<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius authentication with ISE - wrong IP address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519826#M73736</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are using ISE for radius authentication.&amp;nbsp; I have setup a new&amp;nbsp;Cisco switch stack at one of our locations and setup the network device in ISE.&amp;nbsp; Unfortunately, when trying to authenticate, the ISE logs show a failure of "Could not locate Network Device or AAA Client"&amp;nbsp;The reason for this failure is the log shows it's coming from the wrong IP address.&amp;nbsp; The IP address of the switch is 10.xxx.aaa.241, but the logs show it is 10.xxx.aaa.243.&amp;nbsp; I have removed and re-added the radius configs on both ISE and the switch, but it still comes in as .243.&amp;nbsp; There is another switch stack at that location (same model, IOS etc), that works properly.&lt;/P&gt;&lt;P&gt;The radius config on the switch:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login Comm group radius local&lt;BR /&gt;aaa authentication enable default enable&lt;BR /&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlanyy&lt;BR /&gt;radius server 10.xxx.yyy.zzz&lt;BR /&gt;&amp;nbsp;address ipv4 10.xxx.yyy.zzz auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;key 7 abcdefg&lt;/P&gt;&lt;P&gt;The log from ISE:&lt;/P&gt;&lt;P&gt;Overview&lt;BR /&gt;Event&amp;nbsp; 5405 RADIUS Request dropped&amp;nbsp;&lt;BR /&gt;Username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authorization Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication Details&lt;BR /&gt;Source Timestamp&amp;nbsp; 2014-07-30 08:48:51.923&amp;nbsp;&lt;BR /&gt;Received Timestamp&amp;nbsp; 2014-07-30 08:48:51.923&amp;nbsp;&lt;BR /&gt;Policy Server&amp;nbsp; ise&lt;BR /&gt;Event&amp;nbsp; 5405 RADIUS Request dropped&amp;nbsp;&lt;BR /&gt;Failure Reason&amp;nbsp; 11007 Could not locate Network Device or AAA Client&amp;nbsp;&lt;BR /&gt;Resolution&amp;nbsp; Verify whether the Network Device or AAA client is configured in: Administration &amp;gt; Network Resources &amp;gt; Network Devices&amp;nbsp;&lt;BR /&gt;Root cause&amp;nbsp; Could not find the network device or the AAA Client while accessing NAS by IP during authentication.&amp;nbsp;&lt;BR /&gt;Username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;User Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;IP Address&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Identity Store&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Identity Group&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Audit Session Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authentication Method&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authentication Protocol&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Service Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Network Device&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Device Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Location&amp;nbsp;&amp;nbsp;&lt;BR /&gt;NAS IP Address&amp;nbsp; 10.xxx.aaa.243&amp;nbsp;&lt;BR /&gt;NAS Port Id&amp;nbsp; tty2&amp;nbsp;&lt;BR /&gt;NAS Port Type&amp;nbsp; Virtual&amp;nbsp;&lt;BR /&gt;Authorization Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Posture Status&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Security Group&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Response Time&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other Attributes&lt;BR /&gt;ConfigVersionId&amp;nbsp; 107&amp;nbsp;&lt;BR /&gt;Device Port&amp;nbsp; 1645&amp;nbsp;&lt;BR /&gt;DestinationPort&amp;nbsp; 1812&amp;nbsp;&lt;BR /&gt;Protocol&amp;nbsp; Radius&amp;nbsp;&lt;BR /&gt;NAS-Port&amp;nbsp; 2&amp;nbsp;&lt;BR /&gt;AcsSessionID&amp;nbsp; ise1/186896437/1172639&amp;nbsp;&lt;BR /&gt;Device IP Address&amp;nbsp; 10.xxx.aaa.243&amp;nbsp;&lt;BR /&gt;CiscoAVPair&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Steps&lt;BR /&gt;&amp;nbsp; 11001&amp;nbsp; Received RADIUS Access-Request&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 11017&amp;nbsp; RADIUS created a new session&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 11007&amp;nbsp; Could not locate Network Device or AAA Client&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 5405&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test, I setup a device using the .243 address.&amp;nbsp; While ISE claims it authenticates, it really doesn't.&amp;nbsp; I have to use my local account to access the device.&lt;/P&gt;&lt;P&gt;Any advice on how to resolve this issue would be appreciated.&amp;nbsp; Please let me know if more information is needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:54:24 GMT</pubDate>
    <dc:creator>__Beth__</dc:creator>
    <dc:date>2019-03-11T04:54:24Z</dc:date>
    <item>
      <title>Radius authentication with ISE - wrong IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519826#M73736</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are using ISE for radius authentication.&amp;nbsp; I have setup a new&amp;nbsp;Cisco switch stack at one of our locations and setup the network device in ISE.&amp;nbsp; Unfortunately, when trying to authenticate, the ISE logs show a failure of "Could not locate Network Device or AAA Client"&amp;nbsp;The reason for this failure is the log shows it's coming from the wrong IP address.&amp;nbsp; The IP address of the switch is 10.xxx.aaa.241, but the logs show it is 10.xxx.aaa.243.&amp;nbsp; I have removed and re-added the radius configs on both ISE and the switch, but it still comes in as .243.&amp;nbsp; There is another switch stack at that location (same model, IOS etc), that works properly.&lt;/P&gt;&lt;P&gt;The radius config on the switch:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login Comm group radius local&lt;BR /&gt;aaa authentication enable default enable&lt;BR /&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlanyy&lt;BR /&gt;radius server 10.xxx.yyy.zzz&lt;BR /&gt;&amp;nbsp;address ipv4 10.xxx.yyy.zzz auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;key 7 abcdefg&lt;/P&gt;&lt;P&gt;The log from ISE:&lt;/P&gt;&lt;P&gt;Overview&lt;BR /&gt;Event&amp;nbsp; 5405 RADIUS Request dropped&amp;nbsp;&lt;BR /&gt;Username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authorization Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication Details&lt;BR /&gt;Source Timestamp&amp;nbsp; 2014-07-30 08:48:51.923&amp;nbsp;&lt;BR /&gt;Received Timestamp&amp;nbsp; 2014-07-30 08:48:51.923&amp;nbsp;&lt;BR /&gt;Policy Server&amp;nbsp; ise&lt;BR /&gt;Event&amp;nbsp; 5405 RADIUS Request dropped&amp;nbsp;&lt;BR /&gt;Failure Reason&amp;nbsp; 11007 Could not locate Network Device or AAA Client&amp;nbsp;&lt;BR /&gt;Resolution&amp;nbsp; Verify whether the Network Device or AAA client is configured in: Administration &amp;gt; Network Resources &amp;gt; Network Devices&amp;nbsp;&lt;BR /&gt;Root cause&amp;nbsp; Could not find the network device or the AAA Client while accessing NAS by IP during authentication.&amp;nbsp;&lt;BR /&gt;Username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;User Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Endpoint Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;IP Address&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Identity Store&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Identity Group&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Audit Session Id&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authentication Method&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Authentication Protocol&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Service Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Network Device&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Device Type&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Location&amp;nbsp;&amp;nbsp;&lt;BR /&gt;NAS IP Address&amp;nbsp; 10.xxx.aaa.243&amp;nbsp;&lt;BR /&gt;NAS Port Id&amp;nbsp; tty2&amp;nbsp;&lt;BR /&gt;NAS Port Type&amp;nbsp; Virtual&amp;nbsp;&lt;BR /&gt;Authorization Profile&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Posture Status&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Security Group&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Response Time&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other Attributes&lt;BR /&gt;ConfigVersionId&amp;nbsp; 107&amp;nbsp;&lt;BR /&gt;Device Port&amp;nbsp; 1645&amp;nbsp;&lt;BR /&gt;DestinationPort&amp;nbsp; 1812&amp;nbsp;&lt;BR /&gt;Protocol&amp;nbsp; Radius&amp;nbsp;&lt;BR /&gt;NAS-Port&amp;nbsp; 2&amp;nbsp;&lt;BR /&gt;AcsSessionID&amp;nbsp; ise1/186896437/1172639&amp;nbsp;&lt;BR /&gt;Device IP Address&amp;nbsp; 10.xxx.aaa.243&amp;nbsp;&lt;BR /&gt;CiscoAVPair&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Steps&lt;BR /&gt;&amp;nbsp; 11001&amp;nbsp; Received RADIUS Access-Request&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 11017&amp;nbsp; RADIUS created a new session&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 11007&amp;nbsp; Could not locate Network Device or AAA Client&amp;nbsp;&lt;BR /&gt;&amp;nbsp; 5405&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test, I setup a device using the .243 address.&amp;nbsp; While ISE claims it authenticates, it really doesn't.&amp;nbsp; I have to use my local account to access the device.&lt;/P&gt;&lt;P&gt;Any advice on how to resolve this issue would be appreciated.&amp;nbsp; Please let me know if more information is needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519826#M73736</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2019-03-11T04:54:24Z</dc:date>
    </item>
    <item>
      <title>Here is the debug from the</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519827#M73738</link>
      <description>&lt;P&gt;Here is the debug from the switch.&amp;nbsp; It shows the correct IP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Jul 29 19:10:18.346: RADIUS/ENCODE(00000280): ask "Password: "&lt;BR /&gt;Jul 29 19:10:18.346: RADIUS/ENCODE(00000280): send packet; GET_PASSWORD&lt;BR /&gt;Jul 29 19:10:21.568: RADIUS/ENCODE(00000280):Orig. component type = Exec&lt;BR /&gt;Jul 29 19:10:21.568: RADIUS:&amp;nbsp; AAA Unsupported Attr: interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [221] 4&amp;nbsp;&amp;nbsp; 130327720&lt;BR /&gt;Jul 29 19:10:21.568: RADIUS/ENCODE(00000280): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;BR /&gt;Jul 29 19:10:21.568: RADIUS(00000280): Config NAS IP: 10.xxx.aaa.241&lt;BR /&gt;Jul 29 19:10:21.568: RADIUS(00000280): Config NAS IPv6: ::&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS/ENCODE(00000280): acct_session_id: 630&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS(00000280): sending&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS(00000280): Sending a IPv4 Radius Packet&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS(00000280): Send Access-Request to 10.xxx..yyy.zzz:1812 id 1645/63,len 73&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; authenticator C8 AE FE 18 6E 2E 9E 5E - 07 A8 E9 D6 2A 40 41 B6&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 11&amp;nbsp; "username"&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty2"&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.xxx.aaa.241&lt;BR /&gt;Jul 29 19:10:21.572: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:10:26.609: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:10:26.609: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/63&lt;BR /&gt;Jul 29 19:10:26.609: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:10:31.628: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 12:10:31: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.xxx.yyy.zzz:1812,1813 is n&lt;BR /&gt;ot responding.&lt;BR /&gt;Jul 29 12:10:31: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.xxx..yyy.zzz:1812,1813 is being marked alive.&lt;BR /&gt;Jul 29 19:10:31.628: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/63&lt;BR /&gt;Jul 29 19:10:31.628: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:10:36.683: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:10:36.683: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/63&lt;BR /&gt;Jul 29 19:10:36.683: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:10:41.730: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:10:41.730: RADIUS: No response from (10.xxx..yyy.zzz:1812,1813) for id 1645/63&lt;BR /&gt;Jul 29 19:10:41.730: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;BR /&gt;Jul 29 19:10:41.730: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response; FAIL&lt;BR /&gt;Jul 29 19:10:43.750: RADIUS/ENCODE(00000280): ask "Password: "&lt;BR /&gt;Jul 29 19:10:43.750: RADIUS/ENCODE(00000280): send packet; GET_PASSWORD&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS/ENCODE(00000280):Orig. component type = Exec&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; AAA Unsupported Attr: interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [221] 4&amp;nbsp;&amp;nbsp; 130327720&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS/ENCODE(00000280): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS(00000280): Config NAS IP: 10.xxx.aaa.241&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS(00000280): Config NAS IPv6: ::&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS/ENCODE(00000280): acct_session_id: 630&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS(00000280): sending&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS(00000280): Sending a IPv4 Radius Packet&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS(00000280): Send Access-Request to 10.xxx..yyy.zzz:1812 id 1645/64,len 73&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; authenticator 40 8D 12 B8 9B 21 41 F6 - 71 90 77 A6 C0 45 AE C1&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 11&amp;nbsp; "username"&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty2"&lt;BR /&gt;Jul 29 19:10:56.334: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;BR /&gt;Jul 29 19:10:56.337: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.xxx.aaa.241&lt;BR /&gt;Jul 29 19:10:56.337: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:11:01.374: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:11:01.374: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/64&lt;BR /&gt;Jul 29 19:11:01.374: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:11:06.415: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:11:06.415: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/64&lt;BR /&gt;Jul 29 19:11:06.415: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:11:11.469: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:11:11.469: RADIUS: Retransmit to (10.xxx..yyy.zzz:1812,1813) for id 1645/64&lt;BR /&gt;Jul 29 19:11:11.469: RADIUS(00000280): Started 5 sec timeout&lt;BR /&gt;Jul 29 19:11:16.513: RADIUS(00000280): Request timed out!&lt;BR /&gt;Jul 29 19:11:16.513: RADIUS: No response from (10.xxx..yyy.zzz:1812,1813) for id 1645/64&lt;BR /&gt;Jul 29 19:11:16.513: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;BR /&gt;Jul 29 19:11:16.513: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response; FAIL&lt;BR /&gt;Jul 29 19:11:16.537: RADIUS/ENCODE(00000280): author with failed authen&lt;BR /&gt;Jul 29 19:11:16.537: RADIUS/ENCODE(00000280): send packet; BEGIN&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 17:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519827#M73738</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2014-07-30T17:04:16Z</dc:date>
    </item>
    <item>
      <title>can you issue , " radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519828#M73740</link>
      <description>&lt;P&gt;can you issue , " radius-server attribute 6 on-for-login-auth " to switch in config mode?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2014 07:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519828#M73740</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-08-01T07:10:32Z</dc:date>
    </item>
    <item>
      <title>Symptoms or IssueCisco ISE is</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519829#M73741</link>
      <description>&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp184567table184565" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;&lt;SPAN style="color: Black; font-style: normal; font-weight: bold; text-decoration: none; vertical-align: baseline"&gt;Symptoms or Issue&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;Cisco ISE is not able to identify the specified Network Access Device (NAD).&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;Conditions&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;Click the magnifying glass icon in Authentications to display the steps in the Authentication Report. The logs display the following error message:&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;11007 Could not locate Network Device or AAA Client Resolution&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;Possible Causes&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;The administrator did not correctly configure the network access device (NAD) type in Cisco ISE.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P class="pBl_BlockLabel"&gt;Resolution&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt;Add the NAD in Cisco ISE again, verifying the NAD type and settings.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 04 Aug 2014 10:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519829#M73741</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-08-04T10:37:21Z</dc:date>
    </item>
    <item>
      <title>Thank you Salodh, I added</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519830#M73742</link>
      <description>&lt;P&gt;Thank you Salodh, I added radius-server attribute 6 on-for-login-auth to the config and unfortunately, it did not resolve the problem.&lt;/P&gt;&lt;P&gt;Monanak, thank you for your reply.&amp;nbsp; The device is built properly in ISE.&amp;nbsp; The problem seems that when the request comes into ISE, it's using the wrong IP address.&amp;nbsp; The device IP address last octet ends in .241; however, ISE is seeing it come in as .243.&amp;nbsp; As a test, I build a device in ISE with .243 and while ISE thinks it is authenticating, the switch will not allow me in with my radius credentials.&lt;/P&gt;&lt;P&gt;I have attached a screen shot that shows my attempts.&amp;nbsp; The bottom four attempts are where it's using my test config for a .243 device.&amp;nbsp; The top attempts were after I removed the test device.&amp;nbsp; I hope this helps clarify the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 14:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519830#M73742</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2014-08-04T14:26:03Z</dc:date>
    </item>
    <item>
      <title>Well from the debug I would</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519831#M73743</link>
      <description>&lt;P&gt;Well from the debug I would say there may be an issue with the addressing of the radius server on the switch.&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 408pt; border-collapse: collapse;" width="544"&gt;&lt;TBODY&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; width: 408pt; height: 15pt; background-color: transparent;" width="544"&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;radius-server host 10.xxx.xxx.xxx key******** &amp;lt;--- Make sure this address and Key matches what you have in ISE PSN and that switch. Watch for spaces in your key at the begining or end of the string.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;What interface should your switch be sending the radius request?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;ip radius source-interface VlanXXX vrf default&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;Here is what my debug looks like when it is working correctly.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS/ENCODE(00000265): ask "Password: "&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS/ENCODE(00000265):Orig. component type = EXEC&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS(00000265): Config NAS IP: 10.xxx.xxx.251&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS/ENCODE(00000265): acct_session_id: 613&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS(00000265): sending&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS(00000265): Send Access-Request to 10.xxx.xxx.35:1645 id 1645/110, len 104&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; authenticator 97 FB CF 13 2E 6F 62 5D - 5B 10 1B BD BA EB C9 E3&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 9&amp;nbsp;&amp;nbsp; "admin"&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; Reply-Message&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [18]&amp;nbsp; 12&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 50 61 73 73 77 6F 72 64 3A 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Password: ]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty3"&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; Calling-Station-Id&amp;nbsp; [31]&amp;nbsp; 15&amp;nbsp; "10.xxx.xxx.100"&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; Service-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [6]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Login&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.xxx.xxx.251&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS(00000265): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS: Received from id 1645/110 10.xxx.xxx.35:1645, Access-Accept, len 127&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; authenticator 1B 98 AB 4F B1 F4 81 41 - 3D E1 E9 DB 33 52 54 C1&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 9&amp;nbsp;&amp;nbsp; "admin"&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [24]&amp;nbsp; 40&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 52 65 61 75 74 68 53 65 73 73 69 6F 6E 3A 30 61&amp;nbsp; [ReauthSession:0a]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 30 63 66 65 32 33 30 30 30 31 46 37 30 37 35 33&amp;nbsp; [0cfe230001F70753]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 44 46 45 35 46 37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ DFE5F7]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp; Class&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [25]&amp;nbsp; 58&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 43 41 43 53 3A 30 61 30 63 66 65 32 33 30 30 30&amp;nbsp; [CACS:0a0cfe23000]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 31 46 37 30 37 35 33 44 46 45 35 46 37 3A 50 52&amp;nbsp; [1F70753DFE5F7:PR]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 59 49 53 45 30 30 32 2F 31 39 33 37 39 34 36 39&amp;nbsp; [YISE002/19379469]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS:&amp;nbsp;&amp;nbsp; 38 2F 32 30 36 33 31 36&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ 8/206316]&lt;BR /&gt;Aug&amp;nbsp; 4 15:58:47 EST: RADIUS(00000265): Received from id 1645/110&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;---------------------------------------------------------------------------------------------------------------This is after I added the incorrect Radius server address.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS/ENCODE(00000268): ask "Password: "&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS/ENCODE(00000268):Orig. component type = EXEC&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS(00000268): Config NAS IP: 10.xxx.xxx.251&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS/ENCODE(00000268): acct_session_id: 616&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS(00000268): sending&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS(00000268): Send Access-Request to 10.xxx.xxx.55:1645 id 1645/112, len 104&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; authenticator FC 94 BA 5D 75 1F 84 08 - E0 56 05 3A 7F BC FB BB&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 9&amp;nbsp;&amp;nbsp; "admin"&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; Reply-Message&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [18]&amp;nbsp; 12&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp;&amp;nbsp; 50 61 73 73 77 6F 72 64 3A 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Password: ]&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty7"&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; Calling-Station-Id&amp;nbsp; [31]&amp;nbsp; 15&amp;nbsp; "10.xxx.xxx.100"&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; Service-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [6]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Login&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.xxx.xxx.251&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:19 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:23 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:23 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:23 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:29 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:29 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:29 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:33 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:33 EST: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.xxx.xxx.55:1645,1646 is not responding.&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:33 EST: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.xxx.xxx.55:1645,1646 is being marked alive.&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:33 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:33 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:38 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:38 EST: RADIUS: Fail-over to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:38 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:43 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:43 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:43 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:48 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:48 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:48 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:53 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:53 EST: %RADIUS-4-RADIUS_DEAD: RADIUS server 10.xxx.xxx.55:1645,1646 is not responding.&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:53 EST: %RADIUS-4-RADIUS_ALIVE: RADIUS server 10.xxx.xxx.55:1645,1646 is being marked alive.&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:53 EST: RADIUS: Retransmit to (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:53 EST: RADIUS(00000268): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:57 EST: RADIUS(00000268): Request timed out&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:57 EST: RADIUS: No response from (10.xxx.xxx.55:1645,1646) for id 1645/112&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:57 EST: RADIUS/DECODE: parse response no app start; FAIL&lt;BR /&gt;Aug&amp;nbsp; 4 16:05:57 EST: RADIUS/DECODE: parse response; FAIL&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;This is a default template I use for all my devices routers or switches hope it helps.&amp;nbsp;I have two PSN's that is why we have two radius-server host commands..&lt;/FONT&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 503pt; border-collapse: collapse;" width="670"&gt;&lt;TBODY&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; width: 503pt; height: 15pt; background-color: transparent;" width="670"&gt;&lt;FONT face="Calibri"&gt;aaa authentication login vty group radius local enable&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;aaa authentication login con group radius local enable&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;aaa authentication dot1x default group radius&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;aaa authorization network default group radius&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;aaa accounting system default start-stop group radius&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt; mso-height-source: userset;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;ip radius source-interface VlanXXX vrf default&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt; mso-height-source: userset;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server attribute 6 on-for-login-auth&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server attribute 6 support-multiple&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server attribute 8 include-in-access-req&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server attribute 25 access-request include&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server dead-criteria time 30 tries 3&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server host xxx.xxx.xxx.xxx auth-port 1645 acct-port 1646 key *********&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server host xxx.xxx.xxx.xxx auth-port 1645 acct-port 1646 key *********&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;FONT face="Calibri"&gt;radius-server vsa send accounting&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR height="20" style="height: 15pt;"&gt;&lt;TD height="20" style="border: 0px black; height: 15pt; background-color: transparent;"&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;radius-server vsa send authentication&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;You can use this in the switch to test radius &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;test aaa group radius server 10.xxx.xxx.xxx &amp;lt;username&amp;gt; &amp;lt;password&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;COLGROUP&gt;&lt;COL style="width: 503pt; mso-width-source: userset; mso-width-alt: 24502;" width="670" /&gt;&lt;/COLGROUP&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;COLGROUP&gt;&lt;COL style="width: 408pt; mso-width-source: userset; mso-width-alt: 19894;" width="544" /&gt;&lt;/COLGROUP&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 04 Aug 2014 20:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519831#M73743</guid>
      <dc:creator>embowers1</dc:creator>
      <dc:date>2014-08-04T20:41:23Z</dc:date>
    </item>
    <item>
      <title>Thank you embowers!  We are</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519832#M73744</link>
      <description>&lt;P&gt;Thank you embowers!&amp;nbsp; We are making progress!&amp;nbsp; I am not quite sure what did it, but I am now able to authenticate with radius.&amp;nbsp; The only issue is that it fails the first four times and then it works.&amp;nbsp; (All in one session, I don't actually have to reenter my username and password).&amp;nbsp; Here is a piece of the debug:&lt;/P&gt;&lt;P&gt;Aug&amp;nbsp; 7 18:33:41.683: RADIUS: Retransmit to (10.xxx.yyy.zzz:1812,1813) for id 1645/97&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.683: RADIUS(000004B6): Started 5 sec timeout&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.718: RADIUS: Received from id 1645/97 10.xxx.yyy.zzz:1812, Access-Reject, len 20&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.718: RADIUS:&amp;nbsp; authenticator xxx&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.718: RADIUS: response-authenticator decrypt fail, pak len 20&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.718: RADIUS: packet dump: xxx&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.718: RADIUS: expected digest: xxx&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.721: RADIUS: response authen: xxx&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.721: RADIUS: request&amp;nbsp; authen: xxx&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:41.721: RADIUS: Response (97) failed decrypt&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:46.733: RADIUS(000004B6): Request timed out!&lt;BR /&gt;Aug&amp;nbsp; 7 18:33:46.733: RADIUS: Retransmit to (10.xxx.yyy.zzz:1812,1813) for id 1645/97&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, thank you for the tip on how to test it from the switch!&amp;nbsp; I will save that one for future use!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 20:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519832#M73744</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2014-08-07T20:58:25Z</dc:date>
    </item>
    <item>
      <title>Beth,   For this issue I</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519833#M73745</link>
      <description>&lt;P&gt;Beth,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; For this issue I would like to know what type of switch that debug came from and the Version of IOS. What is concerning is the decrypt failure. I will throw a guess that it is a 15.x image?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 12:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519833#M73745</guid>
      <dc:creator>embowers1</dc:creator>
      <dc:date>2014-08-08T12:14:51Z</dc:date>
    </item>
    <item>
      <title>Hi Embowers,  Thank you for</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519834#M73746</link>
      <description>&lt;P&gt;Hi Embowers,&amp;nbsp; Thank you for the reply.&amp;nbsp; It's Cisco IOS Software, C2960X Software (C2960X-UNIVERSALK9-M), Version 15.0(2)EX5, RELEASE SOFTWARE (fc1)&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 14:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519834#M73746</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2014-08-08T14:00:15Z</dc:date>
    </item>
    <item>
      <title>BethRemove your (radius</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519835#M73747</link>
      <description>&lt;P&gt;Beth&lt;/P&gt;&lt;P&gt;Remove your (radius-server host 10.x.x.x ...ect)&amp;nbsp;line(s)&amp;nbsp;and try this command and see if the problem goes away. The new portion is the phrase &lt;STRONG&gt;non-standard &lt;/STRONG&gt;lets see if that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius-server host 10.xxx.xxx.xxx auth-port 1645 acct-port 1646 non-standard key ******&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 14:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519835#M73747</guid>
      <dc:creator>embowers1</dc:creator>
      <dc:date>2014-08-08T14:17:43Z</dc:date>
    </item>
    <item>
      <title>Thank you!  I had used the</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519836#M73748</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp; I had used the newer radius server command as this one will be deprecated soon.&amp;nbsp; Apparently that was the problem, because since I used your suggestion, radius is working as it should.&amp;nbsp; I really do appreciate you help.&amp;nbsp; Have a great weekend!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2014 15:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/2519836#M73748</guid>
      <dc:creator>__Beth__</dc:creator>
      <dc:date>2014-08-08T15:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Thank you!  I had used the</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/3306342#M73749</link>
      <description>&lt;P&gt;So, this thread is 3 1/2 years old now, but I found a more correct solution to the problem you were having. I was having it as well. I changed the IP address of a RADIUS client and could no longer authenticate. What I ended up doing was taking a packet capture from my RADIUS server (Windows NPS) and found that the source IP of the PACKET, not the NAS-ID, was the old IP address. I removed and readded the ip radius source-interface Vlan x command and that did the trick without having to reconfigure the RADIUS server parameters or move from the new radius config to the deprecated config. Hope this helps someone else with the same problem.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 20:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-wrong-ip-address/m-p/3306342#M73749</guid>
      <dc:creator>smace</dc:creator>
      <dc:date>2018-01-04T20:34:43Z</dc:date>
    </item>
  </channel>
</rss>

