Hi everyone!
I'm setting up wireless BYOD with guest portal and having issues with the specific option on ISE - "Prevent active directory user lockout".
I turned this option on and tried to simulate locking out user account entering wrong password for his account.
Fair enough, after 3 attempts ISE won't let me login anymore because it's locked on ISE even if I enter correct password:
AD would block user in AD if badPwdCount gets to 5, so the account is still working for other services.
But now I'm having issues with unlocking the account on ISE. I tried to re-login to wired network using correct login/password to reset badPwdCount Attribute. After that I try to login to BYOD page portal and I still get the same "Selected Indentity Source is DenyAccess" like ISE doesn't care about badPwdCount at all.
I even checked the badPwdCount counter on ISE itself using "Test User" feature on ISE and it actually shows it's zero!
Is there a chance ISE checking some other attributes? How do I troubleshoot why ISE specifically decide to lock me?
ISE 3.3.0.181 Patch 2