<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NenoNothing to do with that in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527212#M73513</link>
    <description>&lt;P&gt;Neno&lt;/P&gt;&lt;P&gt;Nothing to do with that,&lt;/P&gt;&lt;P&gt;The devices will use RADIUS to authenticate fine; databass, credentials, etc fine.&lt;/P&gt;&lt;P&gt;However they send keepalives to validate the RADIUS server is still there.&amp;nbsp; ISE doesn't implement this and ISE logs get full of rejections.&amp;nbsp; The end devices are unable to prioritise which ISE to used based on up/down.&amp;nbsp; But still work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was just a note to everyone so they are aware of the issue,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2014 08:57:51 GMT</pubDate>
    <dc:creator>Ian Cowley</dc:creator>
    <dc:date>2014-08-18T08:57:51Z</dc:date>
    <item>
      <title>ISE v1.2 - Status-Server - 5405 RADIUS Request dropped</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527210#M73509</link>
      <description>&lt;P&gt;Just a note:&lt;/P&gt;&lt;P&gt;Some devices send regular RADIUS status messages;&lt;/P&gt;&lt;P&gt;The ISE drops these as&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event: 5405 RADIUS Request dropped&lt;/P&gt;&lt;P&gt;Failure Reason: 11031 RADIUS packet type is not a valid Request&lt;/P&gt;&lt;P&gt;Root cause: RADIUS packet type is not a valid Request.&lt;/P&gt;&lt;P&gt;Wireshark shows:-&lt;/P&gt;&lt;P&gt;Code: Status-Server (12)&lt;BR /&gt;Attribute Value Pairs:&lt;BR /&gt;AVP: l=6&amp;nbsp; t=Service-Type(6): Shell-User(6)&lt;BR /&gt;AVP: l=18&amp;nbsp; t=Message-Authenticator(80): df48bb4b50f0a772bd7c891ef6548c68&lt;BR /&gt;AVP: l=6&amp;nbsp; t=NAS-IP-Address(4): 10.1.1.1&lt;/P&gt;&lt;P&gt;I believe that ISE should accept and respond to these messages RFC5997&amp;nbsp; up2866.&lt;/P&gt;&lt;P&gt;A RADIUS server or proxy implementing this specification SHOULD respond to a Status-Server packet with an Access-Accept (authentication port) or Accounting-Response (accounting port).&amp;nbsp; An Access-Challenge response is NOT RECOMMENDED.&amp;nbsp; An Access-Reject response MAY be used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527210#M73509</guid>
      <dc:creator>Ian Cowley</dc:creator>
      <dc:date>2019-03-11T04:56:38Z</dc:date>
    </item>
    <item>
      <title>Silly question but you do</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527211#M73511</link>
      <description>&lt;P&gt;Silly question but you do have the NAS added in ISE's database?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 22:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527211#M73511</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-08-15T22:38:09Z</dc:date>
    </item>
    <item>
      <title>NenoNothing to do with that</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527212#M73513</link>
      <description>&lt;P&gt;Neno&lt;/P&gt;&lt;P&gt;Nothing to do with that,&lt;/P&gt;&lt;P&gt;The devices will use RADIUS to authenticate fine; databass, credentials, etc fine.&lt;/P&gt;&lt;P&gt;However they send keepalives to validate the RADIUS server is still there.&amp;nbsp; ISE doesn't implement this and ISE logs get full of rejections.&amp;nbsp; The end devices are unable to prioritise which ISE to used based on up/down.&amp;nbsp; But still work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was just a note to everyone so they are aware of the issue,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 08:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-v1-2-status-server-5405-radius-request-dropped/m-p/2527212#M73513</guid>
      <dc:creator>Ian Cowley</dc:creator>
      <dc:date>2014-08-18T08:57:51Z</dc:date>
    </item>
  </channel>
</rss>

