<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you post the output of  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566195#M72405</link>
    <description>&lt;P&gt;Can you post the output of "show run aaa"? I was having the same issue and it was the syntax of the "aaa authorization network" statement. I was incorrectly specifying the method list.&lt;/P&gt;
&lt;P&gt;It should look like this:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;aaa authorization network [radius-server-group] group radius&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;I had it like this before and it wasn't working:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;aaa authorization network cts&amp;nbsp;group [radius-server-group]&lt;/PRE&gt;
&lt;P&gt;Good luck,&lt;/P&gt;
&lt;P&gt;Ryan&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2015 02:32:36 GMT</pubDate>
    <dc:creator>Ryan Wolfe</dc:creator>
    <dc:date>2015-12-04T02:32:36Z</dc:date>
    <item>
      <title>Cisco TrustSec Catalyst 3650</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566192#M72402</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;I am attempting to follow the Cisco TrustSec Deployment guide (&lt;A href="http://www.cisco.com/c/dam/en/us/td/docs/solutions/Enterprise/Security/TrustSec_2-0/trustsec_2-0_dig.pdf" target="_blank"&gt;http://www.cisco.com/c/dam/en/us/td/docs/solutions/Enterprise/Security/TrustSec_2-0/trustsec_2-0_dig.pdf&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;So far things have been going well. I am at the point of adding in my Seed device. After completing the setup on ISE and then the switch itself (a Cisco Catalyst 3650) I am note that the environment data doesn't appear to have been download. However the PAC file is successfully generated.&lt;/P&gt;&lt;P class="p1"&gt;fos01-l3-01#show cts pacs&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; AID: 43157A4E6832894FE4952D0A1F6167BB&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; PAC-Info:&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;nbsp; PAC-type = Cisco Trustsec&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;nbsp; AID: 43157A4E6832894FE4952D0A1F6167BB&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;nbsp; I-ID: fos01-l3-01&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;nbsp; A-ID-Info: fos01-ise-01v&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;nbsp; Credential Lifetime: 11:00:43 PST Jan 22 2015&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; PAC-Opaque: 000200B8000300010004001043157A4E6832894FE4952D0A1F6167BB0006009C00030100B3696FBA1F7ABE1DAB104CCB18E875850000001354483C8400093A80B5EF16086495444FD0BDB5A88AE9AA775DE1A1AC483A2770B0C5A22D00B2386EFA6BE4847D7CBF2A6FD3C4D623DCD624AB1916A9E3960E082A8897B45D894E9CFDAA6FA8BFF5CBB1E30D17CF985B2913BF6FB105EAE5103DA2E017FB35EA06887D45F99C7D27FC987AE25EF0358CF08CFB4F7D000AC3A42E87640BA1&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; Refresh timer is set for 12w5d&lt;/P&gt;&lt;P class="p1"&gt;fos01-l3-01#show cts environment-data&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;CTS Environment Data&lt;/P&gt;&lt;P class="p1"&gt;====================&lt;/P&gt;&lt;P class="p1"&gt;Current state = START&lt;/P&gt;&lt;P class="p1"&gt;Last status = Failed&lt;/P&gt;&lt;P class="p1"&gt;Environment data is empty&lt;/P&gt;&lt;P class="p1"&gt;State Machine is running&lt;/P&gt;&lt;P class="p1"&gt;Retry_timer (60 secs) is running&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;As you can see it says Last status = Failed.&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Enabling debug logging for cts outputs the following&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: CTS env-data: Time to retry env data download&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: &amp;nbsp; &amp;nbsp; cts_env_data START: during state env_data_start, got event 0(env_data_request)&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: @@@ cts_env_data START: env_data_start -&amp;gt; env_data_waiting_rsp&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: env_data_waiting_rsp_enter: state = WAITING_RESPONSE&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: cts_aaa_is_fragmented: (CTS env-data SM)NOT-FRAG attr_q(0)&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: env_data_request_action: state = WAITING_RESPONSE&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: cts_env_data_is_complete: FALSE, req(x0), rec(x0)&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.455: cts_env_data_is_complete: FALSE, req(x0), rec(x0), expect(x81), complete1(x85), complete2(xB5), complete3(x1485)&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: env_data_request_action: state = WAITING_RESPONSE, received = 0x0 request = 0x0&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: cts_env_data_aaa_req_setup : aaa_id = 4240&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: cts_aaa_req_setup: (CTS env-data SM)Private group appears DEAD, attempt public group&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: cts_aaa_req_setup: (CTS env-data SM)No public method list found&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: cts_aaa_req_setup: (CTS env-data SM)Failed to get AAA method list handle.&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: &amp;nbsp; &amp;nbsp; cts_env_data WAITING_RESPONSE: during state env_data_waiting_rsp, got event 7(env_data_failed)&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: @@@ cts_env_data WAITING_RESPONSE: env_data_waiting_rsp -&amp;gt; env_data_start&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: env_data_start_enter: state = START&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: env_data_error_action: state = START&lt;/P&gt;&lt;P class="p1"&gt;Oct 24 17:35:12.456: env_data_error_action: state = START, received = 0x0 request = 0x0&lt;/P&gt;&lt;P class="p1"&gt;Within ISE itself it shows a successful authentication and PAC generation. However the log messages there are as follows. Not sure if it is significant that it says Access-Reject status at the end.&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3" class="content_table_steps" style="width: 500px;"&gt;&lt;TBODY&gt;&lt;TR class="content_table_steps_highlight"&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15012&lt;/TD&gt;&lt;TD&gt;Selected Access Service&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11507&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12100&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request proposing EAP-FAST with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12102&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response and accepting EAP-FAST as negotiated&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12800&lt;/TD&gt;&lt;TD&gt;Extracted first TLS record; TLS handshake started&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12805&lt;/TD&gt;&lt;TD&gt;Extracted TLS ClientHello message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12806&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerHello message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12808&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerKeyExchange message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12810&lt;/TD&gt;&lt;TD&gt;Prepared TLS ServerDone message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12812&lt;/TD&gt;&lt;TD&gt;Extracted TLS ClientKeyExchange message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12804&lt;/TD&gt;&lt;TD&gt;Extracted TLS Finished message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12801&lt;/TD&gt;&lt;TD&gt;Prepared TLS ChangeCipherSpec message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12802&lt;/TD&gt;&lt;TD&gt;Prepared TLS Finished message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12816&lt;/TD&gt;&lt;TD&gt;TLS handshake succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12131&lt;/TD&gt;&lt;TD&gt;EAP-FAST built anonymous tunnel for purpose of PAC provisioning&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12125&lt;/TD&gt;&lt;TD&gt;EAP-FAST inner method started&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11521&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request/Identity for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11522&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11806&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request for inner method proposing EAP-MSCHAP with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11808&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-MSCHAP challenge-response for inner method and accepting EAP-MSCHAP as negotiated&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15041&lt;/TD&gt;&lt;TD&gt;Evaluating Identity Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15013&lt;/TD&gt;&lt;TD&gt;Selected Identity Source - Internal CTS Devices&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24213&lt;/TD&gt;&lt;TD&gt;Found SGA Device in Network Devices and AAA Clients&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22037&lt;/TD&gt;&lt;TD&gt;Authentication Passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11824&lt;/TD&gt;&lt;TD&gt;EAP-MSCHAP authentication attempt passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11810&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response for inner method containing MSCHAP challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11814&lt;/TD&gt;&lt;TD&gt;Inner EAP-MSCHAP authentication succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11519&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Success for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12128&lt;/TD&gt;&lt;TD&gt;EAP-FAST inner method finished successfully&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12126&lt;/TD&gt;&lt;TD&gt;EAP-FAST cryptobinding verification passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12200&lt;/TD&gt;&lt;TD&gt;Approved EAP-FAST client Tunnel PAC request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15016&lt;/TD&gt;&lt;TD&gt;Selected Authorization Profile -&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12173&lt;/TD&gt;&lt;TD&gt;Successfully finished EAP-FAST CTS PAC provisioning/update&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12105&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12104&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11401&lt;/TD&gt;&lt;TD&gt;Prepared RADIUS Access-Reject after the successful in-band PAC provisioning&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11504&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Failure&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11003&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Reject&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p2"&gt;Any insight would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p2"&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566192#M72402</guid>
      <dc:creator>matthewceroni</dc:creator>
      <dc:date>2019-03-11T05:08:16Z</dc:date>
    </item>
    <item>
      <title>Hi Mattew,I'm trying to</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566193#M72403</link>
      <description>&lt;P&gt;Hi Mattew,&lt;/P&gt;&lt;P&gt;I'm trying to integrate TrustSec as well, using Cisco ISE, on 3560 switch as a seed device. I'm getting the exact same symptoms as you do - the ISE reports that the switch has successfully authenticated, but no environmental data has been downloaded.&lt;/P&gt;&lt;P&gt;I followed this &lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/how_to_intro_macsec_ndac_guide.pdf"&gt;guide &lt;/A&gt;for configuring the ISE and the switch.&lt;/P&gt;&lt;P&gt;Have you been able to resolve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 19:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566193#M72403</guid>
      <dc:creator>oren_cohen</dc:creator>
      <dc:date>2015-03-31T19:39:26Z</dc:date>
    </item>
    <item>
      <title>I also have the same issue</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566194#M72404</link>
      <description>&lt;P&gt;I also have the same issue.&lt;/P&gt;&lt;P&gt;Has anyone found a solution yet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 22:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566194#M72404</guid>
      <dc:creator>tony.parker</dc:creator>
      <dc:date>2015-09-21T22:33:53Z</dc:date>
    </item>
    <item>
      <title>Can you post the output of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566195#M72405</link>
      <description>&lt;P&gt;Can you post the output of "show run aaa"? I was having the same issue and it was the syntax of the "aaa authorization network" statement. I was incorrectly specifying the method list.&lt;/P&gt;
&lt;P&gt;It should look like this:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;aaa authorization network [radius-server-group] group radius&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;I had it like this before and it wasn't working:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;aaa authorization network cts&amp;nbsp;group [radius-server-group]&lt;/PRE&gt;
&lt;P&gt;Good luck,&lt;/P&gt;
&lt;P&gt;Ryan&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566195#M72405</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2015-12-04T02:32:36Z</dc:date>
    </item>
    <item>
      <title>Check out my reply above and</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566196#M72406</link>
      <description>&lt;P&gt;Check out my reply above and see if that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 02:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566196#M72406</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2015-12-04T02:33:54Z</dc:date>
    </item>
    <item>
      <title>Hi, my AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566197#M72407</link>
      <description>&lt;P&gt;Hi, my&amp;nbsp;AAA Authorization network command is correct. Yet the problem persist. Anyone found any solution for this?&lt;/P&gt;
&lt;P&gt;Appreciate if anyone&amp;nbsp;could shed some light here.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2016 13:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/2566197#M72407</guid>
      <dc:creator>khorheesoo</dc:creator>
      <dc:date>2016-06-12T13:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco TrustSec Catalyst 3650</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3189239#M72408</link>
      <description>my problem was I forgot the&lt;BR /&gt;cts authorization list &amp;lt;auth-list&amp;gt;&lt;BR /&gt;there was an aaa radius list to use, but I never told it to use it.</description>
      <pubDate>Mon, 25 Sep 2017 18:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3189239#M72408</guid>
      <dc:creator>CCNASithk</dc:creator>
      <dc:date>2017-09-25T18:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Mattew,I'm trying to</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3216454#M72409</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I was just reading this and wondering what the result is if you run a "cts refresh environmental-data"? Does it pull down the data as expected?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 16:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3216454#M72409</guid>
      <dc:creator>derrick.ray1</dc:creator>
      <dc:date>2017-11-14T16:55:35Z</dc:date>
    </item>
    <item>
      <title>HELP ME - PAC it's OK, but the Environment-Data NOK</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3337521#M72412</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a CTS deployment with:&lt;/P&gt;
&lt;P&gt;- ISE v2.0.1_p4&lt;/P&gt;
&lt;P&gt;- Cisco switches 3850 (classification (dynamic - AuthZ from ISE) / propagation (SXP) / enforcement)&lt;/P&gt;
&lt;P&gt;- Cisco switches 6500 - Sup2T&amp;nbsp;&lt;SPAN&gt;(classification (static - IP-to-SGT) / propagation (SXP) / enforcement)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently the deployment&amp;nbsp;passed&amp;nbsp;to presents the problem on the environment-data download, from 3850 and 6K switches, where the status showing:&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;CTS Environment Data&lt;/P&gt;
&lt;P&gt;====================&lt;/P&gt;
&lt;P&gt;Current state = WAITING_RESPONSE&lt;/P&gt;
&lt;P&gt;Last status = Timeout waiting for response&lt;/P&gt;
&lt;P&gt;Environment data is empty&lt;/P&gt;
&lt;P&gt;State Machine is running&lt;/P&gt;
&lt;P&gt;Retry_timer (60 secs) is not running&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The symptom appear to be from ISE side... In some cases 3850 and 6500 switches I don't have the same problem on environment-data. The refresh &amp;lt;cts refresh environment-data&amp;gt; is working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if this symptom is&amp;nbsp;experienced by other colleagues? Please.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 02:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3337521#M72412</guid>
      <dc:creator>Rafael Trujilho</dc:creator>
      <dc:date>2018-02-26T02:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can you post the output of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3707314#M72415</link>
      <description>&lt;P&gt;It helped me.&lt;/P&gt;
&lt;P&gt;In my case:&lt;/P&gt;
&lt;PRE&gt;aaa group server radius ISE-GROUP&lt;BR /&gt; server name ISE&lt;BR /&gt;aaa authorization network ISE-GROUP group ISE-GROUP &lt;BR /&gt;cts authorization list ISE-GROUP&lt;BR /&gt;radius server ISE&lt;BR /&gt; address ipv4 x.x.x.x auth-port 1645 acct-port 1646&lt;BR /&gt; pac key xxxxxxxx&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Sep 2018 19:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3707314#M72415</guid>
      <dc:creator>bakurenko</dc:creator>
      <dc:date>2018-09-14T19:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can you post the output of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3882196#M72418</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/4880"&gt;@bakurenko&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;It helped me.&lt;/P&gt;
&lt;P&gt;In my case:&lt;/P&gt;
&lt;PRE&gt;aaa group server radius ISE-GROUP&lt;BR /&gt; server name ISE&lt;BR /&gt;aaa authorization network ISE-GROUP group ISE-GROUP &lt;BR /&gt;cts authorization list ISE-GROUP&lt;BR /&gt;radius server ISE&lt;BR /&gt; address ipv4 x.x.x.x auth-port 1645 acct-port 1646&lt;BR /&gt; pac key xxxxxxxx&lt;/PRE&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;This works for me as well - switch refreshed okay.&lt;/P&gt;
&lt;P&gt;What I did then -&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;no aaa authorization network ISE-GROUP group ISE-GROUP&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Now I enter what was 100% non-working before:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;aaa authorization network ISE group ISE-GROUP&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;cts&lt;FONT face="courier new,courier"&gt; auth list ISE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;crs&lt;FONT face="courier new,courier"&gt; refresh env&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;and I see it works. Miracle.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 17:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3882196#M72418</guid>
      <dc:creator>oatroshc</dc:creator>
      <dc:date>2019-06-30T17:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can you post the output of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3990229#M72420</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;This solutions works for me DNAC with ISE, just change the ports&amp;nbsp;&lt;/P&gt;&lt;P&gt;auth-port 1812 acct-port 1813 for&amp;nbsp;auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 16:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-catalyst-3650/m-p/3990229#M72420</guid>
      <dc:creator>Heriberto Diaz</dc:creator>
      <dc:date>2019-11-27T16:36:51Z</dc:date>
    </item>
  </channel>
</rss>

