10-08-2019 04:34 AM
Hi Guys
We're having a strange issue with our Nexus 9ks and wondering if anyone else has seen it before.
We use ISE as our AAA server with a normal TACACS+ connection but every time we attempt to connect to the switches, the 1st attempt succeeds from ISEs perspective but the switch closes the connection. The second connection attempt always succeeds. The user would just be local to the ISE store and tacacs timeout is set to 30 seconds. Theres no failures at all I can find.
We don't have the same issue on any of the catalyst switches with the same configurations.
Anyone come across this before?
Thanks!
Eoin
10-08-2019 12:19 PM
You can check on the ISE what is the reason for rejection, is the ISE users or ISE uses external authentication against LDAP/AD ?
10-09-2019 12:29 AM
10-09-2019 07:32 AM - edited 10-09-2019 07:45 AM
To Identify the issue, if we could enable debug logs and send to syslogto co-related when the problem occurs or simulate the issue to understand what went wrong between ?
Do you have any CoPP policy in place on the switch ?
10-10-2019 01:46 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide