01-22-2024 03:54 AM
When client joins network for a first time, we get "Radius session not found. Please contact helpdesk for assistance". After turning WiFi of the device Off and back on, everything works fine. We are running 17.11.1 on WLC9800 and 3.2 patch 4 on ISE
Solved! Go to Solution.
02-10-2024 12:11 AM
You clearly have a lot more going on here than you initially described and did not provide enough troubleshooting details. Please see How to Ask The Community for Help and call TAC so they may take the time to understand all components involved and where it might be wrong.
02-23-2024 12:33 AM
For anyone that might get an issue, solution was to change "port-bounce" to "re-auth" in Administration >> System >> Settings >> Profiling
01-22-2024 04:19 AM
Sounds like CoA is not properly configured on ISE and/or the controller.
Also why 17.11.1? Why not 17.12.X?
01-22-2024 04:57 AM
At the times when I tried 17.12.x, all WAP's were constantly disconnecting and were causing issues on network. However I can give it another go indeed.
As for the CoA, I am not sure what is there to be misconfigured? Some stations do work from the first attempt, but some not. It used to be all the time that first time attempt ended in the error but then we realised that RADIUS server in WLC was not configured in correct RADIUS group, and after that, situation improved a lot, however it still happens every new client. When testing, I remove MAC address from WLC and ISE to reproduce but that does not always produce the error
01-22-2024 05:10 AM
01-22-2024 04:21 AM
debug packet logging acl ip 1 permit <ISE IP>
Can you share the debug between WLC and ISE
MHM
01-22-2024 04:54 AM
Don't have that option...
MY681-WLC001#debug packet ?
<cr> <cr>
01-22-2024 05:22 AM
Debug not in enable mode in user mode
MHM
01-22-2024 05:54 AM
MY681-WLC001>debug ?
% Unrecognized command
01-22-2024 08:21 AM
We need to make sure the issue is from wlc or ise.
Can you check IP of client and excluded list in wlc' it can client add to exclude list. When trun down and up the client get new IP and hence can auth via ISE.
MHM
01-23-2024 09:55 AM
Clients do not end in Excluded list at all (unless they made mistake in PSK). They get address in same IP range both times, first when it fails and second when it works. And they can reach ISE web portal both time, however that authentication part is not working (always) first time. I am still struggling to reproduce the issue but it happens mostly on newly added devices.
01-22-2024 07:37 AM - edited 01-22-2024 07:38 AM
Not sure, but the issue could be caused by having the RADIUS session split across multiple PSNs. If you have multiple PSNs, did you configure one authorization rule for each one to redirect guest traffic?
01-22-2024 07:53 AM - edited 01-22-2024 07:58 AM
There is only one PSN configured. I have seen the post with F5 load balancing but that does not solves my issue I am afraid. We run everything on a single VM.
01-22-2024 08:07 AM
Single standalone VM? I would highly suggest adding an additional 1-2 VMs. Note that a single VM is only supported for evaluation use-cases: https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html
01-22-2024 08:15 AM
Is a small environment and VM is running in on VMWare cluster (redundant servers). What benefits would be of multiple VM's? Offloading?
01-22-2024 08:20 AM
High Availability
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide