cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
519
Views
2
Helpful
9
Replies

ISE Posture problem

A user connected to a Cisco 2960X switch was re-authenticated every 30 minutes. I replaced the switch with a 9200L model, and now when the user re-authenticates every 1800 seconds, the Posture process shows the error "Posture failed due to Server issue."Posture What could be the cause, and how can I fix it?
9 Replies 9

Could you please share the related configs on the 9200 switch for review including the redirect ACL please?

No ACL configured. What configurations are needed? Radius or all configurations?

If you don't have any redirect ACL created then I think you would need one. This redirect ACL would need to be called exactly with the same name as you configured it in the redirection authorization profile on ISE.

I looked at the cisco ISE logs and when that error occurs, authentication goes through but authorization does not go through and it closes the session,even went through the CoA configurations.Could it be from the firmware version?

Could you share the failure log in ISE for review please? I don't think the firmware version in itself is the issue, however, it could be that some of the commands have not been applied to the 9200 switch. Did you cross check all the commands you had on the 2960 with the ones you applied to the 9200?

11001Received RADIUS Access-Request
 11017RADIUS created a new session
 11027Detected Host Lookup UseCase (Service-Type = Call Check (10))
 15049Evaluating Policy Group
 15008Evaluating Service Selection Policy
 15048Queried PIP - DEVICE.Location
 15048Queried PIP - DEVICE.Device Type
 15041Evaluating Identity Policy
 15013Selected Identity Source - Internal Endpoints
 24209

Looking up Endpoint in Internal Endpoints IDStore - XX:XX:XX:XX:XX:XX

 24211Found Endpoint in Internal Endpoints IDStore
 22037Authentication Passed
 15036Evaluating Authorization Policy
 11055User name change detected for the session. Attributes for the session will be removed from the cache
 15048Queried PIP - DEVICE.Location
 15048Queried PIP - DEVICE.Device Type
 15048Queried PIP - Network Access.EapAuthentication (192 times)
 15048Queried PIP - Normalised Radius.RadiusFlowType
 15016Selected Authorization Profile - DenyAccess
 15039Rejected per authorization profile
 11003Returned RADIUS Access-Reject

These are the logs from ISE. I have compared the configurations of 2960X and 9200L, they are all the same. Radius has session-timeout set to 1800 seconds. After this period expires, it checks again, at which point the posture gives an error and the connection is interrupted for 15 seconds.

 

Not sure, sorry, but from the log you shared it does seem that the wrong authorization profile is being hit. I think I would need to see all your sanitized configs of this whole posture assessment flow to see if anything else come to mind that could help.

Thank you for your all help. The problem has been solved. Problem was anyconnect version

You are welcome, and thanks for sharing the root cause.