<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trustsec Network Authorization not Working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5075928#M1111534</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1605542"&gt;@titusroz03&lt;/a&gt; have you configured &lt;STRONG&gt;cts authorization &amp;lt;methodlistname&amp;gt; list cts&lt;/STRONG&gt; command?&lt;/P&gt;
&lt;PRE class="wp-block-preformatted"&gt;&lt;SPAN&gt;&lt;EM&gt;aaa authorization network CTS group ISE_RADIUS&lt;BR /&gt;cts authorization list CTS&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2018/05/08/cisco-trustsec-enforcement-using-cisco-ise/" target="_self"&gt;Here&lt;/A&gt; is a working example &lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 08:37:08 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-04-23T08:37:08Z</dc:date>
    <item>
      <title>Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5075914#M1111533</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am newly building trustsec in my environment,trying to add one of the switch under trustsec. Have configured Trustsec settings and COA on the ISE for the switch and added the appropriate aaa commands , radius servers and cts commands.But still switch couldn't download the pac and environment data from ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show cts pacs&lt;BR /&gt;No PACs found in the key store.&lt;/P&gt;&lt;P&gt;show cts environment-data&lt;BR /&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = WAITING_RESPONSE&lt;BR /&gt;Last status = In Progress&lt;BR /&gt;Environment data is empty&lt;BR /&gt;State Machine is running&lt;BR /&gt;Retry_timer (60 secs) is running..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network TRUSTSEC group radius&lt;/P&gt;&lt;P&gt;aaa accounting identity default start-stop group radius&lt;/P&gt;&lt;P&gt;radius server xxxx&lt;BR /&gt;address ipv4 xx.xx.xx.xx auth-port 1812 acct-port 1813&lt;BR /&gt;pac key 7 12483612111E1E011A2A717D24653017&lt;/P&gt;&lt;P&gt;dynamic author is added too.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5075914#M1111533</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-23T08:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5075928#M1111534</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1605542"&gt;@titusroz03&lt;/a&gt; have you configured &lt;STRONG&gt;cts authorization &amp;lt;methodlistname&amp;gt; list cts&lt;/STRONG&gt; command?&lt;/P&gt;
&lt;PRE class="wp-block-preformatted"&gt;&lt;SPAN&gt;&lt;EM&gt;aaa authorization network CTS group ISE_RADIUS&lt;BR /&gt;cts authorization list CTS&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2018/05/08/cisco-trustsec-enforcement-using-cisco-ise/" target="_self"&gt;Here&lt;/A&gt; is a working example &lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 08:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5075928#M1111534</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-23T08:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076053#M1111539</link>
      <description>&lt;P&gt;Yes..It is configured already.&lt;/P&gt;&lt;P&gt;aaa authorization network TRUSTSEC group ISE_RADIUS&lt;/P&gt;&lt;P&gt;cts authorization list TRUSTSEC..&lt;/P&gt;&lt;P&gt;And I could also authenticate from switch to ISE through radius.So radius connectivity is fine.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 10:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076053#M1111539</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-23T10:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076068#M1111540</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1605542"&gt;@titusroz03&lt;/a&gt; the message states WAITING_RESPONSE (from ISE). Is ISE configured correctly? Does ISE receive the request from the NAD? Is the RADIUS request from the correct IP that is configured in ISE for that NAD?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 10:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076068#M1111540</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-23T10:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076193#M1111542</link>
      <description>&lt;P&gt;Which version of ISE you're using? please note that TLS 1.0 must be enabled before the PAC keys can be exchanged, so if you're using ISE 3.1 you need to go and enable TLS 1.0 manually because it's disabled by default. Alternatively, you can switch to HTTPS with REST API which uses TLS 1.1, but that requires a few configurations steps before it can work correctly. Also, did you configure the TrustSec settings on the switch in network devices in ISE?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:47:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076193#M1111542</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T12:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076274#M1111543</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;Yes.TLS1.0 and 1.1 both are enabled on ISE. And for the network device have configured the advanced trustsec configs - Device authentication settings &amp;amp; COA &amp;amp; credentials for config deployment.&lt;/P&gt;&lt;P&gt;Same device Id and password is configured in switch as cts credentials and password is configured as PAC key under radius&amp;nbsp; server and dynamic auth server.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076274#M1111543</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-23T13:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076329#M1111546</link>
      <description>&lt;P&gt;Thanks for confirming that. Could you please try to verify the cts credentials on the switch with the command "show cts credentials" to ensure they are correct? also, could you please try to issue the command "cts refresh envi" and see if that fixes the issue? if not, could you please enable the following debug commands and share the output for review?&lt;/P&gt;
&lt;P&gt;deb cts provision events&lt;BR /&gt;deb cts provision packet&lt;BR /&gt;deb cts environment-data all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076329#M1111546</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076716#M1111557</link>
      <description>&lt;P&gt;PFB the below output for credentials&lt;/P&gt;&lt;P&gt;#show cts credentials&lt;BR /&gt;CTS password is defined in keystore, device-id = DOT1XTEST-SW01&lt;/P&gt;&lt;P&gt;Tried the environment refresh as well..Still no luck.&lt;/P&gt;&lt;P&gt;PFB debug output:&lt;/P&gt;&lt;P&gt;HK-DOT1XTEST-SW01#&lt;BR /&gt;*Apr 24 04:36:38.942: CTS env-data: Force environment-data refresh bitmask 0x2&lt;BR /&gt;*Apr 24 04:36:38.942: CTS env-data: download transport-type = CTS_TRANSPORT_IP_UDP&lt;BR /&gt;*Apr 24 04:36:38.942: cts_env_data WAITING_RESPONSE: during state env_data_waiting_rsp, got event 0(env_data_request)&lt;BR /&gt;*Apr 24 04:36:38.942: @@@ cts_env_data WAITING_RESPONSE: env_data_waiting_rsp -&amp;gt; env_data_waiting_rsp&lt;BR /&gt;*Apr 24 04:36:38.942: CTS-provisioning: PAC not found in keystore : aidlen = 0, rc = 6&lt;BR /&gt;*Apr 24 04:36:38.942: PAC not found on the device, triggering PAC provisioning for configured servers. Env-data download wiil be retried after 60 seconds&lt;/P&gt;&lt;P&gt;Above debug logs get repeated in 60 secs&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 04:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5076716#M1111557</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-24T04:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5077038#M1111564</link>
      <description>&lt;P&gt;What logs do you see in ISE RADIUS Live Logs coming from the switch?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 10:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5077038#M1111564</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-24T10:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5077926#M1111592</link>
      <description>&lt;P&gt;I am not seeing any logs from the switch&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 04:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5077926#M1111592</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-25T04:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5078167#M1111598</link>
      <description>&lt;P&gt;Please share the entire configs of the switch and ISE TrustSec configs for review.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 08:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5078167#M1111598</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-25T08:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5081691#M1111791</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debug CTS:&lt;/P&gt;&lt;P&gt;*Apr 29 07:23:06.111: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: commsuk] [Source: 10.200.127.44] [localport: 22] at 07:23:06 UTC Mon Apr 29 2024&lt;BR /&gt;*Apr 29 07:24:35.649: %AAAA-4-CLI_DEPRECATED: WARNING: Command has been added to the configuration using a type 7 password. However, recommended to migrate to strong type-6 encryption&lt;BR /&gt;*Apr 29 07:24:39.027: CTS-provisioning: PAC not found in keystore : aidlen = 0, rc = 6&lt;BR /&gt;*Apr 29 07:25:12.220: Request for pac provisioning is already in progress.Calling pac provisioning stop&lt;BR /&gt;*Apr 29 07:25:12.220: Request successfully sent to PAC Provisioning driver.&lt;BR /&gt;*Apr 29 07:25:39.028: CTS-provisioning: PAC not found in keystore : aidlen = 0, rc = 6&lt;BR /&gt;*Apr 29 07:26:17.609: %SYS-5-CONFIG_I: Configured from console by commsuk on vty0 (10.200.127.44)&lt;BR /&gt;*Apr 29 07:26:39.028: CTS-provisioning: PAC not found in keystore : aidlen = 0, rc = 6&lt;BR /&gt;*Apr 29 07:26:51.284: %SYS-5-CONFIG_I: Configured from console by commsuk on vty0 (10.200.127.44)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config in switch&lt;/P&gt;&lt;P&gt;aaa group server radius ISE-GROUP-RADIUS&lt;BR /&gt;server name ISE_US01&lt;BR /&gt;server name ISE_US02&lt;BR /&gt;server name ISE_UK01&lt;BR /&gt;server name ISE_UK02&lt;BR /&gt;ip radius source-interface Vlan900&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;BR /&gt;aaa authentication login vty local&lt;BR /&gt;aaa authentication dot1x default group ISE-GROUP-RADIUS&lt;BR /&gt;aaa authorization network default group ISE-GROUP-RADIUS&lt;BR /&gt;aaa authorization network TRUSTSEC group ISE-GROUP-RADIUS&lt;BR /&gt;aaa accounting update newinfo periodic 2880&lt;BR /&gt;aaa accounting identity default start-stop group ISE-GROUP-RADIUS&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;client 10.100.1.163 server-key&lt;/P&gt;&lt;P&gt;client 10.100.1.164 server-key&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cts authorization list TRUSTSEC&lt;/P&gt;&lt;P&gt;cts credentials id HK-DOT1XTEST-SW01 password&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol block&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan900&lt;/P&gt;&lt;P&gt;radius server ISE_US01&lt;BR /&gt;address ipv4 10.100.1.163 auth-port 1812 acct-port 1813&lt;BR /&gt;timeout 2&lt;BR /&gt;retransmit 3&lt;BR /&gt;pac key&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;radius server ISE_US02&lt;BR /&gt;address ipv4 10.100.1.164 auth-port 1812 acct-port 1813&lt;BR /&gt;key&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;radius server ISE_UK01&lt;BR /&gt;address ipv4 10.1.80.164 auth-port 1812 acct-port 1813&lt;BR /&gt;key&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 07:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5081691#M1111791</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-29T07:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Network Authorization not Working</title>
      <link>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5081959#M1111813</link>
      <description>&lt;P&gt;There was Mismatch with the device ID which was fixed now.I am able to download the pac..&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 11:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trustsec-network-authorization-not-working/m-p/5081959#M1111813</guid>
      <dc:creator>titusroz03</dc:creator>
      <dc:date>2024-04-29T11:08:59Z</dc:date>
    </item>
  </channel>
</rss>

