08-28-2024 03:10 AM
ISE 3.3 Patch 2 with NDFC - Internal User gets disabled
Hello all,
we have an issue with an internal user on ISE which always gets disabled after some time. Or rather NDFC can not authenticate with a given user anymore.
This user is used by Nexus Dashboard Fabric Controller to discovery nexus devices. At first discovery and management works but after a period of time the user will be disabled. According to ISE authentication fails because of an invalid shared secret or password. And afterwards because of our policies, the user becomes disabled.
Since discovery and management of the devices worked before and nothing was changed, I am rather clueless what might be the reason for the failed authentications.
This issue also appears with an internal user for Prime. But here it will take more time until this user will be disabled.
Changing the password or recreating the user does not work. Authentication policies should be okay.
Do you have any suggestions what might be the reason?
Thanks in advance!
Kind regards,
Daniel
Solved! Go to Solution.
09-02-2024 03:49 AM
Hello,
the issue was on NDFC. Somehow it uses wrong passwords for whatever reason. I restarted and and clean-wiped it and so far the issue disappeard.
Greetings.
08-28-2024 03:42 AM
- For the time being I would start by disabling these settings after lock out actions and disabling after a number of login attempts (during a test period). For the rest you have https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html
which might help looking into ; when choosing logs to start with , you may start by those related to authenticating uses,
M.
09-02-2024 03:49 AM
Hello,
the issue was on NDFC. Somehow it uses wrong passwords for whatever reason. I restarted and and clean-wiped it and so far the issue disappeard.
Greetings.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide