cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

CTS Request before PAC provisioning making RADIUS server DEAD

Michal Olsovsky
Level 1
Level 1

Hi,

after recent upgrade of C3650s from 16.6.4 to 16.6.6 switches started requesting CTS data before PAC is provisioned. Because of this ISE is dropping RADIUS messages with the error message 11302 Received Secure RADIUS request without a cts-pac-opaque cisco-av-pair attribute. These silent drops are effectively marking the RADIUS server "DEAD" and because of "radius-server deadtime 15" making it unusable for some time. 

 

Does anyone else also observed this change of CTS request behavior? Is this now new expected behavior? Is there a way to force the switch to ask for CTS data only once the PAC is provisioned or change the ISE not to silently drop the requests but reply with access reject message?

 

Thank you.

Who Me Too'd this topic