cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2951
Views
10
Helpful
6
Replies

ISE policy nodes not responding to radius requests

asimk
Level 1
Level 1

Hi Guys

ISE v2.3

Everything was working fine and i dont know whats changed and its doing my head in!

 

Anyconnect client connects to an ASA which has an ISE node as a radius server.

 

======================================

aaa-server ISE-RADIUS protocol radius
 authorize-only
 interim-accounting-update periodic 1
 dynamic-authorization
aaa-server ISE-RADIUS (********) host ********************

======================================

 

I can see from te ISE Live logs that the request is getting to the policy node, its authorised and there is content in the results section of the logs which is supposed to get sent back to the ASA but this doesnt happen.

 

debug on ASA shows:

send pkt xxxxxxxxxxxx/1645
RADIUS_SENT:server response timeout

 

packet capture on ASA shows packets going out but none coming back.

packe capture on policy node shows packets coming in from the ASA but none going back out.

 

Any ideas?

 

 

 

1 Accepted Solution

Accepted Solutions

Just to close this one off, I forgot that i had changed the banner on the advanced atributes in the auth profile to something very long and this was the issue.

View solution in original post

6 Replies 6

gbekmezi-DD
Level 5
Level 5
Have you opened a TAC case? Is this happening on a single PSN or all of your PSNs? Can you share a screenshot of the details page of the authenticated and authorized live log entry that’s not sending a result? Can you go back far enough to compare if the details look different than they looked when it was working?

Hi gbekmezi

No TAC just yet but i will do if i dont get anywhere.

screenshots attached.

i cant go back far enough in the logs for success logs.

 

Thanks


AK

sorry, its happening on both of my PSN's

 

Yep, network connectivity is fine between the ASA and the PSN

Just to close this one off, I forgot that i had changed the banner on the advanced atributes in the auth profile to something very long and this was the issue.