04-29-2019 01:16 PM - edited 04-29-2019 01:17 PM
I have a couple of cat 9300 uxm switches in my SDA fabric that continue to attempt to reach out to ISE for pac provisioning. The devices have a valid pac that is not expired. It seems that they have a hung provisioning job. What is the best way of killing the hung session without blowing away the actual pac in use? I would prefer an easier way and would love to avoid having to remove it from fabric and re-add it.
In ISE radius live logs I see:
5405 RADIUS Request dropped
AAA:service-type=cts-pac-provisioning
On the devices I see:
#sh cts provisioning
A-ID: Unknown
Server XXXXX, using shared secret
Req-ID 1c6b002a: callback func 0xffef5a6ba8, context (nil)
#sh cts pacs returns valid pac and shows everything is good.
The hosts 8021x sessions and everything seem to be fine. However, every couple of minutes the live logs get flooded with the attempts/drops. My other fabric switches show no outstanding provisioning jobs. The two devices in question were rebooted over the weekend.
Solved! Go to Solution.
04-29-2019 10:16 PM
04-29-2019 01:49 PM
04-29-2019 10:16 PM
04-30-2019 05:31 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide