cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
794
Views
0
Helpful
4
Replies

Meraki APs no longer access to ISE

jimmy10
Level 1
Level 1

Hi,

My Meraki APs no longer can access to ISE, there has been no change in the configs. When I Run the Radius test from Meraki I get this-

craigaddison_0-1667812453917.png

And the ISE logs have this-

craigaddison_1-1667812762275.png

 

The username & password are correct. I can ping the Radius server from all the APs fine. What will be the issue?

4 Replies 4

RADIUS Pre-shared key?

I can confirm that the Radius PSK is exactly the same on both Meraki & ISE, but there is still the issue as above.

thomas
Cisco Employee
Cisco Employee

thomas_0-1667885654738.png

The LiveLog message is pretty clear. You included no information about the endpoint configuration or Meraki timers so hard to know.

8/10 APs failed to connect to your ISE RADIUS server and 2/10 APs are unreachable.  I suggest you start with checking routes and pings.

 

Are you assuming authentication doesn't work only because of the test results?

If for example your ise is configured to authenticate TLS only, test will fail for sure since it's not TLS, most probably it's not even EAP but simple PAP,