01-23-2025 05:48 AM
Hello everyone, as mentioned in the title we have two ASA-5516-X devices with Software 9.16.4 (57), recently we have been experiencing that authentication through AAA (Cisco-ISE) fails for some reason approximately every 7 days and we have only managed to recover the service by restarting the ASA devices.
It is important to mention that at no time is communication lost at the Network level and in fact at the time of the failure the ASA does not send that type of traffic to the ISE, but other traffic, such as ICMP or something else.
Can you think of what could be happening?
01-23-2025 06:02 AM
Share
Show aaa server
MHM
01-23-2025 06:17 AM
Thank you for the prompt response.
Attached information.
Note: It is important to mention that there is a high number of rejections due to automatic geolocation of unsafe countries.
Server Group: ISE-AWS
Server Protocol: radius
Server Hostname: cisco-ise-zone-a
Server Address: 172.25.12.185
Server port: 1645(authentication), 1646(accounting)
Server status: ACTIVE, Last transaction at 11:11:37 UYST Thu Jan 23 2025
Number of pending requests 0
Average round trip time 938ms
Number of authentication requests 28014
Number of authorization requests 0
Number of accounting requests 6528
Number of retransmissions 0
Number of accepts 8325
Number of rejects 26076
Number of challenges 1049
Number of bad authenticators 0
Number of timeouts 141
Number of unrecognized responses 0
Server Group: ISE-AWS
Server Protocol: radius
Server Hostname: cisco-ise-zone-b
Server Address: 172.25.23.90
Server port: 1645(authentication), 1646(accounting)
Server status: ACTIVE, Last transaction at 14:24:44 UYST Wed Jan 22 2025
Number of pending requests 0
Average round trip time 1601ms
Number of authentication requests 253
Number of authorization requests 0
Number of accounting requests 4
Number of retransmissions 0
Number of accepts 8
Number of rejects 246
Number of challenges 7
Number of bad authenticators 0
Number of timeouts 3
Number of unrecognized responses 0
01-23-2025 09:16 AM
Number of authentication requests 253 <<-
Number of rejects 246 <<-
You have two AAA server abd it seem that ASA try second and the AAA is reiect the request' so try check second AAA.
MHM
01-29-2025 02:33 AM
Any news ?
MHM
01-23-2025 07:08 AM
What is the MFA strategy here? Why not use a SAML Flow instead? What version of ISE?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide