08-03-2021 07:20 AM - edited 08-03-2021 07:21 AM
Hi,
I have a problem with the configuration of our Cisco ISE.
In the Radius logs we receive the messages the I attach.
But the Cisco ISE still manages to authenticate clients and authorize them with the correct policy...
Anyone that have any idea?
Thanks
08-03-2021 08:37 AM
For the community to better assist please provide additional info such as:
-AAA config
-ISE version
-ISE deployment type (ex: 2 PANs, 2 PSNs, etc.)
-NAD Platform/IOS version
Does this happen for all NADs? Usually this is an issue with a shared secret mismatch. However, if clients are onboarding successfully then the issue is something else. Note that it could be bug related depending on versions.
08-04-2021 06:27 AM
08-04-2021 07:32 AM
Have you tried re-entering the shared secret on the WLC side under the AAA server accounting configuration yet? Not familiar with 3500 series, but I know with the 5500 series for the AAA server config there are two different sections where you have to enable/configure AAA servers for both authentication & accounting. My thinking is that maybe there is a typo, if clients are successfully onboarding then that means the AAA authentication server shared secret is accurate. Maybe the AAA accounting server shared secret is off.
08-04-2021 11:32 AM
I agree with Mike - verify you RADIUS Shared Secret on the device and in ISE for that device.
The original error was telling you the solution:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide