07-29-2020 12:39 AM
Hello,
we've got a ISE Test-Device on VM and a Deployment on Hardware.
When I install Patch 2 on the virtual machine, TACACS is broken, I get a " 13078 Invalid TACACS+ authorization request packet - possibly malformed packet"
rolling back Patch 2, everything is fine again.
The same Patch on the Hardware-Deployment is working fine.
Has anyone installed the Patch on a VM and is running TACACS Policy?
Radius is fine
07-29-2020 04:54 PM
I had a horrid experience with 2.7 p1 and I eventually killed it off in favour of the old ISE 2.4 - but thanks for your valuable feedback - if you could open a TAC case to get confirmation of a bug, then it would be very helpful in avoiding this patch. If it is a bug then Cisco ought to reconsider making this a golden/recommended release. There is no reason for TACACS to stop working so late in the game.
07-30-2020 10:53 PM
Hello @gaigl
I have tested device admin with ISE VM 2.7 on a 3750 switch and it works even after upgrading ISE to patch 2.
Were you able to gather packet capture from ISE during the time of the issue ?
If yes, what do you see when you decrypt Tacacs+ packet exchange in wireshark by entering the shared secret?
Thanks,
Dinesh Moudgil
P.S. Please rate helpful posts.
08-02-2020 10:48 PM
no I didn't take a capture, when I saw the error, I instantly rolled back.
But maybe I try the patch once again.
thanks for your test
08-02-2020 10:58 PM
Please do take packet captures and debugs on both ISE and switch or perhaps open a TAC case if you can, to investigate further.
Thanks,
Dinesh Moudgil
08-03-2020 05:08 AM
I have ISE 2.7 Patch 2 (single node VM deployment) in my lab with TACACS (Device Admin role) and it is working fine.
08-03-2020 06:36 AM
I've tried patch-install a decond time: now it's ok.
strange but ok
thanks guys
11-18-2020 01:20 AM
I see your Tacacs Live logs are working? I cant get mine working, not sure what's happening. I am same version and patch as yourself.
Tacacs reports are fine.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide