cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1190
Views
0
Helpful
6
Replies

ISE - IOS bug!

sudheere
Level 1
Level 1

I am using a stange issue in my environment. I use ISE 1.2 fo as radius server for device management/authentication(Not NAC usage). I am having Cisco c6509E VSS as core device. The device was added to ISE and aaa auth was working fine. I changed IP address of switch during my DC migration. Since then AAA fail for thsi device. ISE report and TCPdump shows old IP. My wireshard capture(SPAN port) also showing old IP in packet header irrespective of radius source interface I use in switch. Debug (radius/aaa) output in switch showing the correct interface addres whcih I  use in 'ip radius source-interface'.

Unfortunatly I am unable to restart switch as it is core device in a critical place. It looks like a stange IOS issue. Did any one faced this kind of issues? Please advise how to resolve without restart. Don't know why the switch is always using its old IP to frame radius packet.

6 Replies 6

Kevin P Sheahan
Level 5
Level 5

Check the following:

  • Radius source interface on the 6k matches ISE NAD IP for 6k
  • ISE NAD IP was changed when IP on 6k changed
  • Route/Connectivity to/from ISE/6k.

Kind Regards,

Kevin Sheahan, CCIE # 41349 (Security)

Kind Regards, Kevin Sheahan, CCIE # 41349

These have been virified. I tried difference source interfaces and even changed  MAC addresses of SVIs. I am sniffing interface of ISE appliance to capture radius packets. I wondering how C6509E switch can frame a IP packet with source address not belonging to it. MAC address belongs to the switch but source IP address not belonging to the switch(Its old IP address).

I cleared all all aaa/radius related configuration and reconfigured again but probelm remains.

Did you change the ip of the device in your ISE configuration under Administration > Network Devices?

What version of code are you running? Also when issue a "debug radius authentication" do you see any errors when pulling the new ip address? Also if you are using radius server groups did you change the source interface under the group configuration also?

Tarik Admani
*Please rate helpful posts*

Try removing and re-adding the AAA configuration to the switch, to see if that will make the RADIUS service pick the right source interface.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: