<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Testing - Cisco ISE -  not all passing in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528812#M311197</link>
    <description>We came across the same issue and found bug &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq00652/?rfs=iqvred" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq00652/?rfs=iqvred&lt;/A&gt; which was affecting our test results.</description>
    <pubDate>Fri, 11 Oct 2019 17:16:55 GMT</pubDate>
    <dc:creator>Eric101</dc:creator>
    <dc:date>2019-10-11T17:16:55Z</dc:date>
    <item>
      <title>Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528805#M311190</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Firmware: 25.13&lt;/P&gt;&lt;P&gt;Cisco ISE: &lt;SPAN&gt;2.3.0.298&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;just testing the radius authentication from the dashboard to our Cisco ISE radius&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Total APs: &lt;/TD&gt;&lt;TD&gt;9&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;APs passed: &lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;APs failed: &lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;APs unreachable: &lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;these are same subnet, same site, same everything&lt;/P&gt;&lt;P&gt;each time I test I receive different results and sometime I receive an error&lt;/P&gt;&lt;DIV&gt;&lt;STRONG&gt;RADIUS attributes used:&lt;/STRONG&gt;&lt;BR /&gt;Airespace-ACL-Name:HS-Laptop&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;RADIUS attributes unused:&lt;/STRONG&gt;&lt;BR /&gt;User-Name: *domain\user*&lt;BR /&gt;State:ReauthSession:0a2d000fKS4uutHjQp5FArmB2ZstcLZ63zRmIXdtubIA7tDgTB4&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I managed to find a good site explaining this a long time ago but I am unable to find it now so looking for help with a solution of explanation&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;our old Cisco ISE box (decommissioned) used to always be 100% but as I am not a Cisco ISE person I unable to to even work out the difference&lt;/DIV&gt;&lt;DIV&gt;and cisco forums are a mess so hoping here someone can point me in the correct direction&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Working AP ISE output:&lt;/DIV&gt;&lt;DIV&gt;&lt;H3&gt;Authentication Details&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Source Timestamp&lt;/TD&gt;&lt;TD&gt;2019-09-05 09:42:20.332&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Received Timestamp&lt;/TD&gt;&lt;TD&gt;2019-09-05 09:42:20.333&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Policy Server&lt;/TD&gt;&lt;TD&gt;servername&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5200 Authentication succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;domain\user&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Id&lt;/TD&gt;&lt;TD&gt;00:00:00:00:00:02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Calling Station Id&lt;/TD&gt;&lt;TD&gt;00-00-00-00-00-02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Identity Store&lt;/TD&gt;&lt;TD&gt;HS_AD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Method&lt;/TD&gt;&lt;TD&gt;MSCHAPV2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Protocol&lt;/TD&gt;&lt;TD&gt;PEAP (EAP-MSCHAPv2)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Network Device&lt;/TD&gt;&lt;TD&gt;Meraki_AP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;All Device Types#Meraki_AP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS IPv4 Address&lt;/TD&gt;&lt;TD&gt;10.45.99.12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS Port Type&lt;/TD&gt;&lt;TD&gt;Wireless - IEEE 802.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authorization Profile&lt;/TD&gt;&lt;TD&gt;HS_Laptop_Permit_All&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Response Time&lt;/TD&gt;&lt;TD&gt;19 milliseconds&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;failing AP ISE output&lt;/P&gt;&lt;H3&gt;Authentication Details&lt;/H3&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Source Timestamp&lt;/TD&gt;&lt;TD&gt;2019-09-05 09:42:21.899&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Received Timestamp&lt;/TD&gt;&lt;TD&gt;2019-09-05 09:42:21.9&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Policy Server&lt;/TD&gt;&lt;TD&gt;servername&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5400 Authentication failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Resolution&lt;/TD&gt;&lt;TD&gt;Verify known NAD issues and published bugs. Verify NAD configuration. Turn debug log on DEBUG level to troubleshoot the problem.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Root cause&lt;/TD&gt;&lt;TD&gt;Session was not found on this PSN. Possible unexpected NAD behavior. Session belongs to this PSN according to hostname but may has already been reaped by timeout. This packet arrived too late.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;domain\user&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Id&lt;/TD&gt;&lt;TD&gt;00:00:00:00:00:02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Calling Station Id&lt;/TD&gt;&lt;TD&gt;00-00-00-00-00-02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Network Device&lt;/TD&gt;&lt;TD&gt;Meraki_AP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;All Device Types#Meraki_AP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS IPv4 Address&lt;/TD&gt;&lt;TD&gt;10.45.99.13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;NAS Port Type&lt;/TD&gt;&lt;TD&gt;Wireless - IEEE 802.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Response Time&lt;/TD&gt;&lt;TD&gt;4 milliseconds&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;any help on this is greatly appreciated&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 05 Sep 2019 10:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528805#M311190</guid>
      <dc:creator>jake.ryan1</dc:creator>
      <dc:date>2019-09-05T10:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528806#M311191</link>
      <description>&lt;P&gt;I can't help here as I don't mess with ISE, but found the following links that might be of assistance (unless you've already read them then never mind lol).&lt;/P&gt;&lt;P&gt;You'll want to make sure your ISE is updated/patched etc.&lt;/P&gt;&lt;P&gt;Are you able to open up a TAC case for your issue?&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-2-4-and-error-12953/td-p/3828922" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-2-4-and-error-12953/td-p/3828922&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/wireless-security-and-network/ise-ad-802-1x-authentication-failure-all-of-the-sudden/td-p/2502236" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.cisco.com/t5/wireless-security-and-network/ise-ad-802-1x-authentication-failure-all-of-the-sudden/td-p/2502236&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Old, mentioning if you have load-balancer in the mix&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/ise-eap-authentication-fails/td-p/2658436" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.cisco.com/t5/policy-and-access/ise-eap-authentication-fails/td-p/2658436&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Old, but mentioning switch IOS version&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/ise-ad-authentication-stop-working-for-wireless/td-p/2363848" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.cisco.com/t5/policy-and-access/ise-ad-authentication-stop-working-for-wireless/td-p/2363848&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;Old, but might help?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 05 Sep 2019 14:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528806#M311191</guid>
      <dc:creator>Nolan H.</dc:creator>
      <dc:date>2019-09-05T14:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528807#M311192</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/8886"&gt;@jake.ryan1&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Do you have radius accounting enabled? If so you might be running into an ISE bug. &lt;/P&gt;&lt;P&gt;Can you try disabling accounting and see if you still see the same issue?&lt;/P&gt;&lt;P&gt;P.S: For security reasons, it will be a good idea to mask out sensitive information like Re-auth session IDs and all &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Raj &lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 17:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528807#M311192</guid>
      <dc:creator>raj.yarlagadda@meraki.com</dc:creator>
      <dc:date>2019-09-05T17:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528808#M311193</link>
      <description>&lt;P&gt;Are all the APs listed as clients in ISE?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 20:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528808#M311193</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2019-09-05T20:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528809#M311194</link>
      <description>&lt;P&gt;Hi Raj&lt;/P&gt;&lt;P&gt;sorry I was not sure what is passed in all these things&lt;/P&gt;&lt;P&gt;do you have any description of what the ISE bug could be as I am sure we are running accounting&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 22:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528809#M311194</guid>
      <dc:creator>jake.ryan1</dc:creator>
      <dc:date>2019-09-05T22:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528810#M311195</link>
      <description>&lt;P&gt;Hi Philip&lt;/P&gt;&lt;P&gt;i am covering our entire network subbnet with meraki so authentication is covered at this point as you can see the Same subnet is taking authentication the same as the AP which is not &lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2019 23:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528810#M311195</guid>
      <dc:creator>jake.ryan1</dc:creator>
      <dc:date>2019-09-05T23:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528811#M311196</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/8886"&gt;@jake.ryan1&lt;/A&gt; I was looking into the Auth error details and found this article in Cisco forums which is related to the auth error you are seeing. You can see the bug id in there.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/ise-ad-authentication-stop-working-for-wireless/td-p/2363848" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.cisco.com/t5/policy-and-access/ise-ad-authentication-stop-working-for-wireless/td-p/2363848&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 16:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528811#M311196</guid>
      <dc:creator>raj.yarlagadda@meraki.com</dc:creator>
      <dc:date>2019-09-06T16:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Testing - Cisco ISE -  not all passing</title>
      <link>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528812#M311197</link>
      <description>We came across the same issue and found bug &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq00652/?rfs=iqvred" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq00652/?rfs=iqvred&lt;/A&gt; which was affecting our test results.</description>
      <pubDate>Fri, 11 Oct 2019 17:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-testing-cisco-ise-not-all-passing/m-p/5528812#M311197</guid>
      <dc:creator>Eric101</dc:creator>
      <dc:date>2019-10-11T17:16:55Z</dc:date>
    </item>
  </channel>
</rss>

