<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with PSN ISE node (error 5405 Radius session drop) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-psn-ise-node-error-5405-radius-session-drop/m-p/5298162#M596726</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;Recently in Deployment ISE on PSN in one of the nodes the following errors appeared: when attempting to authorize via Dot1.x and MAB protocols.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AleksandrPashko_0-1749570871479.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/246273i8015FF581A8647D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AleksandrPashko_0-1749570871479.png" alt="AleksandrPashko_0-1749570871479.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there are also normal sessions.&lt;/P&gt;
&lt;P&gt;After Radius Request Drop, due to load balancing configured on NADs, the device is successfully authenticated/authorized on the next PSN node in the group (there are only 3 PSN nodes in each group)&lt;/P&gt;
&lt;P&gt;Rebooting the node does not help.&lt;/P&gt;
&lt;P&gt;When deregistering (removing) a node from Deployment, all radius sessions are successful (when the node is Stand Alone)&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine Version 3.1.0.518&lt;BR /&gt;Cisco Identity Services Engine Patch Version 7&lt;/P&gt;
&lt;P&gt;Could someone help us to resolve problem?&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jun 2025 15:56:58 GMT</pubDate>
    <dc:creator>Aleksandr Pashko</dc:creator>
    <dc:date>2025-06-10T15:56:58Z</dc:date>
    <item>
      <title>Problem with PSN ISE node (error 5405 Radius session drop)</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-psn-ise-node-error-5405-radius-session-drop/m-p/5298162#M596726</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;Recently in Deployment ISE on PSN in one of the nodes the following errors appeared: when attempting to authorize via Dot1.x and MAB protocols.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AleksandrPashko_0-1749570871479.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/246273i8015FF581A8647D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AleksandrPashko_0-1749570871479.png" alt="AleksandrPashko_0-1749570871479.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there are also normal sessions.&lt;/P&gt;
&lt;P&gt;After Radius Request Drop, due to load balancing configured on NADs, the device is successfully authenticated/authorized on the next PSN node in the group (there are only 3 PSN nodes in each group)&lt;/P&gt;
&lt;P&gt;Rebooting the node does not help.&lt;/P&gt;
&lt;P&gt;When deregistering (removing) a node from Deployment, all radius sessions are successful (when the node is Stand Alone)&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine Version 3.1.0.518&lt;BR /&gt;Cisco Identity Services Engine Patch Version 7&lt;/P&gt;
&lt;P&gt;Could someone help us to resolve problem?&lt;/P&gt;
&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 15:56:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-psn-ise-node-error-5405-radius-session-drop/m-p/5298162#M596726</guid>
      <dc:creator>Aleksandr Pashko</dc:creator>
      <dc:date>2025-06-10T15:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with PSN ISE node (error 5405 Radius session drop)</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-psn-ise-node-error-5405-radius-session-drop/m-p/5298224#M596729</link>
      <description>&lt;P&gt;Sounds like a TAC case to me. But if you want to investigate yourself, then try reproducing it, and run a tcpdump on that node - if the RADIUS Access-Request packet looks normal (i.e. same as a 'working' request) then you can conclude that the PSN has lost its marbles. But since we (ISE admins) can't influence the programming of a PSN node (it's all done via the Admin node) there is little we can do, other than de-register, re-register, reboot etc. I don't understand why a de-registered node would work any differently to a registered one. The Services programming remains in tact after de-registration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes, you can force a config "push" to the PSNs by making a config change that should be replicated to all nodes - e.g. create a new dummy Policy Set that does nothing, and then delete it again - perhaps that's enough to force a reprogramming of the node. But it's just a guess.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2025 21:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-psn-ise-node-error-5405-radius-session-drop/m-p/5298224#M596729</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-06-10T21:28:34Z</dc:date>
    </item>
  </channel>
</rss>

