<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5087867#M589219</link>
    <description>&lt;P&gt;adding ISE FQDN to SAN seems to have helped with limited testing, will do more testing&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2024 15:57:32 GMT</pubDate>
    <dc:creator>mitchellT</dc:creator>
    <dc:date>2024-05-02T15:57:32Z</dc:date>
    <item>
      <title>Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5081158#M589091</link>
      <description>&lt;P&gt;we are testing version 3.3 p2 and when I point my existing user ,which are working fine on version 3.2 p5 , they start getting the action required that asking them to sign in to the network. this does not happen on verision 3.2 only on version 3.3. if they don't click on sign in the authentication will fail and on ISE the error will say no response from user.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2024 16:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5081158#M589091</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-28T16:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5081160#M589092</link>
      <description>&lt;P&gt;this is the error message on switch. Anyone has seen this issue ? thanks&lt;/P&gt;&lt;P&gt;Apr 27 08:57:25.537: %SESSION_MGR-5-FAIL: Switch 3 R0/0: sessmgrd: Authorization failed or unapplied for client (c4b9.cdb5.4ba0) on Interface GigabitEthernet2/0/11 AuditSessionID 0A2E0A01000181E31C2948C2. Failure reason: Authc fail. Authc failure reason: No Response from Client.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2024 16:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5081160#M589092</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-28T16:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5082142#M589108</link>
      <description>&lt;P&gt;This indicates a supplicant issue.&amp;nbsp; What is the EAP type?&amp;nbsp; What is the supplicant?&amp;nbsp; What is the NAD?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 12:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5082142#M589108</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-29T12:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5082682#M589112</link>
      <description>&lt;P&gt;they are windows native wired dot1x supplicant using EAP-TLS and connecting from Cisco 3850 switches. both version 3.2 and 3.3 use the same root certificate and domain controller for AD.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 16:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5082682#M589112</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-29T16:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083459#M589120</link>
      <description>&lt;P&gt;What version of IOS-XE?&amp;nbsp; Everything correct on the supplicant side?&amp;nbsp; Is ISE 3.3 using a different certificate than 3.2?&amp;nbsp; What other differences in the configuration exist between the 3.2 and 3.3 deployments?&amp;nbsp; Is the supplicant configured to only talk to certain RADIUS servers?&amp;nbsp; And the 3.3 PSNs are not in this list?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 23:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083459#M589120</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-29T23:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083473#M589124</link>
      <description>&lt;P&gt;Cisco IOS XE Software, Version 16.12.07. I built version 3.3 and restore from backup with version 3.2's back file so they are exactly the same configuration with same root certificate. I've added the new version 3.3 to the list of allowed radius server on windows supplicant. the only change I'm doing is pointing the radius server to either version 3.2 or version 3.3 on the switch itself and this is when I point to version 3.3 it will ask user to sign in but it will not do that on version 3.2&lt;/P&gt;&lt;P&gt;aaa group server radius RADIUS-GROUP&lt;BR /&gt;server name ISESERVER3.2OR3.3&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 23:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083473#M589124</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-29T23:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083474#M589125</link>
      <description>So you re-issued a new certificate? Or manually imported/exported the certificate? Private keys are not contained in the backup file except for the PAN.&lt;BR /&gt;&lt;BR /&gt;Is the ISE PSN FQDN in the SAN field of the certificate? &lt;BR /&gt;&lt;BR /&gt;What type of deployment is this? How many nodes and what roles?&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Apr 2024 23:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083474#M589125</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-29T23:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083476#M589126</link>
      <description>&lt;P&gt;yes, i did re-issue a new certificate since the same of the server is different from version 3.2. the PSN FQDN is not in the SAN field of version 3.3 but i checked my version 3.2 and it doesn't have that either. maybe I'll add that and see if that helps with version 3.3.&lt;/P&gt;&lt;P&gt;this version 3.3 is only one node and it does all. my version 3.2 has only two nodes with primary and secondary PAN but both PSN are active.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 00:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083476#M589126</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-30T00:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083483#M589127</link>
      <description>3.3 is a single node? Will it become a two or three node? Note that standalone ISE nodes are only supported from an evaluation standpoint.&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Apr 2024 00:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083483#M589127</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-30T00:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083485#M589128</link>
      <description>&lt;P&gt;yes, when we get this sorted out it will be two node deployment&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 00:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5083485#M589128</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-04-30T00:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5087867#M589219</link>
      <description>&lt;P&gt;adding ISE FQDN to SAN seems to have helped with limited testing, will do more testing&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 15:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5087867#M589219</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-05-02T15:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5106234#M589466</link>
      <description>&lt;P&gt;I thought that fixed the issue with limited testing but with more testing we still have the same issue with asking user to sign in. Cisco TAC has no idea either.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 16:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5106234#M589466</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-05-16T16:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5128721#M590004</link>
      <description>&lt;P&gt;I installed a vm version on one of my UCS server and the issue did not occur. so the problem is caused by Azure ISE and cisco TAC has no idea and don't even reply to any email anymore after I sent them the logs they asked. My advise to those thinking about using Azure ISE, don't.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5128721#M590004</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-06-11T22:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5128732#M590006</link>
      <description>&lt;P&gt;Possibly related to this issue with Azure dropping out of sequence UDP packets (which is normal for EAP-TLS), but would have to look at packet captures and more detail to confirm.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/eap-tls-to-azure-ise-is-failing-but-not-with-an-ise-node-in-the/td-p/4739038" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/eap-tls-to-azure-ise-is-failing-but-not-with-an-ise-node-in-the/td-p/4739038&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5128732#M590006</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2024-06-11T22:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.3 P2 authentication issue, asking user to sign in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5129246#M590026</link>
      <description>&lt;P&gt;we have another azure ISE version 3.2 in the same azure vnet without this issue. that one has tons of other problems that's why we are trying to get rid of it by going to version 3.3.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 20:37:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-3-p2-authentication-issue-asking-user-to-sign-in/m-p/5129246#M590026</guid>
      <dc:creator>mitchellT</dc:creator>
      <dc:date>2024-06-12T20:37:51Z</dc:date>
    </item>
  </channel>
</rss>

