cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
659
Views
0
Helpful
4
Replies

Recent upgrade ISE to 2.4 stopped authentication working

kticehurst
Level 1
Level 1

Have had an ISE deployment running for some time performing DOT1x wired authentication, authorisation and profiling. Had some issues with 3650 switches but traced that to them not running in install mode. Recently we have upgraded the ISE to 2.4.0.357 and now clients all fail authentication and are rejected. No policies have changed only the code version and patch. Anyone had any issues with 2.4 and 3650 switches ?

4 Replies 4

Craig Hyps
Level 10
Level 10

Recommend open TAC case to troubleshoot.

cjwolff
Level 1
Level 1

What did you find out about bundle vs install mode?  I have quite a few issues with regard to profiling on 3650s with the latest 2.4p1.

Thanks,

C.

Hi Christopher, Had problems with 3650s in bundle mode where they would get stuck during posturing of the client. Would see switch authentication complete but never apply the redirect access list for the ISE posture check. Installled 3.6.6 in install mode and no problem.

Also found an issue with ISE 2.4 where if you are identifying network device as all locations but have that switch in a location sub group it will not match the profile set.

I did run in to the sub group behavior you mentioned during an ACS to ISE migration.  Switching from "in all locations" to "contains all locations" fixed it up though. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: