12-20-2019 08:09 AM
Good morning everyone. Is there a fix for these alerts?
Alarm Name :
RADIUS Request Dropped
Details :
RADIUS Authentication Request dropped : Server=CiscoISEVM01; NAS IP Address=x.x.x.x; NAS Identifier=N/A; Failure Reason=5440 Endpoint abandoned EAP session and started new
Description :
The authentication/accounting request from a NAD is silently discarded. This maybe because the NAD is unknown to ISE, mismatched Shared Secrets, or invalid packet content per RFC.
Severity :
Warning
Suggested Actions :
Check that the NAD/AAA Client has a valid configuration in ISE. Check whether the Shared Secrets on the NAD/AAA Client and ISE match. Ensure that the AAA Client and the network device, have no hardware problems or problems with RADIUS compatibility. Also ensure that the network that connects the device to the ISE, has no hardware problems.
*** This message is generated by Cisco Identity Services Engine (ISE) ***
Sent By Host : XXXXX
Solved! Go to Solution.
12-20-2019 01:27 PM
These are normal alerts and can be ignored for the most part. What this is saying is that the endpoint started an EAP session and before it was completed, the endpoint started a new session so ISE dropped the original request. This happens when Windows machines are booting up. The machine will start the 802.1x process and once GPO's get applied, the machine will stop and start again with a new exchange. That causes the 5440 alerts on ISE. If it is happening quite a bit and users are complaining, then I would recommend opening a TAC case. But most times, it doesn't impact users.
12-20-2019 01:27 PM
These are normal alerts and can be ignored for the most part. What this is saying is that the endpoint started an EAP session and before it was completed, the endpoint started a new session so ISE dropped the original request. This happens when Windows machines are booting up. The machine will start the 802.1x process and once GPO's get applied, the machine will stop and start again with a new exchange. That causes the 5440 alerts on ISE. If it is happening quite a bit and users are complaining, then I would recommend opening a TAC case. But most times, it doesn't impact users.
12-23-2019 07:11 AM
Thanks for the info. I'll suppress the alerting as they are frequent but so far no one is complaining. We have 30 locations online and about 900 employees.
12-23-2019 02:28 PM
I'd recommend looking at tuning your wireless network and other items to suppress these as well. @cgambrel has a nice session on further tuning BRKSEC-2059 check out http://cs.co.ise-training, Also check out BRKSEC-3432 slides and recording over the years
10-21-2024 09:00 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide