Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,after recent upgrade of C3650s from 16.6.4 to 16.6.6 switches started requesting CTS data before PAC is provisioned. Because of this ISE is dropping RADIUS messages with the error message 11302 Received Secure RADIUS request without a cts-pac-opaq...
Hi team,
I have a case where SGT tagging based on IP/subnet to SGT map is needed on N7K (M3 LC) without enforcement active. Traffic that needs to be tagged can enter nexus:
- via untrusted access portchannel - no SVI for this specific VLAN, packets...
Dear team,
I'm trying to find a way how to easily delete a lot of policies from an existing TrustSec matrix. Based on documentation this seems to be the right way:
"Check the Overwrite Existing Data with New Data check box if you want to overwrit...
In my opinion when ISE is the pushing static IP-SGT mappings it acts like a kind of automation tool that the engineer is using in a controlled way as he needs to trigger the deployment manually using the deploy button so no unexpected saves can happe...
Hi, RADIUS servers are probed every 1 with the automate-tester feature and ISE is sending back access-reject messages however this doesn't bring the RADIUS servers UP again. I have also tried to remove the whole RADIUS config and applied back but no ...
Thanks for the reply.
In our setup we have N7k (NX-OS 8.3.1) registered to ISE and envi-data & policies downloaded successfully. IP to SGT mappings are correctly pushed from ISE and present in config and no enforcement is active. We have 1 VLAN wit...