<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please remove the WLC from in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/3205538#M90838</link>
    <description>&lt;P&gt;Dear Support&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got the same problem.&lt;/P&gt;
&lt;P&gt;What the workaround for this case ?&lt;/P&gt;
&lt;P&gt;I was try to re enter the secret-shared but the problem still occurs.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Muhamad&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2017 08:06:22 GMT</pubDate>
    <dc:creator>nohfendi1</dc:creator>
    <dc:date>2017-10-26T08:06:22Z</dc:date>
    <item>
      <title>ISE Radius accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488178#M90833</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are seen some error messages as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1" id="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a" style="display: block;"&gt;&lt;SPAN id="section.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN id="8793d5ff0a0a3c08548b83ca00e3bc1a" style="display: block; margin-bottom: 5px;"&gt;&lt;SPAN style=""&gt;&lt;SPAN&gt;11038 RADIUS Accounting-Request header contains invalid Authenticator field."&lt;BR /&gt;&lt;BR /&gt;ISE cannot validate the Authenticator field in the header of the RADIUS Accounting-Request packet. Note that the Authenticator field should not be confused with the Message-Authenticator RADIUS attribute.&lt;BR /&gt;Ensure that the RADIUS Shared Secret configured on the AAA client matches that configured for the selected Network Device on the ISE server. Also, ensure that the AAA client has no hardware problems or problems with RADIUS compatibility.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1" style="display: block;"&gt;&lt;SPAN&gt;&lt;SPAN style="display: block; margin-bottom: 5px;"&gt;&lt;SPAN style=""&gt;&lt;SPAN&gt;we have removed the shared secrete and reapplied&amp;nbsp; but still this error shows up.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1" style="display: block;"&gt;&lt;SPAN&gt;&lt;SPAN style="display: block; margin-bottom: 5px;"&gt;&lt;SPAN style=""&gt;&lt;SPAN&gt;any idea?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1" style="display: block;"&gt;&lt;SPAN&gt;&lt;SPAN style="display: block; margin-bottom: 5px;"&gt;&lt;SPAN style=""&gt;&lt;SPAN&gt;thanks &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1" style="display: block;"&gt;&lt;SPAN&gt;&lt;SPAN style="display: block; margin-bottom: 5px;"&gt;&lt;SPAN style=""&gt;&lt;SPAN&gt;Lance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488178#M90833</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2019-03-11T04:40:47Z</dc:date>
    </item>
    <item>
      <title>Please remove the WLC from</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488179#M90834</link>
      <description>&lt;P&gt;Please remove the WLC from ISE, register there after rebooting the WLC once.&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 11:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488179#M90834</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-05-01T11:23:51Z</dc:date>
    </item>
    <item>
      <title>CSCtw56571Symptom:When aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488180#M90835</link>
      <description>&lt;DIV class="releaseNoteText"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;CSCtw56571&lt;A name="description" style="text-decoration:none"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;BR /&gt;When aaa dot1x accounting and trustsec accounting are both enabled, RADIUS accounting does not work. When the ISE receives and accounting packet, it receives the following error.&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;BR /&gt;The following command needs to be present on the device.&lt;BR /&gt;&lt;BR /&gt;aaa accounting dot1x default start-stop group radius&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;BR /&gt;Two workarounds:&lt;BR /&gt;&lt;BR /&gt;1. Disable aaa accounting :&lt;BR /&gt;&lt;BR /&gt;no aaa accounting dot1x default start-stop group radius&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2. Define two AAA server groups: one with PAC for TrustSec and the other without PAC for non-TrustSec.&lt;BR /&gt;&lt;BR /&gt;Below is a snippet of sample configuration for Catalyst 3850 03.03.02SE, tested ok with ISE:&lt;BR /&gt;&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!! Define two radius servers;&lt;BR /&gt;!! one uses ports 1645 and 1646 and&lt;BR /&gt;!! the other uses PAC and ports 1812 and 1813&lt;BR /&gt;radius server ise.demo.local&lt;BR /&gt;address ipv4 10.1.100.21 auth-port 1645 acct-port 1646&lt;BR /&gt;automate-tester username radius-test ignore-acct-port idle-time 5&lt;BR /&gt;key ISEc0ld&lt;BR /&gt;!&lt;BR /&gt;radius server ise.demo.local+pac&lt;BR /&gt;address ipv4 10.1.100.21 auth-port 1812 acct-port 1813&lt;BR /&gt;pac key ISEc0ld&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ISE+PAC&lt;BR /&gt;server name ise.demo.local+pac&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ISE&lt;BR /&gt;server name ise.demo.local&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group ISE&lt;BR /&gt;aaa authentication dot1x authc-dot1x group ISE&lt;BR /&gt;aaa authorization network default group ISE&lt;BR /&gt;aaa authorization network cts-mlist group ISE+PAC&lt;BR /&gt;aaa accounting update newinfo periodic 15&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE&lt;BR /&gt;aaa accounting network acct-net start-stop group ISE&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;client 10.1.100.21 server-key ISEc0ld&lt;BR /&gt;auth-type any&lt;BR /&gt;!&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 mac format ietf upper-case&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!!!! CTS configuration !!!!!!!!!&lt;BR /&gt;cts authorization list cts-mlist&lt;BR /&gt;cts sgt 2&lt;BR /&gt;cts logging verbose&lt;BR /&gt;cts role-based enforcement&lt;BR /&gt;cts role-based enforcement vlan-list 10,20,99-100,200&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Further Problem Description:&lt;/B&gt;&lt;BR /&gt;The documentation guide for trustsec shows that aaa accounting is enabled, however once that is done the RADIus accounting is broken and we see the following error when the ISE receives an accounting packet :&lt;BR /&gt;&lt;BR /&gt;11038 RADIUS Accounting-Request header contains invalid Authenticator field&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Jun 2014 11:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488180#M90835</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-06-12T11:22:43Z</dc:date>
    </item>
    <item>
      <title>On the Network device from</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488181#M90836</link>
      <description>&lt;P&gt;On the Network device from which you're receiving these Accounting packets, ensure that both the Authentication server and Accounting server is set to the same ISE IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gurudatt&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2014 06:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488181#M90836</guid>
      <dc:creator>Gurudatt Pai</dc:creator>
      <dc:date>2014-06-19T06:55:03Z</dc:date>
    </item>
    <item>
      <title>Just disabling the accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488182#M90837</link>
      <description>&lt;P&gt;Just disabling the accounting tester fixed the same issue for me without adding 2 radius groups.&lt;/P&gt;
&lt;P&gt;radius server MEGATRON&lt;BR /&gt;&amp;nbsp;address ipv4 x.x.x.x auth-port 1812 acct-port 1813&lt;BR /&gt;&amp;nbsp;automate-tester username ise-check ignore-acct-port idle-time 5&lt;BR /&gt;&amp;nbsp;pac key !radius-key!&lt;/P&gt;
&lt;P&gt;aaa group server radius ISE&lt;BR /&gt;&amp;nbsp;server name MEGATRON&lt;BR /&gt;&amp;nbsp;ip radius source-interface Loopback0&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x default group ISE&lt;BR /&gt;aaa authorization network default group ISE&lt;BR /&gt;aaa authorization network CTS group ISE&lt;BR /&gt;aaa authorization auth-proxy default group ISE&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE&lt;BR /&gt;aaa accounting system default start-stop group ISE&lt;BR /&gt;cts authorization list CTS&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 21:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/2488182#M90837</guid>
      <dc:creator>fashour</dc:creator>
      <dc:date>2015-12-04T21:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Please remove the WLC from</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/3205538#M90838</link>
      <description>&lt;P&gt;Dear Support&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got the same problem.&lt;/P&gt;
&lt;P&gt;What the workaround for this case ?&lt;/P&gt;
&lt;P&gt;I was try to re enter the secret-shared but the problem still occurs.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Muhamad&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 08:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/3205538#M90838</guid>
      <dc:creator>nohfendi1</dc:creator>
      <dc:date>2017-10-26T08:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Radius accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/4051852#M559135</link>
      <description>&lt;P&gt;Make sure your ISE-&amp;gt;NetworkDevice-&amp;gt;WLC password is same as your WLC-&amp;gt;Security-&amp;gt;radius-&amp;gt;Accounting-&amp;gt;ServerAddress(x.y.z.w) password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sanket&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 08:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-radius-accounting/m-p/4051852#M559135</guid>
      <dc:creator>sanket</dc:creator>
      <dc:date>2020-03-25T08:31:28Z</dc:date>
    </item>
  </channel>
</rss>

