08-27-2019 02:50 AM - edited 02-21-2020 11:09 AM
Hello Expert,
My customer's requirement is , they want to use RADIUS protocol for Device Administration for the GUI Based Devices.
External Identity Source to be used for the same is LDAP server running in a Microsoft Server.
We have configured the Authc and Authz Policy for the same. Issue which we are facing here is when a user is logging into the GUI their authentication is failing, but on ISE RADIUS Live logs failed log is not seen. (No logs available for GUI Authentication Request)
We took packet capture for the same where we can seen device is sending "ACCESS-ACCEPT" to ISE node but node is sending back "ACCESS-REJECT".
Please note If we are using MS- Active Directory in AUthentication Rule same is working fine. But here the requirement is to use the LDAP server.
I have attached the pcap for the same.
Any pointer for the resolving this issue is really helpful!!!
Thanks and Regards,
Solved! Go to Solution.
08-27-2019 02:45 PM
Sounds to me as if your LDAP integration is perhaps not working as expected. You would need to share some more details about how you integrated the LDAP, and the various tabs of the config that relate to that. I have set it up myself in the past and it's a fiddle job to get the parameters right (AD is plug and play, but with LDAP you have to be very prescriptive and exact).
Does the bind from ISE to LDAP success?
If your Subject Search Base and Group Search Base is setup correctly then you should be able to Retrieve Groups from Directory as a confirmation.
The wireshark doesn't tell us much - if you still have the pcap file, add an OR filter to include ldap - let's see what's going on there. And the ISE Live Logs must be showing the access-request at least, or else you have some suppression enabled that is blocking it. Disable it temporarily for testing
Admin -> System -> Settings ->Protocols -> RADIUS and then uncheck the "Suppress repeated failed auths"
08-27-2019 02:45 PM
Sounds to me as if your LDAP integration is perhaps not working as expected. You would need to share some more details about how you integrated the LDAP, and the various tabs of the config that relate to that. I have set it up myself in the past and it's a fiddle job to get the parameters right (AD is plug and play, but with LDAP you have to be very prescriptive and exact).
Does the bind from ISE to LDAP success?
If your Subject Search Base and Group Search Base is setup correctly then you should be able to Retrieve Groups from Directory as a confirmation.
The wireshark doesn't tell us much - if you still have the pcap file, add an OR filter to include ldap - let's see what's going on there. And the ISE Live Logs must be showing the access-request at least, or else you have some suppression enabled that is blocking it. Disable it temporarily for testing
Admin -> System -> Settings ->Protocols -> RADIUS and then uncheck the "Suppress repeated failed auths"
08-30-2019 04:02 AM
I would also recommend working through TAC for deep level troubleshooting and support
08-30-2019 11:14 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide