06-09-2020 01:59 PM
Hi All,
Recently noticed a strange issue with a few switches in our network.
Using SGT/CTS with ISE 2.4.
Switches are 9200 series, working ok until several switches started to show an error with CTS server info list I.E. marking the ISE servers as down?
2 switch outputs below (sw1 not working, sw2 working). The switches have the same config and in the same location, able to refresh env data and also PAC files on both switches without error.
The only difference I can see is info output for TAG 0:Unknown
The working switch shows "status alive" with auto-test=false?
The none working switch shows "status dead" with auto-test=true?
Can anyone explain this auto-test feature please.
Output for sw1 (error switch):
Output for sw2 (working switch):
06-09-2020 02:06 PM
Quick update: After a reboot on sw1# (No config change at all) the switch is now making the ISE servers as "alive" when I do sw1#show cts env data?
What is causing the switch to previously report the severs as "dead"?
Reboot and the issue disappears but for how long is the question.
Could this be an auth time type loop issue?
If anyone has a working CTS config and willing to post that would be great.
Thanks,
06-12-2020 03:49 PM
Sounds like a switch bug since a reboot fixed it.
06-14-2020 04:13 PM
See this duplicate post:
https://community.cisco.com/t5/network-access-control/cisco-ise-cts-switch-issues/m-p/4101462
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide