06-10-2025 08:56 AM
Hello everyone!
Recently in Deployment ISE on PSN in one of the nodes the following errors appeared: when attempting to authorize via Dot1.x and MAB protocols.
But there are also normal sessions.
After Radius Request Drop, due to load balancing configured on NADs, the device is successfully authenticated/authorized on the next PSN node in the group (there are only 3 PSN nodes in each group)
Rebooting the node does not help.
When deregistering (removing) a node from Deployment, all radius sessions are successful (when the node is Stand Alone)
Cisco Identity Services Engine Version 3.1.0.518
Cisco Identity Services Engine Patch Version 7
Could someone help us to resolve problem?
Thank you in advance!
Solved! Go to Solution.
06-10-2025 02:28 PM
Sounds like a TAC case to me. But if you want to investigate yourself, then try reproducing it, and run a tcpdump on that node - if the RADIUS Access-Request packet looks normal (i.e. same as a 'working' request) then you can conclude that the PSN has lost its marbles. But since we (ISE admins) can't influence the programming of a PSN node (it's all done via the Admin node) there is little we can do, other than de-register, re-register, reboot etc. I don't understand why a de-registered node would work any differently to a registered one. The Services programming remains in tact after de-registration.
Sometimes, you can force a config "push" to the PSNs by making a config change that should be replicated to all nodes - e.g. create a new dummy Policy Set that does nothing, and then delete it again - perhaps that's enough to force a reprogramming of the node. But it's just a guess.
06-10-2025 02:28 PM
Sounds like a TAC case to me. But if you want to investigate yourself, then try reproducing it, and run a tcpdump on that node - if the RADIUS Access-Request packet looks normal (i.e. same as a 'working' request) then you can conclude that the PSN has lost its marbles. But since we (ISE admins) can't influence the programming of a PSN node (it's all done via the Admin node) there is little we can do, other than de-register, re-register, reboot etc. I don't understand why a de-registered node would work any differently to a registered one. The Services programming remains in tact after de-registration.
Sometimes, you can force a config "push" to the PSNs by making a config change that should be replicated to all nodes - e.g. create a new dummy Policy Set that does nothing, and then delete it again - perhaps that's enough to force a reprogramming of the node. But it's just a guess.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide