cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9436
Views
10
Helpful
4
Replies

11213 No response received from Network Access Device after sending a Dynamic Authorization request

Hi there,

 

I see this error a lot in my ISE dashboard

11213 No response received from Network Access Device after sending a Dynamic Authorization request

At the same time I see the Posture Status as "Compliant"

What could be causing this? Have anyone encountered this before

 

Thanks,

Hari

 

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

It seems the CoA response packet from the NAD to ISE PSN lost or something like that, but the NAD went ahead and performed a re-auth to put the endpoint in compliant state.

I would suggest you to monitor the connectivity between ISE PSN and the NADs.

View solution in original post

4 Replies 4

hslai
Cisco Employee
Cisco Employee

It seems the CoA response packet from the NAD to ISE PSN lost or something like that, but the NAD went ahead and performed a re-auth to put the endpoint in compliant state.

I would suggest you to monitor the connectivity between ISE PSN and the NADs.

hnouel
Level 1
Level 1

I was having this problem and it turns out that the Shared Secret in the device configuration, Radius section, did not match the switch -  aaa server radius dynamic-author - client x.x.x.x server-key. Once I made them the same, the endpoints started to authenticate.

Are you using DTLS? If so was the server-key just "radius/dtls" I am experiencing similar issues.

i.e.

radius server THE_IMPERFECT_SERVER
address ipv4 1.1.1.1

key radius/dtls

dtls ip vrf forwarding JUST_A_VRf

dtls ip radius source-interface vlan 4010

dtls trustpoint client SUB_CA (who issues cert manual enrollment)

dtls trustpoitn server SUB_CA (who issues cert manual enrollment)

 

aaa server dynamic-author

client 1.1.1.1 vrf JUST_A_VRf dtls client-tp SUB-CA server-tp SUB-CA

auth-type any

dtls ip radius source-interface VLAN 4010

 

 

ruhulamin210
Level 1
Level 1

enable coa from ISE as per the screenshot