11-26-2018 07:20 AM
Hi everybody. Right now I'm having an issue when connecting an endpoint. This endpoint can't have a successful authorization access because it generates the error "15022 Could not find selected Access Service". I'm looking for the root cause of this error online, but I haven't found anything yet. I will apprecciate any help someone can give me. I attached the error generated.
Thank you in advance.
Solved! Go to Solution.
12-10-2018 08:59 AM
Hi everybody, we found the solution!
The issue was with the Active Directory sync, because the AD clock was not syc with the PSNs clocks. Thank you so much for your help.
11-26-2018 07:26 AM
You may have to check allowed protocol. Try using default allowed protocol.
11-26-2018 02:47 PM
11-26-2018 03:36 PM
Can you show the step data?
How are the clients authenticating? User/pass, cert etc?
Is it all the same devices, or just one?
11-27-2018 12:07 PM - edited 11-27-2018 12:28 PM
We have the next envirnoment: 3 PSN, 2 PAN, and 2 MnMT. We only have configured dot1x and MAB for now, and we're testing only Wired network devices. We're using EAP-TLS and PEAP with dot1X and Internal Endpoints for mab. I have attached images of all the configuratinos we have set. There are several users with the same problem, and even when every endpoint has his certificate, it failed dot1x and starts MAB, sometimes failing too.
I will apprecciate any help you guys can give me.
11-28-2018 01:21 PM
just curious what config you have on switch side.
have you follow the best cisco ISE config on switch side
11-26-2018 07:43 PM
Please use "Default network access" shown in first attachment. Also what method you are using for authentication?
11-27-2018 12:02 PM - edited 11-27-2018 12:28 PM
We have the next envirnoment: 3 PSN, 2 PAN, and 2 MnMT. We only have configured dot1x and MAB for now, and we're testing only Wired network devices. We're using EAP-TLS and PEAP with dot1X and Internal Endpoints for mab. I have attached images of all the configuratinos we have set. There are several users with the same problem, and even when every endpoint has his certificate, it failed dot1x and starts MAB, sometimes failing too.
I will apprecciate any help you guys can give me.
11-27-2018 02:35 PM
Would suggest you to check the configuration at Policy > Policy Sets > Authentication. Here check every policy set for the section "Allowed Protocols / Server Sequence". See if any policy set has an empty one. If yes, choose one and save the config.
11-28-2018 11:32 AM
@Surendra wrote:
Would suggest you to check the configuration at Policy > Policy Sets > Authentication. Here check every policy set for the section "Allowed Protocols / Server Sequence". See if any policy set has an empty one. If yes, choose one and save the config.
Hi surendra. I checked that and everything is OK with that. All policy sets have the field "Allowed Protocols / Server Sequence" with a service list.
11-26-2018 09:40 PM
Please raise a TAC case to troubleshoot this further.
11-28-2018 01:57 PM
seem to me your authorization rules are not define properly.
you need to be more specific narrow it down for exmaple if
network access-EapTunnel = Peap MSCAP than permit
12-10-2018 08:59 AM
Hi everybody, we found the solution!
The issue was with the Active Directory sync, because the AD clock was not syc with the PSNs clocks. Thank you so much for your help.
10-05-2019 01:14 PM
When upgrading from Cisco ISE v2.2 to Cisco ISE v2.4 either an oridinary upgrade or an re-image to v2.4 followed by a restore from backup, I ran into the issue that some policy sets were missing the settings for Allowed Protocols.
When re-selecting the right allowed protocol, it works again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide