07-21-2019 04:22 AM
Hi, we have a 2 node ISE deployment with authentication requests going to ISE1. This is configured for multiple different connection types and all works as expected. However, when I test the PSN failover by removing ISE1 from the network I have issues with wired DOT1X connections (EAP-TLS). In the logs I am seeing attempts to ISE2 but the following error:
5440 Endpoint abandoned EAP session and started new
I have tried resetting the client NIC / rebooting and removing the client from ISE but still experience the same problem.
When I bring ISE1 back online everything works again as it should.
Any help on this would be appreciated.
Thanks
Terry
Solved! Go to Solution.
07-21-2019 05:09 AM
The most common cause would be a certificate issue. Do the PSN certificates match on both nodes? Typically we would have a single certificate with SANs for each node.
Are you using native supplicant? If so do you have "Verify the server's identity..." (certificate matching) checked in the supplicant configuration? See step 9 here:
07-21-2019 05:09 AM
The most common cause would be a certificate issue. Do the PSN certificates match on both nodes? Typically we would have a single certificate with SANs for each node.
Are you using native supplicant? If so do you have "Verify the server's identity..." (certificate matching) checked in the supplicant configuration? See step 9 here:
07-21-2019 06:21 AM
07-21-2019 06:55 AM
Check the step section of the auth details report and see how far it got. You might also need debugging on the client side. Or, restart ISE services on the second node. Please engage Cisco TAC if you need help troubleshooting it further.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide