cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
545
Views
2
Helpful
2
Replies

ISE 2.7 Radius suppression and CTS

kefear
Level 1
Level 1

Hi all!

We're using Cisco Trustsec in our Branch Office and currently investigating an interesting issue - it looks like Radius Suppression does not work for endpoints connected to NADs onboarded for CTS.

As a result we see all of the failed attempts (MAB, for example) for every endpoint where as having radius suppression turned on:

kefear_0-1698679929406.png

For all of them we see expected reject:

kefear_1-1698679966628.png

Our Radius Suppression Settings:

kefear_2-1698680053522.png

I've collected some debugs and it looks like CTS has some impact here:

2023-10-30 22:17:24,466 DEBUG [Thread-250][] cisco.cpm.prrt.impl.PrRTLoggerImpl -:::::- ClientSuppression,DEBUG,0x7f348e1a3700,cntx=0000106875,sesn=ise-1n2/488037056/2462,CPMSessionID=6704840A0001C45A35C19954,CallingStationID=6C-24-08-8A-E9-26,FramedIPAddress=10.132.74.148,ClientSuppression isRejectEndpoint: EndpointID=6C:24:08:8A:E9:26,ClientSuppression.cpp:424
2023-10-30 22:17:24,466 DEBUG [Thread-250][] cisco.cpm.prrt.impl.PrRTLoggerImpl -:::::- ClientSuppression,DEBUG,0x7f348e1a3700,cntx=0000106875,sesn=ise-1n2/488037056/2462,CPMSessionID=6704840A0001C45A35C19954,CallingStationID=6C-24-08-8A-E9-26,FramedIPAddress=10.132.74.148,ClientSuppression endpoint is not in the misconfigured list,ClientSuppression.cpp:468
2023-10-30 22:17:24,523 DEBUG [Thread-211][] cisco.cpm.prrt.impl.PrRTLoggerImpl -:::::- Radius,DEBUG,0x7f348e5a7700,cntx=0000106875,sesn=ise-1n2/488037056/2462,CPMSessionID=6704840A0001C45A35C19954,user=6C-24-08-8A-E9-26,CallingStationID=6C-24-08-8A-E9-26,FramedIPAddress=10.132.74.148,FAILED ATTEMPT - AccessReject detected.,RadiusRequestFlow.cpp:758
2023-10-30 22:17:24,523 DEBUG [Thread-211][] cisco.cpm.prrt.impl.PrRTLoggerImpl -:::::- ClientSuppression,DEBUG,0x7f348e5a7700,cntx=0000106875,sesn=ise-1n2/488037056/2462,CPMSessionID=6704840A0001C45A35C19954,user=6C-24-08-8A-E9-26,CallingStationID=6C-24-08-8A-E9-26,FramedIPAddress=10.132.74.148,ClientSuppression OnFailure: prevent client suppression for CTS client endpoint,ClientSuppression.cpp:148

However, i did not find any input on such behavior in documentation. Any thoughts?

 

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

What version of ISE is this? You might want to open a TAC case. I agree with you - I don't see why CTS should make any difference with respect to the suppression functionality in ISE.

View solution in original post

2 Replies 2

Arne Bier
VIP
VIP

What version of ISE is this? You might want to open a TAC case. I agree with you - I don't see why CTS should make any difference with respect to the suppression functionality in ISE.

Currently we're on 2.7.0.356 Patch 6. Agree with you, we'll definitely open SR to investigate this