cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1234
Views
0
Helpful
3
Replies

CTS environmental-data download failed in ASA

swajalsarkar
Level 1
Level 1

Hello,

 

I am facing an issue where my ASA is not able to download the TrustSec environment-data from ISE. I have configured the device properly in ISE, generated and imported the PAC file as well.

Strange thing is when I checked ISE RADIUS logs for #CTSREQUEST# it shows environmental data downloaded, but in ASA on executing  "show cts environmental-data" command it shows last download failed.

In the ASA logs it's showing CTS Env data retrieval failed, error response from ISE.

Can anyone please help in this?

 

 

3 Replies 3

hslai
Cisco Employee
Cisco Employee

I would suggest checking the connectivity between ASA and ISE. If possible, get packet captures at both sides. ASA has "debug cts", which should give you more info. 

In the " debug cts all" it's not showing any logs.

The communication between ASA and ISE looks good as I am able to see the RADIUS request being made by the ASA during env-data refresh and being received by ISE and sending replies.

In ISE logs it's showing "Trust Sec environmental-data download succeeded"

But in ASA last download is showing as failed and every minute asa is trying to download

hslai
Cisco Employee
Cisco Employee

Please use the debug cts command on the ASA. If that does not help, engage Cisco TAC.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: