cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1103
Views
5
Helpful
2
Replies

Cisco ISE as Tacacs only server - alarm: ISE Authentication Inactivity

ivan.mastrenko
Level 1
Level 1

Hello!

I have ISE 2.3, Patch 5 deployment, for Device Admin (Tacacs+) purposes only.

And I have an alarm that raising every 15 minuts:

Alarms: ISE Authentication Inactivity
Description: The ISE Policy Service nodes are not receiving Authentication requests from the Network Devices
Suggested Actions: Check the ISE/NAD configuration, check the network connectivity of the ISE/NAD infrastructure.

But I have an authentication actions on devices at periods when alarm is triggering, I see it at TACACS live logs, and reports.

 

Does this alarm consider TACACS authentication on devices?

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni
This alarm is for RADIUS authentications only. If you have a dedicated TACACS deployment that sees very seldom radius packets or none at all then this is expected.

Currently your only option is to live with the alarm or disable it from the alarm settings page. I suggest disabling it, hopefully in the future this alarm will be split in to radius/tacacs.

View solution in original post

2 Replies 2

I think you are hitting the following bug.

CSCuz52877

Damien Miller
VIP Alumni
VIP Alumni
This alarm is for RADIUS authentications only. If you have a dedicated TACACS deployment that sees very seldom radius packets or none at all then this is expected.

Currently your only option is to live with the alarm or disable it from the alarm settings page. I suggest disabling it, hopefully in the future this alarm will be split in to radius/tacacs.