<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble adding ISE server in Network Settings in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5356532#M4247</link>
    <description>&lt;P&gt;key point there is "ISE or AAA". looking at your move "&lt;SPAN&gt;to add a AAA server" i guess you missteered somewhere.&lt;BR /&gt;bc with 1st stages of integration u made DNAC must be communicated by PAN with configured policy servers u must choose as such. I didnt touch SDA for about year so i have to look in live deployment to steer u in proper direction. w/o promises to be asap&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 16:51:19 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2025-12-19T16:51:19Z</dc:date>
    <item>
      <title>Trouble adding ISE server in Network Settings</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5356529#M4246</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I'm doing the CCIE Practice Labs so I can get practice with SDA. One of the first things I'm doing in SDA is the integration of DNAC with ISE (in the lab, the DNAC is version &lt;STRONG&gt;2.3.5&lt;/STRONG&gt;). The integration works fine, and during the integration I use the&amp;nbsp;&lt;STRONG&gt;Advanced Settings&lt;/STRONG&gt; to check both the&amp;nbsp;&lt;STRONG&gt;Radius&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;TACACS&lt;/STRONG&gt; checkboxes, since I want this ISE server to be used for both endpoint authentication and switch authentication.&lt;/P&gt;&lt;P&gt;After the DNAC/ISE integration I do the Policy migration, which also works great.&lt;/P&gt;&lt;P&gt;So at this point, in &lt;STRONG&gt;System &amp;gt; Settings &amp;gt; External Services &amp;gt; Authentication and Policy Servers&lt;/STRONG&gt;, I have an ISE server defined there, with an IP address and Protocol =&amp;nbsp;&lt;STRONG&gt;RADIUS_TACACS&lt;/STRONG&gt; and Type =&amp;nbsp;&lt;STRONG&gt;ISE&lt;/STRONG&gt; and Status =&amp;nbsp;&lt;STRONG&gt;ACTIVE&lt;/STRONG&gt;. So all seems well.&lt;/P&gt;&lt;P&gt;I then go to &lt;STRONG&gt;Design &amp;gt; Network Settings&lt;/STRONG&gt;&amp;nbsp;to add a AAA server (i.e.&amp;nbsp;&lt;STRONG&gt;Add Servers &amp;gt; AAA&lt;/STRONG&gt;) to the &lt;STRONG&gt;Global&lt;/STRONG&gt; area. I check both the&amp;nbsp;&lt;STRONG&gt;Network&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;Client/Endpoint&lt;/STRONG&gt; checkboxes, and then I start configuring the &lt;STRONG&gt;Network&amp;nbsp;&lt;/STRONG&gt;section first.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Under the &lt;STRONG&gt;Network &amp;gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Servers&lt;/STRONG&gt;&amp;nbsp;heading, I click the&amp;nbsp;&lt;STRONG&gt;ISE&lt;/STRONG&gt; radio button since the server I added above is of Type = ISE, and I select my ISE IP address from the drop-down menu.&lt;/LI&gt;&lt;LI&gt;Under the&amp;nbsp;&lt;STRONG&gt;Network &amp;gt;&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Protocol&lt;/STRONG&gt; heading, I click the&amp;nbsp;&lt;STRONG&gt;TACACS&lt;/STRONG&gt; radio button since I want my network authentication to use TACACS. HOWEVER, when I click the&amp;nbsp;&lt;STRONG&gt;IP Address (Primary)&lt;/STRONG&gt; drop-down menu to select my ISE IP address, there are no IP addresses available to select. If I change the protocol to&amp;nbsp;&lt;STRONG&gt;RADIUS&lt;/STRONG&gt; instead, I do get an IP address available in the drop-down, but I don't want to use RADIUS, I want to use TACACS for this &lt;STRONG&gt;Network&lt;/STRONG&gt; part. (Additional info - underneath the &lt;STRONG&gt;IP address (Primary)&lt;/STRONG&gt; drop-down box, it does have text that says&amp;nbsp;&lt;STRONG&gt;(Only device administration nodes)&lt;/STRONG&gt; ).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'm confused by the end of Step 2 above, where there are no IP addresses available in the&amp;nbsp;&lt;STRONG&gt;IP Address (Primary)&lt;/STRONG&gt; drop-down menu when I try to add a AAA server and use TACACS for the Network section. What do I need to do to get an IP address listed in this drop-down for selection?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Looking at the &lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-5/user_guide/b_cisco_dna_center_ug_2_3_5/m_configure-network-settings.html#add_ise_or_other_aaa_servers" target="_self"&gt;DNAC 2.3.5 guide&lt;/A&gt;, it says:&lt;UL&gt;&lt;LI&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Step&amp;nbsp;6&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class=""&gt;Choose the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Servers&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for authentication and authorization:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ISE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;AAA&lt;/SPAN&gt;.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;If you choose&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ISE&lt;/SPAN&gt;, configure the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;From the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Network&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drop-down list, choose the IP address of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;server. The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Network&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drop-down list contains all the IP addresses of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;servers that are registered in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;System Settings&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco DNA Center&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;home page. &lt;STRONG&gt;Selecting a&amp;nbsp;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;&amp;nbsp;IP populates the primary and additional IP address drop-down lists with Policy Service Node (PSN) IP addresses for the selected&amp;nbsp;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;.&lt;/STRONG&gt; You can either enter an IP address for the AAA server or choose the PSN IP address from the&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;IP Address (Primary)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;IP Address (Additional)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;drop-down lists.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;However, in my case, Selecting the Cisco ISE IP in the&amp;nbsp;&lt;STRONG&gt;Network&lt;/STRONG&gt; drop-down menu does not populate anything in the &lt;STRONG&gt;IP Address (Primary)&lt;/STRONG&gt; drop-down menu.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 19 Dec 2025 16:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5356529#M4246</guid>
      <dc:creator>vv0bbLeS</dc:creator>
      <dc:date>2025-12-19T16:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble adding ISE server in Network Settings</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5356532#M4247</link>
      <description>&lt;P&gt;key point there is "ISE or AAA". looking at your move "&lt;SPAN&gt;to add a AAA server" i guess you missteered somewhere.&lt;BR /&gt;bc with 1st stages of integration u made DNAC must be communicated by PAN with configured policy servers u must choose as such. I didnt touch SDA for about year so i have to look in live deployment to steer u in proper direction. w/o promises to be asap&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 16:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5356532#M4247</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-12-19T16:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble adding ISE server in Network Settings</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5362106#M4289</link>
      <description>&lt;P&gt;When you are adding an ISE node to use for TACACS in DNAC, in ISE you need the "Enable Device Admin Service" checkbox marked under where you enable the Policy Service on the ISE node. At my current organization we have a multi node ISE deployment and in DNAC you can only choose the IP addresses of only the nodes with that service enabled for TACACS. It's also good to note that in order to enable that service on the ISE node, you also need the TACACS license for that node. Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 12:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/trouble-adding-ise-server-in-network-settings/m-p/5362106#M4289</guid>
      <dc:creator>barryjm</dc:creator>
      <dc:date>2026-01-16T12:10:11Z</dc:date>
    </item>
  </channel>
</rss>

