05-13-2023 11:32 PM
Hi everyone, I have a question about cisco ISE 3, how can i find cisco switch error-disabled port reason on cisco ISE?
Solved! Go to Solution.
05-14-2023 01:22 PM
Hi @Raminkn20
ISE won't tell you why an interface has been put in err-disabled state. You can get that reason from the switch logs (show logging).
It's usually because a condition has been violated - e.g. in the context of ISE and NAC, it's usually because you have exceeded the number of MAC addresses allowed (e.g. >1 MAC address in DATA domain in multi-domain mode causes err-disable)
Back in the early days of ISE the recommendation was to send SYSLOGS to the ISE MNTs (on UDP/20514) - but nobody does that anymore - and I doubt that ISE would even process them.
05-14-2023 01:22 PM
Hi @Raminkn20
ISE won't tell you why an interface has been put in err-disabled state. You can get that reason from the switch logs (show logging).
It's usually because a condition has been violated - e.g. in the context of ISE and NAC, it's usually because you have exceeded the number of MAC addresses allowed (e.g. >1 MAC address in DATA domain in multi-domain mode causes err-disable)
Back in the early days of ISE the recommendation was to send SYSLOGS to the ISE MNTs (on UDP/20514) - but nobody does that anymore - and I doubt that ISE would even process them.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide