Hi
I have ISE PSNs loadbalanced with a Citrix MPX - there are 2 VIPs (same IP) for RADIUS authentication and accounting. These VIPs have the same peristence rules (calling-id with a backup of nas-ip).
I've noticed the following syslog messages in ISE RADIUS accounting for some clients:
Audit session was not found
Accounting start was received for non-existing session
I thought this may have something to do with some clients authenticating against one psn and the accounting traffic being sent to another. I confirmed this by modifying a NAD switch to use a particular PSN IP rather than the loadbalanced VIP for RADIUS. With this config in place, there were no more syslogs like the ones above.
I'm looking at the netscaler documentation below to share persistent sessions between the 2 RADIUS auth/acct VIPs so that a client's auth/acct traffic always hits the same psn for both services.
https://docs.citrix.com/en-us/netscaler/12/load-balancing/load-balancing-persistence/sharing-persistent-sessions.html
Has anyone else come across this issue and, if so, am I on the right track?
Thanks
Andy