<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSN rejecting TACACS Traffic - tcp reset on port 49 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4972687#M585570</link>
    <description>&lt;P&gt;Check if Device Administration Service is enabled on that PSN.&lt;/P&gt;
&lt;P&gt;Go to Administration -- Deployment -- click on the PSN, click on the checkbox next to Device Administration&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 22:05:50 GMT</pubDate>
    <dc:creator>Sri Harsha Dasari</dc:creator>
    <dc:date>2023-12-06T22:05:50Z</dc:date>
    <item>
      <title>PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/3912812#M457503</link>
      <description>&lt;P&gt;Hey all, I'm seeing an issue with one of our PSNs which has stopped serving TACACS authentication. PSN2 works fine PSN1 is sending a TCP reset. Running ISE 2.4 patch 7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN2&lt;/P&gt;&lt;P&gt;telnet 2.2.2.2 49&lt;BR /&gt;Trying 2.2.2.2, 49 ... Open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN1&lt;/P&gt;&lt;P&gt;telnet 1.1.1.1 49&lt;BR /&gt;Trying 1.1.1.1, 49 ...&lt;BR /&gt;% Connection refused by remote host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The application services look fine and the deployment screen has a green tick on the PSN. I have checked and the Device Admin role is ticked under the PSN and it is utilizing a license for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know where I can find some more info on the specific services running? Which log or command can give me an output specifically on the TACACS service? It is also running RADIUS and profiling roles too but those services are running fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PSN1/admin# show application status ise&lt;/P&gt;&lt;P&gt;ISE PROCESS NAME STATE PROCESS ID&lt;BR /&gt;--------------------------------------------------------------------&lt;BR /&gt;Database Listener running 3256&lt;BR /&gt;Database Server running 115 PROCESSES&lt;BR /&gt;Application Server running 27263&lt;BR /&gt;Profiler Database running 6292&lt;BR /&gt;ISE Indexing Engine disabled&lt;BR /&gt;AD Connector running 18370&lt;BR /&gt;M&amp;amp;T Session Database disabled&lt;BR /&gt;M&amp;amp;T Log Collector disabled&lt;BR /&gt;M&amp;amp;T Log Processor disabled&lt;BR /&gt;Certificate Authority Service running 18103&lt;BR /&gt;EST Service running 18470&lt;BR /&gt;SXP Engine Service disabled&lt;BR /&gt;Docker Daemon running 7701&lt;BR /&gt;TC-NAC Service disabled&lt;/P&gt;&lt;P&gt;Wifi Setup Helper Container disabled&lt;BR /&gt;pxGrid Infrastructure Service disabled&lt;BR /&gt;pxGrid Publisher Subscriber Service disabled&lt;BR /&gt;pxGrid Connection Manager disabled&lt;BR /&gt;pxGrid Controller disabled&lt;BR /&gt;PassiveID WMI Service disabled&lt;BR /&gt;PassiveID Syslog Service disabled&lt;BR /&gt;PassiveID API Service disabled&lt;BR /&gt;PassiveID Agent Service disabled&lt;BR /&gt;PassiveID Endpoint Service disabled&lt;BR /&gt;PassiveID SPAN Service disabled&lt;BR /&gt;DHCP Server (dhcpd) disabled&lt;BR /&gt;DNS Server (named) disabled&lt;BR /&gt;ISE RabbitMQ Container running 9152&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 06:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/3912812#M457503</guid>
      <dc:creator>Jovan</dc:creator>
      <dc:date>2019-08-23T06:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/3913037#M457505</link>
      <description>Does anyone know where I can find some more info on the specific services running? Which log or command can give me an output specifically on the TACACS service? It is also running RADIUS and profiling roles too but those services are running fine.&lt;BR /&gt;&lt;BR /&gt;From ISE CLI:&lt;BR /&gt;#show ports&lt;BR /&gt;#show ports | i 49</description>
      <pubDate>Fri, 23 Aug 2019 12:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/3913037#M457505</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-08-23T12:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4845434#M582010</link>
      <description>&lt;P&gt;Probably you need to enable the Device Admin service under Deployment and then Edit the PSN persona services and enable Device Admin (Be careful that the Device Admin is use a dedicated licenses)&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 13:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4845434#M582010</guid>
      <dc:creator>Nicolo.Steffe</dc:creator>
      <dc:date>2023-05-30T13:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4846071#M582028</link>
      <description>&lt;P&gt;ISE 2.4 is already EoL/EoS:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-743964.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-743964.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Suggestion is to first upgrade the ISE deployment, test and update the results here.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 04:34:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4846071#M582028</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2023-05-31T04:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4972687#M585570</link>
      <description>&lt;P&gt;Check if Device Administration Service is enabled on that PSN.&lt;/P&gt;
&lt;P&gt;Go to Administration -- Deployment -- click on the PSN, click on the checkbox next to Device Administration&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 22:05:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4972687#M585570</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2023-12-06T22:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973225#M585575</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;I'm posting in this forum, since I see the relevant discussion is running. Need support on finding the API[ansible]&lt;/P&gt;&lt;P&gt;a. Trying to find the API for enabling PSN&amp;nbsp;work centers -&amp;gt; Overview -&amp;gt; Deployment -&amp;gt;&amp;nbsp;Device Administration Deployment&lt;/P&gt;&lt;P&gt;=&amp;gt; Activate ISE Nodes for Device Administration&lt;BR /&gt;None&lt;BR /&gt;All Policy Service Nodes ------ &amp;gt; Finding API to enable the same via ansible&lt;BR /&gt;Specific Nodes&lt;/P&gt;&lt;P&gt;b. Similarly, trying to find API to enable&amp;nbsp;Administration - &amp;gt;Network devices - &amp;gt; Network Device - Default Device&lt;/P&gt;&lt;P&gt;=&amp;gt;&amp;nbsp;Default Network Device Status&lt;BR /&gt;Disable to Enable ---- &amp;gt; Need API for the same to use in Ansible.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is to set password under TACACS&amp;nbsp;&lt;/P&gt;&lt;P&gt;TACACS Authentication Settings&lt;BR /&gt;Enable TACACS&lt;BR /&gt;Shared Secret&amp;nbsp; ____________&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 12:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973225#M585575</guid>
      <dc:creator>lanagna</dc:creator>
      <dc:date>2023-12-07T12:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973434#M585582</link>
      <description>&lt;P&gt;Please open a new question in this forum for this topic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 14:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973434#M585582</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-12-07T14:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: PSN rejecting TACACS Traffic - tcp reset on port 49</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973439#M585583</link>
      <description>&lt;P&gt;ISE 2.4 was not EoL when the question was asked in 2019.&amp;nbsp; Unfortunately, the OP didn't respond to the questions in the first response so there's no way of knowing what the actual resolution for them was.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 14:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-rejecting-tacacs-traffic-tcp-reset-on-port-49/m-p/4973439#M585583</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2023-12-07T14:10:02Z</dc:date>
    </item>
  </channel>
</rss>

