<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Radius Access-Request will not be challenged in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5142466#M590508</link>
    <description>&lt;P&gt;Have you tried performing a manual sync up of&amp;nbsp;&lt;SPAN&gt;ISE01?&amp;nbsp; We have to rely on every node getting the same programming from the PAN - I have seen it once where I was configuring in the GUI, but one of the PSN's wasn't getting the changes I was making - I had to manually sync the node.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If that doesn't work, then it would check your ISE RADIUS Policy Set - are the hit counters increasing?&amp;nbsp; If not, then the Meraki is possibly not sending the request to that ISE - you can prove that ultimately by running a tcpdump on ISE01 while running that test from Meraki switch.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 04:23:32 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-07-10T04:23:32Z</dc:date>
    <item>
      <title>ISE Radius Access-Request will not be challenged</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5136784#M590276</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi there,&lt;BR /&gt;I have encountered the following problem.&lt;BR /&gt;ISE small network deployment with two VMs each Pri/Sec (PAN,MnT,PSN) on Proxmox virtualisation.&lt;BR /&gt;Authenticators are Meraki Wired/Wireless configured with the Dashboard.&lt;BR /&gt;A test for a radius access request sent from the Meraki Dashboard (Switching - Access Policies) to both ISE PSN gets a response from ISE02 (Pri) but not from ISE01 (Sec).&lt;BR /&gt;The same test for a Radius Access request sent from the Meraki Dashboard (Wireless - Access Policies) to both ISE PSN is getting a response from both PSN (Pri/Sec).&lt;BR /&gt;There is no firewall or routing in place and both ISE nodes are reachable via ping.&lt;BR /&gt;A pcap on the Core SW shows that the EAP packets are being sent to the VMs.&lt;BR /&gt;A pcap on the Proxmox VMs interface shows that the EAP packet for the radius access request is reaching the dedicated node, but it is not being answered when sent from the switching access policy.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 07:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5136784#M590276</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-06-27T07:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Radius Access-Request will not be challenged</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5137070#M590293</link>
      <description>&lt;P&gt;If certain RADIUS requests work (wireless) and others do not (wired) to your secondary PSN, are you seeing any Access-Rejects in the ISE LiveLogs from the switching requests to the 2nd node? If so, what is the reason?&lt;/P&gt;
&lt;P&gt;Turn off all RADIUS Suppression to ensure you are seeing all RADIUS Failed attempts:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/221805i70BDDF414EFF2E11/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 15:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5137070#M590293</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-06-27T15:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Radius Access-Request will not be challenged</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5137239#M590302</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/909893"&gt;@alex.f.&lt;/a&gt;&amp;nbsp;- are you able to issue a ping from the Switch Dashboard "Tools tab" (ping from .13 to .122) ?&lt;/P&gt;
&lt;P&gt;If ping succeeds, then the next thing I would check is whether the Switch (.13 address) is defined in ISE&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 21:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5137239#M590302</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-06-27T21:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Radius Access-Request will not be challenged</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5142210#M590499</link>
      <description>&lt;P&gt;Yes, ping from the Meraki Dashboard is done successfully and the Switches are Network Devices in ISE.&lt;/P&gt;
&lt;P&gt;But all Switches in one Network Devices Object. &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2024-07-09 um 16.56.09.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/222865iEE729F2F4458E482/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bildschirmfoto 2024-07-09 um 16.56.09.png" alt="Bildschirmfoto 2024-07-09 um 16.56.09.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 14:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5142210#M590499</guid>
      <dc:creator>alex.f.</dc:creator>
      <dc:date>2024-07-09T14:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Radius Access-Request will not be challenged</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5142466#M590508</link>
      <description>&lt;P&gt;Have you tried performing a manual sync up of&amp;nbsp;&lt;SPAN&gt;ISE01?&amp;nbsp; We have to rely on every node getting the same programming from the PAN - I have seen it once where I was configuring in the GUI, but one of the PSN's wasn't getting the changes I was making - I had to manually sync the node.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If that doesn't work, then it would check your ISE RADIUS Policy Set - are the hit counters increasing?&amp;nbsp; If not, then the Meraki is possibly not sending the request to that ISE - you can prove that ultimately by running a tcpdump on ISE01 while running that test from Meraki switch.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 04:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-access-request-will-not-be-challenged/m-p/5142466#M590508</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-10T04:23:32Z</dc:date>
    </item>
  </channel>
</rss>

