<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE TCP Dump query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4926467#M584140</link>
    <description>&lt;P&gt;Yes, it was the loadbalancer after all - the packet capture on the switch showed no sign of the traffic. All sorted now&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 10:03:42 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2023-09-20T10:03:42Z</dc:date>
    <item>
      <title>ISE TCP Dump query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4925867#M584131</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I recently upgraded an ISE deployment from 2.7 patch 7 to 3.2 patch 3. One of the PSNs failed during the upgrade so I deregistered the node and manually installed 3.2 patch 3 before re-registering it with the deployment.&lt;/P&gt;&lt;P&gt;All services are working fine except for the following issue with External RADIUS Servers.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the 2 PSNs that successfully upgraded are working fine with the configured External RADIUS Servers - ISE TCP dumps show RADIUS traffic&lt;/LI&gt;&lt;LI&gt;the PSN that failed the upgrade does not respond to RADIUS requests from the External RADIUS Servers. The External RADIUS Servers report "No Reply" with this PSN. ISE TCP dumps show no RADIUS traffic from the External RADIUS Server but does show icmp. ISE RADIUS logs show nothing for this traffic.&lt;/LI&gt;&lt;LI&gt;the PSN that failed the upgrade works fine with all other RADIUS traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The PSNs are behind a loadbalancer - I confirmed with packet captures that I could see RADIUS traffic from the External RADIUS Servers to the PSN passing through the edge firewalls and the loadbalancer. This RADIUS traffic just seems to disappear!!&lt;/P&gt;&lt;P&gt;The deployment does have issues with External RADIUS Servers bugs like the one below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwb04566" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCwb04566&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does the fact that the ISE TCP dumps show no sign of this RADIUS traffic definitively mean that the PSN isn't receiving it?&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 15:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4925867#M584131</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2023-09-19T15:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE TCP Dump query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4925919#M584132</link>
      <description>&lt;P&gt;Yes, I would anticipate this being an issue with the load balancer or firewalls.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 17:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4925919#M584132</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-09-19T17:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE TCP Dump query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4926023#M584135</link>
      <description>&lt;P&gt;Thanks for the reply. It does sound like it given the lack of RADIUS traffic from the External RADIUS Servers in the TCP dump (RADIUS traffic from the loadbalancer and other NADs to the affected PSN is showing in the dumps and no changes have been made to the loadbalancer). The PSN is an appliance - I'll arrange a packet capture on its upstream switch to confirm if the traffic is actually reaching it.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 17:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4926023#M584135</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2023-09-19T17:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE TCP Dump query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4926467#M584140</link>
      <description>&lt;P&gt;Yes, it was the loadbalancer after all - the packet capture on the switch showed no sign of the traffic. All sorted now&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 10:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tcp-dump-query/m-p/4926467#M584140</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2023-09-20T10:03:42Z</dc:date>
    </item>
  </channel>
</rss>

