;SPAN&gt;Steps&lt;/SPAN&gt;&lt;/H3&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11007&lt;/TD&gt;&lt;TD&gt;Could not locate Network Device or AAA Client&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;5405&lt;/TD&gt;&lt;TD&gt;RADIUS Request dropped&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If it's sending the response on G0 - obviously the NAD won't be reachable.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 16:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673015#M576804</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-21T16:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673021#M576805</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/41089"&gt;@tsuthar&lt;/a&gt; this message "Could not locate Network Device or AAA Client" sticks out.....&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions &lt;/STRONG&gt;&lt;SPAN&gt;Click the magnifying glass icon in Authentications to display the steps in the &lt;/SPAN&gt;&lt;SPAN&gt;Authentication Report. The logs display the following error message:&lt;/SPAN&gt;&lt;BR role="presentation" /&gt;&lt;SPAN&gt;•&lt;/SPAN&gt; &lt;EM&gt;&lt;U&gt;11007 &lt;SPAN class="highlight selected appended"&gt;Could not locate Network Device or AAA Client&lt;/SPAN&gt; Resolution&lt;/U&gt;&lt;/EM&gt;&lt;BR role="presentation" /&gt;&lt;STRONG&gt;Possible Causes&lt;/STRONG&gt; &lt;SPAN&gt;The administrator did not correctly configure the network access device (NAD) type &lt;/SPAN&gt;&lt;SPAN&gt;in Cisco ISE.&lt;/SPAN&gt;&lt;BR role="presentation" /&gt;&lt;STRONG&gt;Resolution &lt;/STRONG&gt;&lt;SPAN&gt;Add the NAD in Cisco ISE again, verifying the NAD type and settings.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.pdf" target="_blank"&gt;https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_troubleshooting.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you saying the packet capture confirms it's coming from the incorrect interface IP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 16:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673021#M576805</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-21T16:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673357#M576817</link>
      <description>&lt;P&gt;Sorry Rob - was outside yesterday.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If its a NAD issue that it should not work on when using the G0 interface. I tried re-adding the NAD type and attributes but no luck.&lt;/P&gt;&lt;P&gt;To your earlier question - the tcpdump shows the incoming request to the ISE on the G2 interface (correct interface) but nothing going back or no response going out on G2.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673357#M576817</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-22T13:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673362#M576818</link>
      <description>&lt;P&gt;from NAD can you ping G2.&amp;nbsp;&lt;BR /&gt;how you connect both Interface to SW ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673362#M576818</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-22T13:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673367#M576820</link>
      <description>&lt;P&gt;Yes, I am able to ping the G2 interface (stated earlier too) from the NAD as well as the Client. G0 is on a different network for VM-NET-MGMT (for management purpose only i.e. for users to login to ISE etc..). The G2 is on a different Network that connects into the DC Switch where the Client + NAD auth requests come in. Hope this clarifies my setup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673367#M576820</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-22T13:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673370#M576821</link>
      <description>&lt;P&gt;able to ping G2 using the NAD IP add in ISE ?&amp;nbsp;&lt;BR /&gt;use&amp;nbsp;&lt;BR /&gt;ping G2 source NAD IP &amp;lt;as you enter in ISE&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:39:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673370#M576821</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-22T13:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673380#M576822</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; Thanks - that was the issue. When I flipped back and forth I didn't change the IP of the NAD in the ISE. Once I corrected auth started working. Thanks for the pointer.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 14:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673380#M576822</guid>
      <dc:creator>tsuthar</dc:creator>
      <dc:date>2022-08-22T14:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 - Radius requests on a different interface</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673391#M576823</link>
      <description>&lt;P&gt;You are so so welcome&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 14:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-radius-requests-on-a-different-interface/m-p/4673391#M576823</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-22T14:17:05Z</dc:date>
    </item>
  </channel>
</rss>

