SXP connections between devices or switches and ISE is not in the "UP" state. The connection state is either "PENDING_ON" or "OFF".
The local mode in the device SCP configuration is different from Peer Role in the SXP Devices section on ISE. For example, local mode configured on the device is listener and the Peer Role on ISE is both or speaker.
You are unable to ping ISE from the device, especially when SCP is configured for a particular VRF.
Verify whether the SXP connection between the device and ISE is on.
sh cts sxp connections
Or, in the case of VRF:
sh cts sxp connections vrf <VRF name>
The output of thee command should show the connection status as "ON".
9500BR#sh cts sxp connections vrf WIRED
SXP : Enabled
Highest Version Supported: 4
Default Password : Not Set
Default Source IP: Not Set
Connection retry open period: 120 secs
Reconcile period: 120 secs
Retry open timer is not running
Peer-Sequence traverse limit for export: Not Set
Peer-Sequence traverse limit for import: Not Set
Peer IP : 172.18.202.4
Source IP : 184.108.40.206
Conn status : On
Conn version : 4
Conn capability : IPv4-IPv6-Subnet
Conn hold time : 120 seconds
Local mode : SXP Listener
Connection inst# : 1
TCP conn fd : 3
TCP conn password: none
Hold timer is running
Duration since last state change: 0:23:55:59 (dd:hr:mm:sec)
On ISE, navigate to Workcenters > TrustSec > SXP.
Configure the device by clicking Add. Make sure thee Peer role is the same as the local mode defined on the device.
After a few minutes, the status should show as ON.
If the SXP connection between the device and ISE is not in the UP state after the above-mentioned verification and configuration steps, open a TAC case to further troubleshoot the issue. Please provide the output of the verification commands while opening the case.
Recently i need to migrate our windows 2008 server that installed with ssh tectia.All my laptop and checkpoint firewall were able to sftp to the new server successfully. However, for cisco switch we have, i have tried several different devices but th...
Hi......everyone ...my question is related to vlan......i have an cisco switch 2960G and i have configured vlans e.g vlan 100 for wirednetworks and vlan 200 foe wireless network......now i want that both vlans users are communicate with my med...
Okay, I'm a newbie. My question: I have set up 2 routers, connected to each other: R1int s0/3/0ip address 192.168.1.1 255.255.255.252int lo0ip address 220.127.116.11 255.255.255.0 R2int s0/3/0ip address 192.168.1.2 255.255.255.252int lo0ip address 1.1....
Hello Everyone, I have 3 SG350 and connected each other Here is the configSpoiler (Highlight to read)SW1#sh runconfig-file-headerSW1v18.104.22.168 / RLINUX_923_093CLI v1.0file SSD indicator encrypted@ssd-control-startssd configssd file passphrase con...
I have BGP learned prefixes that I want to redistribute into EIGRP but with different metrics. I use a route-map with a "set metric +512000" (with or without the + sign) but that does not take effect... I still receive the same metric with the default red...