cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1654
Views
0
Helpful
5
Replies

No authentication request from switch to ISE

welmjendel
Level 1
Level 1

hi Guys,

I faced a problem with our ISE ; when  i changed the ip address of our ISE, there is no authentication request from switch and  there is no log to troubleshoot.

FYI: i changed the ip address on the switch.

Regards,

 

 

5 Replies 5

Hi,

Is there basic network connectivity between the switch and ISE server? Can you ping the ISE servers's new ip address from the switch?

Run show aaa server on the switch and see if the radius server is alive or dead

thank you for your response! 

yes i can ping the ise from Switch ; there is no issue of connectivity.

What is the output of the show aaa server command? Is the radius server marked alive or dead? Is this issue just on one switch or all switches?

 

Can you run a test authentication using the command test aaa group radius server.... you'll have to fill in the ip address of your ise server and username etc in order to run the command. What is then displayed in the ISE logs?

Additionally, when you ping are you using source interface as your radius source. 

 

Also, if you debug radius authen are you seeing request without response.? 

kussriva
Level 1
Level 1
Hi welmjendel,

When you enter the new IP in the switch config, re-enter the shared key as well. Now run the test aaa group radius command and see if the server comes back up.

Thanks & Regards,

Kushagra Srivastava
Cisco PDI
http://www.cisco.com/go/pdi
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: