cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2321
Views
10
Helpful
3
Replies

Security Group Tag, and SGFW

jiyoung Kim
Level 1
Level 1

Hi, I'm trying to configure SGFW with ASA 5585-20,

I registered in ISE, and imported pac, matched all shared secret, password. peering with WLC via SXP.

so I got the USER IP and TAG, However, ASA cannot download the environment-data from ISE.

When I enable debug cts all in asa, it says error recieved from ISE.

and on live Authentications on ISE,

Overview

Event5405 RADIUS Request dropped
Username
Endpoint Id
Endpoint Profile
Authorization Profile

Authentication Details

Source Timestamp2013-08-08 10:24:06.691
Received Timestamp2013-08-08 10:24:06.691
Policy Serverise
Event5405 RADIUS Request dropped
Failure Reason11303 Could not parse the cts-pac-opaque attribute
ResolutionRefer to the documentation for the client's supplicant to perform a new PAC-provisioning operation.
Root causeThe cts-pac-opaque cisco-av-pair attribute contained in the Secure RADIUS request did not parse.
Username
User Type
Endpoint Id
Endpoint Profile
IP Address
Identity Store
Identity Group
Audit Session Id
Authentication Method
Authentication Protocol
Service Type
Network DeviceASA5585X
Device TypeFirewall#ASA5585X
LocationDJ
NAS IP Address172.30.0.1
NAS Port Id
NAS Port TypeVirtual
Authorization Profile
Posture Status
Security Group
Response Time

and, also 5420 SGA Data Download Failed.

does anyone know how to solve this problem ?

I'm usning ASA 9.1, ISE 1.2 official release.

3 Replies 3

ThibaultMean
Level 1
Level 1

I wouldn't expect too much help from cisco on this.

Poorly documented...

Try patching ise with this : ise-patchbundle-1.2.0.899-2-85601.x86_64.tar.gz

comand: patch install ise-patchbundle-1.2.0.899-2-85601.x86_64.tar.gz

It fixed my issue.

This fix my issue too... Tks ThibaultMean

Review Cisco Networking products for a $25 gift card