cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1051
Views
0
Helpful
4
Replies

radius response ise

edondurguti
Level 4
Level 4

Any idea why I get this even though clients are authenticated?

radius.png

2 Accepted Solutions

Accepted Solutions

Tarik Admani
VIP Alumni
VIP Alumni

Edon,

I usually see this when i am testing, if I start to do dot1x and then i unplug the port, the peap session is still active in the ISE database and then expires after 120 seconds. Usually if users are roaming even with mobility groups set, if they happen to roam from one controller to the other, you could expect this behavior if the client happens to be associating at that time.

Thanks,

Tarik Admani
*Please rate helpful posts*

View solution in original post

Keep in mind that the radius server selection is done at the NAS (WLC and switches), once they mark a radius server dead they will keep forwarding traffic until that radius server goes off line and then they flip back over. That is to be expected.

Tarik Admani
*Please rate helpful posts*

View solution in original post

4 Replies 4

Tarik Admani
VIP Alumni
VIP Alumni

Edon,

I usually see this when i am testing, if I start to do dot1x and then i unplug the port, the peap session is still active in the ISE database and then expires after 120 seconds. Usually if users are roaming even with mobility groups set, if they happen to roam from one controller to the other, you could expect this behavior if the client happens to be associating at that time.

Thanks,

Tarik Admani
*Please rate helpful posts*

Yeah I think it got intense when I rebooted the primary ISE for that CSR issue that I had where it wouldn't generate a signing request, then everybody got policed from secondary ISE and the error popped up.

Interesting though when the primary ise came up, all the new authentication were still pointing to the secondary one all untill i had to reboot the secondary aswell, it's like the PRIMARY ISE didn't kick in when it came online.

Thank you for your help.

Keep in mind that the radius server selection is done at the NAS (WLC and switches), once they mark a radius server dead they will keep forwarding traffic until that radius server goes off line and then they flip back over. That is to be expected.

Tarik Admani
*Please rate helpful posts*

Hi,

here is an article that may help you understand the flow of the radius server tracking verify these settings on your wlc.

https://supportforums.cisco.com/message/3716828#3716828

Thanks,

Tarik Admani
*Please rate helpful posts*