cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
513
Views
1
Helpful
1
Replies

cisco switch error-disabled port reason on cisco ISE

Raminkn20
Level 1
Level 1

Hi everyone, I have a question about cisco ISE 3, how can i find cisco switch error-disabled port reason on cisco ISE?

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

Hi @Raminkn20 

ISE won't tell you why an interface has been put in err-disabled state. You can get that reason from the switch logs (show logging).

It's usually because a condition has been violated - e.g. in the context of ISE and NAC, it's usually because you have exceeded the number of MAC addresses allowed (e.g. >1 MAC address in DATA domain in multi-domain mode causes err-disable)

Back in the early days of ISE the recommendation was to send SYSLOGS to the ISE MNTs (on UDP/20514) - but nobody does that anymore - and I doubt that ISE would even process them.

View solution in original post

1 Reply 1

Arne Bier
VIP
VIP

Hi @Raminkn20 

ISE won't tell you why an interface has been put in err-disabled state. You can get that reason from the switch logs (show logging).

It's usually because a condition has been violated - e.g. in the context of ISE and NAC, it's usually because you have exceeded the number of MAC addresses allowed (e.g. >1 MAC address in DATA domain in multi-domain mode causes err-disable)

Back in the early days of ISE the recommendation was to send SYSLOGS to the ISE MNTs (on UDP/20514) - but nobody does that anymore - and I doubt that ISE would even process them.