cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

5449
Views
10
Helpful
14
Replies
Manish Patel
Beginner

ISE doesnt send Guest accounts via Email

HI

I have come across an issue in ISE1.1.2.

once i create a guest account, and click on email, i get the below error

i have patched version 1.1.2 to the latest patch 3

i have also configured teh sponsor portal customisation email address.

           

ISE reports "Internal Error encountered. Please contact administrator or help desk"

anyone have any suugestions?

14 REPLIES 14
nspasov
Cisco Employee

Hmm that is strange. I just configured this today on the same version and worked just fine. Can you please confirm that you have:

1. SMTP configuration completed in the ISE admin node

2. Have defined an e-mail address in the sponsor portal (under settings)

3. Allowed the ISE node to use your SMTP relay

Thank you for rating!

Hi Neno

i have configured an SMTP server on ISE admin, i have created a default email address ( sponsor@xyz.com.au). i have got an email address in the customization page of teh sponsor portal ( user@xyz.com.au).

One thing i just tried was when i create a guest user with an email address of user@xyz.com.au , that worked fine. but if i configure a guest user with an email address of user2@abc.com.au , this is when i get the error message.

Hmm perhaps a bug then...I can test this in my lab when I return but I had 4 accounts generated and they all worked with no problems. Are you using valid e-mail addresses or some not real ones?

i am using valid email addresses for both the guests and sponsor

I'm having the same issue, but it does appear to be sending the emails in my case.  The error is pretty generic and doesn't indicate what the actual issue is.

what i found out was that if teh sponsor email and the guest user email are on the same domain , then the email works. if sponsor email is on xyz.com and guest user is on abc.com  , then both of them dont get emails.

Anyone come across this or is it a bug..on version 1.1.2

That matches up with what I am seeing too except the sponsor always seems to get the email.

descalante2007
Beginner

I was with the same issue by several days. I set SPAN in the switch port to monitor SMTP on the ISE port and I saw an authentication message. "530 5.7.1 Client was not authenticated". With this info I realized the ISE was sending and the Exchange Server was dening the service.

It is working now, but I still have a question:

When I create new accounts, the email with username and password should be sent inmediately or the Sponsor must send it manually selecting the user from the main list and clicking on Send Email ... ??

These problems all sound like your exchange server is not allowing the ise to do relaying.

Jan, so in an environment where Exchange restricts IPs that are allowed to relay mail, do you need to add all of the ISE PSNs for sponsor, and PANs for Alerting, or does ISE use the PAN IP for all messages?

I'm not 100% sure if PSN's will be used for sending email, you should probably add all ise servers to the relay allow list just to be on the safe side.

Did anyone find a fix for this or know if it is a bug? I am running into the same issue. Can send emails to users on the same domain but not to users on a different domain. However, if I manually send the emails through a telnet session from the ISE appliance I am able to send the emails.

I'm experiencing the same issue.

Right now, ISE does not support SMTP authentication as a global setting so that one can send emails for guest/contractors using a secure SMTP server.

In my particular case, adding an exception to the SMTP server that allow ISE to send emails without beeing authenticated is not a option. The customer will simply say that ISE - as a security platform - should have a SMTP authentication tab and sending email wihout any form of authentication is a security breach.

The same thing applies with proxy settings. There is no tab or checkbox for proxy authentication settings...

Facing the same issue today. I realized that I only had part of my PSN's into the Exchange Relay List so I just added into it and done. Everything is working fine now.

Create
Recognize Your Peers
Content for Community-Ad

ISE Webinars


Miss a previous ISE webinar?
Never miss one again!

CiscoISE on YouTube