<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - Out Of Band (OOB) TrustSec PAC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128533#M589978</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp; ... thanks for the response. The docs are hard to find with regards to this. However, I was able to get my issue resolved by doing this. 1) I was able to regenerate the PAC by issuing &lt;STRONG&gt;cts refresh pac&lt;/STRONG&gt; from the switch. I don't know why this switch required manual intervention. DNAC is involved, so I will have to look into that. Once I issue that command, the device in ISE was showing the PAC issued by "Network Device". 2) We had another issue with this switches AAA setup being misconfigured as well. After these changes were made, our TrustSec/SXP mappings were present on this switch when viewing the out from the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;show cts environment-data&lt;/STRONG&gt; command.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 12:17:54 GMT</pubDate>
    <dc:creator>MattMH</dc:creator>
    <dc:date>2024-06-11T12:17:54Z</dc:date>
    <item>
      <title>Cisco ISE - Out Of Band (OOB) TrustSec PAC</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128027#M589943</link>
      <description>&lt;P&gt;I am having issues getting my TrustSec policy working on one my switches. When I run the following command I see,&lt;/P&gt;&lt;P&gt;27-Switch#show cts environment-data&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = START &lt;EM&gt;&lt;STRONG&gt;(always in START)&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Last status = Cleared&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then I started debugging (debug cts environment-data all) the switch and see this error..."PAC not found on the device"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I went to the device in ISE, compared it to the switches that are working and noticed the OOB cert has expired. No other switch (that I am aware of yet) has an expired cert.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I went ahead a clicked the "Generate PAC' on the device in ISE. However, what I find odd is that after I generate the cert, my username is in the "Issued By" section&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattMH_0-1718026254029.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/220511iCDF6189CCECA33EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MattMH_0-1718026254029.png" alt="MattMH_0-1718026254029.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Every other device, which none of them have expired certs, shows Issued By as "network device", which leads me to believe something automated is being used to regenerate these certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regenerating the PAC did not resolve the issue, so with all that said, could have just sent you down the wrong rabbit hole and this OOB is all unrelated. 1 of my 100+ switches does not work, which started last week.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128027#M589943</guid>
      <dc:creator>MattMH</dc:creator>
      <dc:date>2024-06-10T13:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Out Of Band (OOB) TrustSec PAC</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128209#M589956</link>
      <description>&lt;P&gt;Did you use DNAC (integrated with ISE at that time) to onboard the switches in a greenfield scenario? In that case DNAC does all this for you and I have never understood how this works.&lt;/P&gt;
&lt;P&gt;I have tried reading various Cisco articles on PAC but I just don't get it into my head. I wish someone with a knack for explaining this could write up a simple article about why anyone needs PAC and how it works, and best of all, how to fix it when it breaks.&lt;/P&gt;
&lt;P&gt;If you're not using SDA, DNAC provisioning still pushes PAC/CTS stuff to the switches - AFAIK, when not using SDA you don't need PAC in the device's RADIUS shared secret config. Not sure why DNAC insists on pushing this out, and I have not found an option in DNAC to disable this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 20:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128209#M589956</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-10T20:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Out Of Band (OOB) TrustSec PAC</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128533#M589978</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp; ... thanks for the response. The docs are hard to find with regards to this. However, I was able to get my issue resolved by doing this. 1) I was able to regenerate the PAC by issuing &lt;STRONG&gt;cts refresh pac&lt;/STRONG&gt; from the switch. I don't know why this switch required manual intervention. DNAC is involved, so I will have to look into that. Once I issue that command, the device in ISE was showing the PAC issued by "Network Device". 2) We had another issue with this switches AAA setup being misconfigured as well. After these changes were made, our TrustSec/SXP mappings were present on this switch when viewing the out from the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;show cts environment-data&lt;/STRONG&gt; command.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 12:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5128533#M589978</guid>
      <dc:creator>MattMH</dc:creator>
      <dc:date>2024-06-11T12:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Out Of Band (OOB) TrustSec PAC</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5148489#M590792</link>
      <description>&lt;P&gt;Dear Cisco, I concur with Arne on why Catalyst Center deploys this CTS configuration on the switch and on ISE when there is no intention to use it.&amp;nbsp; Or if there is some reason to use this config other than SDA, please enlighten us.&amp;nbsp; &amp;nbsp;And I also add my voice to requesting some detailed documentation on this whole process involving Catalyst Center, ISE, and the device.&amp;nbsp; And how to avoid these nagging PAC expiration issues.&amp;nbsp; thanks for bringing this up Arne.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 19:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5148489#M590792</guid>
      <dc:creator>TomM</dc:creator>
      <dc:date>2024-07-22T19:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - Out Of Band (OOB) TrustSec PAC</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5148672#M590799</link>
      <description>&lt;P&gt;thanks for the feedback but I cannot guarantee that anyone from Cisco will see your comments. It's probably best to get Cisco's attention via your local account teams.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 02:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-out-of-band-oob-trustsec-pac/m-p/5148672#M590799</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-23T02:57:50Z</dc:date>
    </item>
  </channel>
</rss>

