cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
947
Views
0
Helpful
2
Replies

Cisco ISE 2.2 Tacacs+ authen works and authoriz not work with WLC 2504

sampansampan
Level 1
Level 1

Hi

 

I have a problem between ISE and WLC use taccas authentication.

 

- ISE Version 2.2

- WLC 2504 software Version 8.3.141

 

- i have wlc 3 locations (A,B,C)

- ISE Install at site A, 

- WLC (A) can authentication and authorization with ISE,

- WLC (B,C) can authentication but can't authorization with ISE,

- ISE shown error message below.

"TACACS: Invalid TACACS+ request packet - possibly mismatched Shared Secrets"

- shared secrets are configure correct.

- i try to create authorization policy permit any but still not work.

 

 

*** Tacacs work fine because all switch can use tacacs+


Anyone can help?

 

Thank you.

 

 

 

 

2 Replies 2

Are you doing NAT for the other two sites?

How are the sites connected? If it is through a DMVPN or some tunnels that add overhead, do you have ip tcp adjust-mss 1360 on one of the interfaces to prevent fragmentation?

If you can share a snippet of the AuthZ result removing any sensitive information would be good.
** Please rate helpful posts **

CCIE #58023

Thank you for your reply

 

Site works

ISE use MSS = 1460
WLC use  MSS = 1394

 

Site not work

ISE use MSS = 1460
WLC use  MSS = 1380

 

how can i fix its?