cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1630
Views
0
Helpful
2
Replies

Cisco ISE 1.3 failed to authenticate wireless endpoint

terrychow123
Level 1
Level 1

Dear all,

 

I recently have a big problem of my ISE after upgraded from version 1.2 to 1.3, the original plan is follow for wireless laptop authenticate to our network.

 

There are 2 SSID, REG and INT, when the user and laptop first time use the WIFI, they need to request a user certificate from CA, and they need to login to the REG SSID with AD username and password. The Wireless controller 2504 will pass the packet to ISE, the use will use 802.1x authen method with PEAP to request for cert. if the authentication successful, the user need to open a web browser and the NSP page of ISE will shown up for user to register, and the CA will generate the user cert to user. Then the SSID will switch to INT and using EAP/TLS to authenticate the user cert with the CA.

That was fine when working in ISE 1.2. However, after upgrade to 1.3 because of the proxy setting in 1.3 allow to input username and password which our proxy server required and cannot be changed. Under 1.3 the authentication failed even in the first step of authentication policy of ISE, the policy will check if the laptop using 802.1x and login by AD account, then it will pass to authorization policy. But when I check the log, there is always have the error message 5411 Supplicant stopped responding to ISE , 12930 Supplicant stopped responding to ISE after sending it the first PEAP message , 5440 Endpoint abandoned EAP session and started new

I have search long time in the Internet but without any help, appreciate if any expert can help me. I have also upload the debug message from our ISE for reference.

 

Thank you

 

Best Regards,

 

Terry Chow

2 Replies 2

terrychow123
Level 1
Level 1

Hi

 

Can anyone please help?

 

Thank you

johncaston_2
Level 1
Level 1

Hi Terry,

 

Just wondering if you got an answer to your problem?

I am deploying a new solution with ISE 1.3 and I was having a similar problem with my wireless users when I tried to enable it last night

Cheers,

John