cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1463
Views
0
Helpful
3
Replies

About the output contents of LiveLog

Keisuke.I
Level 1
Level 1

The following alert is output to Misconfigured NAS.

-------

The Message-Authenticator RADIUS attribute is invalid. This maybe because of mismatched Shared Secrets.
Check whether the Shared Secrets on the AAA Client and ISE Server, match. Ensure that the AAA Client and the network device, have no hardware problems or problems with RADIUS compatibility. Also ensure that the network that connects the device to the ISE, has no hardware problems.

-------

 I do not know where I set SharedSecret.
Please tell me what items can be set on the GUI.

1 Accepted Solution

Accepted Solutions

It was the Radius log that was output because the information from the previous provisioning remained.

 

By deleting the old pac file or restarting the device, the alert no longer occurs.

View solution in original post

3 Replies 3

anshsinh
Cisco Employee
Cisco Employee

You can navigate to ISE->Administration->Network Resources->network Devices . Select the network device ( if not already added , add a new device ) -> Now we need to enter the ip address of the switch ( NAS IP address ) . If you scroll down , you will see the Radius check box . Check that box and expand and you will see option to enter the secret . Here we need to make sure that the secret matches that you have given in the switch .

In my environment, I use DNACenter.

Since we provisioned using DNACenter linked with ISE, Shared Secret is already set.

 

Where is the value of Shared Secret performed on ISE defined in DNACenter?

Should I specify the value on ISE using DNACenter > Settings > Authentication and Policy Server > Add AAA / ISE Server > Shared Secret?

It was the Radius log that was output because the information from the previous provisioning remained.

 

By deleting the old pac file or restarting the device, the alert no longer occurs.