Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Could you please share the aaa sanitized configs for review? also, you mentioned no authorization logs are generated when you try to SSH into the replaced firewall, you don't even see any failure logs on ISE? if you see any, could you please share a ...
I am assuming that you are referring to the FMC management accesses? If so, I think you would need to enable logging for IP Tables, or if you just want to check the IP Tables rules then you can use the command "sudo iptables -L" from FMC CLI.
Get #IP...
What do you mean by "Behavior seems more common on networks using web filtering or SSL inspection"? is this issue happening on clients that are sitting on networks with no URL filtering or SSL decryption?
Imo, what you descibed couldn't be caused by ...
Generally speaking, it's always recommended to move away from MAB and credentials based authentication to certificate based. So, the aim should be to start moving towards EAP-TEAP (so you don't have to rely on NAM) for authentication chaining and do ...