06-17-2019 01:15 AM
Hi there,
I see this error a lot in my ISE dashboard
11213 No response received from Network Access Device after sending a Dynamic Authorization request
At the same time I see the Posture Status as "Compliant"
What could be causing this? Have anyone encountered this before
Thanks,
Hari
Solved! Go to Solution.
06-29-2019 02:27 PM
It seems the CoA response packet from the NAD to ISE PSN lost or something like that, but the NAD went ahead and performed a re-auth to put the endpoint in compliant state.
I would suggest you to monitor the connectivity between ISE PSN and the NADs.
06-29-2019 02:27 PM
It seems the CoA response packet from the NAD to ISE PSN lost or something like that, but the NAD went ahead and performed a re-auth to put the endpoint in compliant state.
I would suggest you to monitor the connectivity between ISE PSN and the NADs.
10-15-2021 01:17 PM
I was having this problem and it turns out that the Shared Secret in the device configuration, Radius section, did not match the switch - aaa server radius dynamic-author - client x.x.x.x server-key. Once I made them the same, the endpoints started to authenticate.
12-29-2022 02:06 PM
Are you using DTLS? If so was the server-key just "radius/dtls" I am experiencing similar issues.
i.e.
radius server THE_IMPERFECT_SERVER
address ipv4 1.1.1.1
key radius/dtls
dtls ip vrf forwarding JUST_A_VRf
dtls ip radius source-interface vlan 4010
dtls trustpoint client SUB_CA (who issues cert manual enrollment)
dtls trustpoitn server SUB_CA (who issues cert manual enrollment)
aaa server dynamic-author
client 1.1.1.1 vrf JUST_A_VRf dtls client-tp SUB-CA server-tp SUB-CA
auth-type any
dtls ip radius source-interface VLAN 4010
12-12-2023 01:32 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide