SXP connections between devices or switches and ISE is not in the "UP" state. The connection state is either "PENDING_ON" or "OFF".
The local mode in the device SCP configuration is different from Peer Role in the SXP Devices section on ISE. For example, local mode configured on the device is listener and the Peer Role on ISE is both or speaker.
You are unable to ping ISE from the device, especially when SCP is configured for a particular VRF.
Verify whether the SXP connection between the device and ISE is on.
sh cts sxp connections
Or, in the case of VRF:
sh cts sxp connections vrf <VRF name>
The output of thee command should show the connection status as "ON".
9500BR#sh cts sxp connections vrf WIRED
SXP : Enabled
Highest Version Supported: 4
Default Password : Not Set
Default Source IP: Not Set
Connection retry open period: 120 secs
Reconcile period: 120 secs
Retry open timer is not running
Peer-Sequence traverse limit for export: Not Set
Peer-Sequence traverse limit for import: Not Set
Peer IP : 172.18.202.4
Source IP : 126.96.36.199
Conn status : On
Conn version : 4
Conn capability : IPv4-IPv6-Subnet
Conn hold time : 120 seconds
Local mode : SXP Listener
Connection inst# : 1
TCP conn fd : 3
TCP conn password: none
Hold timer is running
Duration since last state change: 0:23:55:59 (dd:hr:mm:sec)
On ISE, navigate to Workcenters > TrustSec > SXP.
Configure the device by clicking Add. Make sure thee Peer role is the same as the local mode defined on the device.
After a few minutes, the status should show as ON.
If the SXP connection between the device and ISE is not in the UP state after the above-mentioned verification and configuration steps, open a TAC case to further troubleshoot the issue. Please provide the output of the verification commands while opening the case.
hello everyone I'm trying to setup a management network at home containing 4 routers and 4 switches the switch I chose to be my mgmt switch is a c2960 running IOS 15 k9 version. the problem I'm having is that I can ssh from the switch to all ot...
I have configured my cisco 3850 swtich for L3 Routing and have followed many online resources from Cisco about proper configuration, but am not able to get the inter-vlan routing to work. I have checked all of my commands several times and going thr...
Hi,please tell me,Can I block a switch locally connected in a network with Cisco ASA 5500 series firewall, so that any computer connected to that switch does not get the ip address from firewall dhcp service?Thanks.
I have to open port 1149 to be able to access OpenVPN, but I am not having success with the NAT configuration I made.by the dTCP port checkert, is giving time out, in the output of the show ip nat translate is showing that is translating.attached has the ...