<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LOG cisco ISE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177376#M1075393</link>
    <description>&lt;P&gt;...or if the PSNs are behind a load balancer and the LB directed the non-initial packet to the wrong PSN.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Nov 2020 13:40:11 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-11-02T13:40:11Z</dc:date>
    <item>
      <title>LOG cisco ISE</title>
      <link>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177259#M1075382</link>
      <description>&lt;P&gt;Hello can someone please help me understand this live log from cisco ise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Overview&lt;BR /&gt;Event 5400 Authentication failed&lt;BR /&gt;Username host/DESKTOP-QEDO10M&lt;BR /&gt;Endpoint Id 70:5A:0F:2A:47:DE&lt;BR /&gt;Endpoint Profile&lt;BR /&gt;Authentication Policy Wired&lt;BR /&gt;Authorization Policy Wired&lt;BR /&gt;Authorization Result&lt;/P&gt;&lt;P&gt;Authentication Details&lt;BR /&gt;Source Timestamp 2020-11-02 09:22:20.802&lt;BR /&gt;Received Timestamp 2020-11-02 09:22:20.802&lt;BR /&gt;Policy Server -ISE-PAN&lt;BR /&gt;Event 5400 Authentication failed&lt;BR /&gt;Failure Reason 12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist&lt;BR /&gt;Resolution Verify known NAD issues and published bugs. Verify NAD configuration. Turn debug log on DEBUG level to troubleshoot the problem.&lt;BR /&gt;Root cause Session was not found on this PSN. Possible unexpected NAD behavior. Session belongs to this PSN according to hostname but may has already been reaped by timeout. This packet arrived too late.&lt;BR /&gt;Username host/DESKTOP-QEDO10M&lt;BR /&gt;Endpoint Id 70:5A:0F:2A:47:DE&lt;BR /&gt;Calling Station Id 70-5A-0F-2A-47-DE&lt;BR /&gt;IPv4 Address 10.100.105.53&lt;BR /&gt;Audit Session Id 0AC8D0640000000D00202A45&lt;BR /&gt;Authentication Method dot1x&lt;BR /&gt;Service Type Framed&lt;BR /&gt;Network Device Test&lt;BR /&gt;Device Type All Device Types#Wired&lt;BR /&gt;Location All Locations#-HQ&lt;BR /&gt;NAS IPv4 Address 10.200.208.100&lt;BR /&gt;NAS Port Id GigabitEthernet1/0/10&lt;BR /&gt;NAS Port Type Ethernet&lt;BR /&gt;Response Time 5 milliseconds&lt;/P&gt;&lt;P&gt;Other Attributes&lt;BR /&gt;ConfigVersionId 148&lt;BR /&gt;Device Port 1645&lt;BR /&gt;DestinationPort 1812&lt;BR /&gt;RadiusPacketType AccessRequest&lt;BR /&gt;Protocol Radius&lt;BR /&gt;NAS-Port 50110&lt;BR /&gt;Framed-MTU 1500&lt;BR /&gt;NetworkDeviceProfileId b0699505-3150-4215-a80e-6753d45bf56c&lt;BR /&gt;IsThirdPartyDeviceFlow false&lt;BR /&gt;AcsSessionID -ISE-PAN/392570377/111256&lt;BR /&gt;EndPointMACAddress 70-5A-0F-2A-47-DE&lt;BR /&gt;ISEPolicySetName Wired&lt;BR /&gt;DTLSSupport Unknown&lt;BR /&gt;Network Device Profile Cisco&lt;BR /&gt;Location Location#All Locations#-HQ&lt;BR /&gt;Device Type Device Type#All Device Types#Wired&lt;BR /&gt;IPSEC IPSEC#Is IPSEC Device#No&lt;BR /&gt;RADIUS Username host/DESKTOP-QEDO10M&lt;BR /&gt;Device IP Address 10.200.208.100&lt;BR /&gt;CPMSessionID 0AC8D0640000000D00202A45&lt;BR /&gt;Called-Station-ID 3C:41:0E:F2:25:0A&lt;BR /&gt;CiscoAVPair service-type=Framed,&lt;BR /&gt;audit-session-id=0AC8D0640000000D00202A45,&lt;BR /&gt;method=dot1x&lt;/P&gt;&lt;P&gt;Result&lt;BR /&gt;RadiusPacketType AccessReject&lt;/P&gt;&lt;P&gt;Session Events&lt;BR /&gt;&lt;BR /&gt;Steps&lt;BR /&gt;11001 Received RADIUS Access-Request&lt;BR /&gt;11017 RADIUS created a new session&lt;BR /&gt;15049 Evaluating Policy Group&lt;BR /&gt;15008 Evaluating Service Selection Policy&lt;BR /&gt;15048 Queried PIP - Normalised Radius.RadiusFlowType&lt;BR /&gt;15048 Queried PIP - DEVICE.Device Type&lt;BR /&gt;12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist&lt;BR /&gt;11504 Prepared EAP-Failure&lt;BR /&gt;11003 Returned RADIUS Access-Reject&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 10:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177259#M1075382</guid>
      <dc:creator>Tutu</dc:creator>
      <dc:date>2020-11-02T10:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: LOG cisco ISE</title>
      <link>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177328#M1075389</link>
      <description>Hi, it seems that you are using distributed PSNs. Not sure what flow is&lt;BR /&gt;triggering this for you but but the message states that the radius packet&lt;BR /&gt;came to this PSN is not an initial access request message. Instead it's a&lt;BR /&gt;message for an existing conversation and since this PSN has no context&lt;BR /&gt;about this conversation it dropped it.&lt;BR /&gt;&lt;BR /&gt;Typical example, you have user redirected to guest portal. The user&lt;BR /&gt;authenticated initial radius request to PSN-1 but PSN-1 responded to user&lt;BR /&gt;with guest portal redirection with URL of the portal pointing to PSN-2.&lt;BR /&gt;PSN-2 will drop the next message that want to access guest portal since it&lt;BR /&gt;didn't get the initial request.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Mon, 02 Nov 2020 12:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177328#M1075389</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-02T12:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: LOG cisco ISE</title>
      <link>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177376#M1075393</link>
      <description>&lt;P&gt;...or if the PSNs are behind a load balancer and the LB directed the non-initial packet to the wrong PSN.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 13:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/log-cisco-ise/m-p/4177376#M1075393</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-11-02T13:40:11Z</dc:date>
    </item>
  </channel>
</rss>

