<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switch Server RADIUS Config Post SP Node Addition in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5022520#M587549</link>
    <description>&lt;P&gt;To add context, the encrypted key as viewed on the NAD is different for each ISE node configured (primary and secondary respectively), i.e. switch1 has an encrypted key for ISE1 and an encrypted key for ISE2. When reviewing the ISE configuration via the GUI, a singular RADIUS key exists. Yet, both encrypted keys utilise two different hashes, those same hashed keys are configured identically across different switching infrastructure. Is this simply a case that the key (and password) has been hashed twice, and applied on multiple NADs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 08:08:17 GMT</pubDate>
    <dc:creator>aavnet89</dc:creator>
    <dc:date>2024-02-22T08:08:17Z</dc:date>
    <item>
      <title>Switch Server RADIUS Config Post SP Node Addition</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021283#M587474</link>
      <description>&lt;P&gt;Good morning, good afternoon, good evening,&lt;/P&gt;&lt;P&gt;I am currently in the process of adding an additional Service Policy Node at a branch office, providing first response authentication, locally to site. This node is adopted and syncronising within the distrubted deployment.&lt;/P&gt;&lt;P&gt;Current switch configuration has the IP and ports of both the primary and secondary ISE nodes, with a seperate encrypted key for each configured responding RADIUS node. I wish to add the third SPN to the configuration, with an encrypted key. My question: &lt;STRONG&gt;Where in the ISE GUI can I add an *additional* RADIUS secret key on an already configured NAD?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Example config:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius server ISE1&lt;BR /&gt;address ipv4 1.1.1.1 auth-port 1645 acct-port 1646&lt;BR /&gt;key 7 DSDSHJDJKSHAKDKSHKDLKHSAKLDASD&lt;/P&gt;&lt;P&gt;radius server ISE2&lt;BR /&gt;address ipv4 2.2.2.2 auth-port 1645 acct-port 1646&lt;BR /&gt;key 7 DSLKJUDJSALKDJSAJDLKi823797239871DS&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius server NEW-ISE3&lt;BR /&gt;address ipv4 3.3.3.3 auth-port 1656 acct-port 1646&lt;BR /&gt;&lt;STRONG&gt;key 7 ENTERNEWKEYHERE *add to ISE*&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;With thanks, in advance,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 14:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021283#M587474</guid>
      <dc:creator>aavnet89</dc:creator>
      <dc:date>2024-02-20T14:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Switch Server RADIUS Config Post SP Node Addition</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021389#M587484</link>
      <description>&lt;P&gt;Why not just use the same key?&amp;nbsp; ISE supports up to two different keys for the same NAD but not three.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 17:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021389#M587484</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-20T17:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Switch Server RADIUS Config Post SP Node Addition</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021988#M587503</link>
      <description>&lt;P&gt;Thanks, ahollifield. An option, I have concidered.&lt;/P&gt;&lt;P&gt;To add context, the encrypted key as viewed on the NAD is different for each ISE node configured (primary and secondary respectively), i.e. switch1 has an encrypted key for ISE1 and an encrypted key for ISE2. When reviewing the ISE configuration via the GUI, a singular RADIUS key exists. Yet, both encrypted keys utilise two different hashes, those same hashed keys are configured identically across different switching infrastructure. Is this simply a case that the key (and password) has been hashed twice, and applied on multiple NADs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 14:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5021988#M587503</guid>
      <dc:creator>aavnet89</dc:creator>
      <dc:date>2024-02-21T14:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Switch Server RADIUS Config Post SP Node Addition</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5022520#M587549</link>
      <description>&lt;P&gt;To add context, the encrypted key as viewed on the NAD is different for each ISE node configured (primary and secondary respectively), i.e. switch1 has an encrypted key for ISE1 and an encrypted key for ISE2. When reviewing the ISE configuration via the GUI, a singular RADIUS key exists. Yet, both encrypted keys utilise two different hashes, those same hashed keys are configured identically across different switching infrastructure. Is this simply a case that the key (and password) has been hashed twice, and applied on multiple NADs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 08:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-server-radius-config-post-sp-node-addition/m-p/5022520#M587549</guid>
      <dc:creator>aavnet89</dc:creator>
      <dc:date>2024-02-22T08:08:17Z</dc:date>
    </item>
  </channel>
</rss>

