ISE server receives requests for authentication of the bridge VLAN, not the IP Address of the switch management

Hello

A 3850 catalyst switch has VLAN 20 (10.18.4.32/29) defined on it, which has a 10.18.4.38 gateway:

D01-01-BWY #show ip short int vlan 20
Interface IP-Address OK? Method State Protocol
Vlan20 10.18.4.38 YES manual up up

A server of ISE (SNS3415) is connected to a port configured on VLAN 20, with IP address of 10.18.4.33.

01-BWY-D01 has to a management interface of 10.18.4.17.

I created this switch as a device network in ISE and activated the RADIUS config and then configured the switch with the following commands:

RADIUS attribute 6 sur-pour-login-auth server
RADIUS attribute 6 support-multiple server
Server RADIUS attribute 8 include-in-access-req
RADIUS attribute 25-application access server include
dead-criteria 5 tent 3 times RADIUS server
RADIUS-server host 10.18.4.33 auth-port 1812 acct-port 1813 borders 7 1521030916792F077C236436125657
RADIUS-server host 10.18.4.35 auth-port 1812 acct-port 1813 borders 7 02350C5E19550B02185E580D044653

radius of the IP source-interface GigabitEthernet1/0/1

The problem:

When I test the functionality of RADIUS using the following command, it fails. HOWEVER, the customer (switch) IP listed in the error log in the front door of the VLAN 20 (!):

test the aaa group RADIUS server 10.18.4.33 auth-port 1812 Capita123 user radius acct-port 1813! new-code

10.18.4.38 is the gateway IP address of the VLAN that hosts the servers of the ISE, I don't understand why its listed in error as IP device logs!

ource Timestamp 2016-06-22 16:38:02.826
Receipt of timestamp 2016-06-22 16:38:02.841
Policy Server GLS-ISE-01
Event 5413, accounting RADIUS-Request dropped
Reason for failure 11007 could locate no device network or Client AAA
Resolution Check if the device network or AAA client is configured in: Administration > network resources > network devices
First cause Could not find the network device or the AAA Client while accessing NAS by IP during authentication.
Type of service Box
NAS IPv4 address 10.18.4.38

Other attributes

ConfigVersionId 118
Port of the device 1646
DestinationPort 1813
Protocol RADIUS
ACCT-status-Type Update-intermediate
ACCT-Delay-Time 15
ACCT-Session-Id 00000000
ACCT-Authentic RADIUS
AcsSessionID GLS-ISE-01/255868885/32
IP address of the device 10.18.4.38

If I reconfigure the switch to the ISE - peripheral network and give it the IP address of 10.18.4.38 (the ip of the gateway), my radius authentication tests suddenly becomes successful.

can someone clarify the situation what is happening here?

I need to be able to define multiple switches by their unique IP addresses.

Thanks for your time

m

Hello

The only time I saw that it was due to use a deprecated command: radius server host.  There was a bug on the IOS XR platform as well.

Could you please reconfigure your order of RADIUS by using the new command: radius server? And test again?

The doc of Cisco for the new order:

http://www.Cisco.com/c/en/us/products/collateral/iOS-NX-OS-software/iDEN...

Thank you

PS: Please do not forget to rate and score as good response if this solves your problem

Tags: Cisco Security

Similar Questions

  • HP 110 mini book requested for password on the switch on

    Anyone can help with my problem. I am asked to enter a password when that I start my notebook 110 hp.

    Thank you pfindla

    Pfind try.

    e9lofqxkqd

    3rd letter tiny L.

    4th letter lowercase O.

    6th and 9th Q lowercase letter.

    Use this code to go into the BIOS.

    Disable all passwords that are enabled.

    If demand for CURRENT password using this code.

    Request NEW password just press ENTER.

    If asked to hit just to CHECK password to enter.

    Save and exit.

    REO

    I must inform you that these services are not endorsed by HP, and that HP is not responsible for any damages that may occur to your system using these services. Please be aware that you do so at your own risk.

  • How can I make Apple sent an official request for Andorra in the list of international codes?

    Apple acknowledges that Andorra Telecom (Mobiland) is an approved operator.

    However it does not include the international dialing code of Andorra (+ 376) in the list of phone prefixes in the country.

    This prevents verification services, such as in two steps and two-factor authentication.

    How can I make Apple sent an official request for Andorra in the list of international codes?

    Thank you.

    Return of goods - Apple

  • My safari has locked up with a request for verification of the property query.  What can be done to fix this?

    My safari has locked up with a request for verification of the property query.  What can be done to fix this?

    This is the shit that came.

    Force Quit Safari (cmd-option-esc) then restart Safari by holding down the SHIFT key.

    Sorry, wrong forum... question thought it was an OS X. In any case don't give them any info.

  • IBM think centre @ request for initialization of the system user password and a genius set the bios to lock keyboard can it is bypassed and how?

    Original title: IBM think centre @ start request.

    IBM think centre @ request for initialization of the system user password and a genius set the bios to lock keyboard can it is bypassed and how?

    Hi brandon1980,

    I recommend you contact your computer manufacturer for assistance. The manufacturer would be able to give details about the BIOS (Basic Input Output System) and find out if this feature can be disabled.

    Hope the helps of information.

  • How to separate requests for authentication to GBA 4.2

    Hello

    I have a 4.2 ACS for AAA. Right now I use this server to authenticate users this connection for all my devices cisco (routers, switches, ASAs, APs) and also to authenticate users for remote access VPN to ASA.

    The problem I have is that VPN users residing on another group in ACS are able to authenticate to log to manage network devices and it is a problem of security. I need the vpn users only being able to authenticate to the vpn and not be able to authenticate to connect to network devices.

    Any ideas? is it possible to separate requests for access radius and vpn connection?

    Hi Fernando,

    Yes it is possible to restrict your users only VPN to VPN - ASA. If you want that they do not have telnet/ssh/http access with other devices in the network, then you can go for NAR (network access restriction).

    The only thing you need to know what we are calling-station-id. I think it's an ip address. You can check this activity and reports > past authentication for VPN users.

    Here are the steps:

    GBA > go to the VPN group > Edit > search for NAR > under Ip based NAR > set the action to "DECLINED" > select the devices (routers/switches) you want to deny access to > put * for the port field and address > click on submit + restart.

    Doing this will of users can connect through vpn and unable to do ssh and telnet.

    I have attached the screenshot of the same thing (I did for 6509 switch)

    HTH

    JK

    Please evaluate the useful messages-

  • local group can be used for authentication to the remote user?

    Hello

    Can I use local user databease created the PIX as authentication method for remote access VPN clients. When tried to make using PDM following error has been shown

    "Local group is not taken care of for the user remote auth.of a client remote easy vpn." Please select another group of servers auth... »

    Snapshot of PIX is attached.

    This cliché is: suite menu.

    ---> VPN configuration---> remote access--> vpn cisco client---> select the Group---> edit--> Advanced-->

    Is there is another way, what can I use the local PIX basic data itself to authenticate users from the outside world of the VPN client.

    no doubt this pix is able to authenticate the user remote vpn against its local database.

    Here are the code examples:

    access-list 101 permit ip 192.168.1.0 255.255.255.0 10.1.1.0 255.255.255.0

    access-list 120 allow ip 192.168.1.0 255.255.255.0 10.1.1.0 255.255.255.0

    (Inside) NAT 0-list of access 101

    part of pre authentication ISAKMP policy 10

    ISAKMP policy 10 3des encryption

    ISAKMP policy 10 md5 hash

    10 2 ISAKMP policy group

    ISAKMP life duration strategy 10 86400

    ISAKMP identity address

    ISAKMP nat-traversal 20

    Crypto ipsec transform-set esp-3des esp-md5-hmac vpnset

    IP local pool ippool 10.1.1.11 - 10.1.1.21

    vpngroup address ippool vpnclient-pool

    vpngroup idle 1800 vpnclient-time

    vpngroup vpnclient-Server dns 139.130.4.4

    vpngroup vpnclient password cisco456

    vpngroup split tunnel 120 vpnclient

    Crypto-map dynamic dynmap 10 transform-set vpnset

    map remote_vpn 20-isakmp ipsec crypto dynamic dynmap

    Cisco username password cisco123

    AAA-server local LOCAL Protocol

    client authentication card crypto remote_vpn LOCAL

    client configuration address card crypto remote_vpn throw

    client configuration address card crypto remote_vpn answer

  • The use of tables of database for authentication in the ADF

    Hello

    I need to use my user table in the database for authentication in ADF (adf 11.1.2).

    I have 3 categories: agent admin and user is unique, each has its own page, logging, the application checks the type of user and directs its jsf task or the page of the jsf page flow.

    I have a user with the type attribute table

    HOW CAN I MAKE THIS PRAYER.

    Hello

    See links below.

    Whatever Fusion Middleware: Tables database user to implement authentication in the ADF

    Java / Oracle SOA blog: the use of tables of database as in WebLogic authentication provider

  • How to make a request for Validation on the field of comments in BPM Worklist task details Page

    Hello
    I am newbie to SOA 11 g.

    I use SOA 11 g and Jdev 11.1.1.3 for development. I created a human with two results (APPROVE, REJECT) and task able to display the page the task details in the BPM list. I have the comments of default section that comes by 'Auto generation of ADF Taskflow' in the Task Details page. This comments section will display the comments of several users who have access to the task. I want to add validation for the field of comments as below-

    (1) to DISMISS the action, we must check whether or not the APPROVER had provided the reason for REJECTION in the comments field. If this isn't the case, we need to display a popup asking him to provide observations of REJECTION.
    (2) on the action to APPROVE, no need to check for comments, so no validation is necessary.

    Can someone give me some ideas how it is possible.

    Thank you
    Udaya Neeliahgari

    Hello
    Try the following...
    In the composite open y'r process bpel... and then to expand the human task... you will notice a task entitled just before the initiateTask run the following two copy operation in the task of AssignTaskAttributes within the scope of the human task.

    IMP Note: The variable is the variable initiateTaskInput of the human task field. Don't assign not on on the global variable

    1 assign a string value "REJECT" in the expression (assuming that you do so that the result of REJECTION) and assign it to the variable

    /TaskService:initiateTask / task: task / mission: systemAttributes / task: preActionUserSteps / task: preActionUserStep / task: results

    2 assign the string value "PROVIDE_COMMENTS" in the expression and assign it to the variable

    /TaskService:initiateTask / task: task / mission: systemAttributes / task: preActionUserSteps / task: preActionUserStep / task: userStep

    view the .bpel file source y'r and make sure that you see something like the following:




    Query = "" / taskservice:initiateTask / task: task / task: systemAttributes / task: preActionUserSteps / task: preActionUserStep / task: result "/ >"




    Query = "" / taskservice:initiateTask / task: task / task: systemAttributes / task: preActionUserSteps / task: preActionUserStep / task: userStep "/ >"

    Just deploy the app... and when you try to dismiss... it should appear the message.

    concerning
    Raja

  • What could change the ID of the computer used for licenses in the License Manager OR?

    the site of our client we initially implemented our software that uses the Vision Run-Time and Acquisition of Vision software.    We bought a license for the PC and it has been installed. He has headed since July.   But today the customer started getting errors requesting the license. using the License Manager, OR we see "status: activated for another computer.

    look no further, we now see a different ID 'computer' code I have original screenshots when I applied the license originally so I know that the ID of the computer was not a typing error.

    The customer says person only has swapped the PC, but is currently looking to see if any work has been done.

    Someone at - it expirenced this before?

    Quote: Your computer ID is based on the MAC address of your Ethernet card. In some cases, your computer ID is based on the disk volume serial number.

    Well, my computer has literally just sat there week and this morning it me that LabVIEW was not enabled.  I do not think that the MAC address or the disc has changed in that time.  But who knows.  Our IT is pretty bad.

  • Request for each thumbnail EXR bridge if transparency should be used as transparent or alpha! WTF?

    Since the last update, the bridge behaves like photoshop with OpenExr files: he asks if the alpha should be used as transparency or alpha.

    And this for EACH file in a folder in the Bridge creates thumbnails. You just ruined my workflow with EXRs. Completelly. Imagine a folder with hundreds of animation EXR images. Bridge wants to create thumbnails and wonder hundrets of times how? What did you even think to this? Have you even thought about everything? Why oh why?

    Change this behavior immediately or give me a hack to work around. Please, I beg you!

    Hi Otto.

    We published a new version of Adobe Bridge (CC 2017) on 2 November 2016. The new version of version number is 7.0.0.93. This version is available for installation via the Adobe Creative Cloud application.

    Please try the new version and look for problems you encounter.

    You may need to update the creative cloud app and restart your computer to see the update patch.

    Kind regards

    Gerard

  • Shop for fonts and the extensions Manager WHY is it so difficult?

    I am trying to install the add-on from the shop to the police. I can not yet do a smart search in the 'Adobe modules'... search can't find the FontShop module even if I type the term a few obvious ways.   YOUR RESEARCH NEEDS SPELL CHECK AND FIND * CLOSING MATCHES. There are SO MANY problems of usability in this forum and in the modules Adobe Adobe it's ridiculous. Basic stuff - usability 101.

    But I can directly download the add-on from FonstShop... But it will not install in my Photoshop CC 2015. The problem is 'Adobe Extensions Manager' will not appear Photoshop CC 2015 even if I installed it (via could Creative).

    How do you get the extensions Manager recognize Photoshop CC 2015?

    The short answer, as Stephanie, is that you don't have. It is obsolete. Check out these resources: Adobe Exchange, specifically this one: Adobe Exchange

  • Requests for comment move the cc on another partition?

    Hello everyone,

    I would have liked to move all of the cc to partition applications another.

    At installation, the program allows me at any time to indicate another partition or another disc, on which I would like to install the software.

    4 cc applications take me more than 3 GB on the partition dedicated to the operating system (SSD drive) and lacking space.

    Thanks in advance for any proposal and soon

    Germain Delsart

    Hi, Germain,.

    I think you want to change the installation location of the CC apps.

    Please launch the desktop creative cloud application > click the gear on the top icon right > select preferences > under the creative cloud section, you can specify the installation location.

    Reference: installation directory change request

    Kind regards

    Sheena

  • Request for information on the BAM database

    Hello

    I have a few questions about the BAM database:

    1. when the entry is created in the BAM database, it's always an "Add" operation or it can be 'Update' operation also? (A new record is entered each time or sometimes old records are updated?).
    2. What is the difference between rucheDans, origActivityIn and waitActivityIn columns of the BAM_WORKLOAD table? Can someone provide a simple example to make a difference?

    Thanks in advance!

    Jean René

    1. the BAM database receives no updates and inserts. New lines are added when occur snapshots. The inside of the engine there is a setting (usually 24 hours) to the BAM database where the outdated information (lines) are removed from the database.

    2. the "rucheDans" represents the instance number of the current instance in the process.

    The "origActivityIn" column is almost always '1 '. When he is not this, then it means that the work item instance is sitting inside a subflow activity. The number in this column represents the instance number for the work item instance inside the begotten child sub-process.

    Similarly, the "waitActivityIn" is almost always '1 '. I have never seen that everything except "1". It is not documented anywhere I know, but I think that this instance of the child process respresents who number a Message wait activity waits for a notification. This can happen when a child process is created in a parent process asynchrously using process creation activity. The child can then in turn send a notification to the parent using an activity to send the Message.

    Dan

  • request for information on the database adapter...

    Hello
    I have a scenario where I have to interview a few tables that is not related to each other and I get different queries for each table. I tried to create a single DB adapter and imported from all the tables in it. But I faced two places where I was asked to define a root table and also to set up a select query.

    As a result of reagrding doubts, I have this:

    1. do I need to need to create different DB adapter for each table?

    2. What is the significance of the db table root?

    Concerning
    Lokesh

    Yes, you must create 3 links of different partner using the DB adapter.

    In theory Yes, you would create a new partner link using the DB adapter for each table that is not bound. If you want to select PO_HEADERS_ALL and PO_LINES, this can be done in a single call because they are related.

    This review is based on the fact that you select batch data, no data rows. If you receive 1 row of several unrelated table, this could be done via a custome procedure / package. I don't want to lead you down the wrong path, so I need to learn more about your use case. In most senerios in Oracle apps you call API / packages.

    If you could provide more information about your use case, I'll try to offer the best advice

    see you soon
    James

Maybe you are looking for

  • Problems with my Skype account.

    Dear users of the Skype forum,I currently have some problems with my Skype account.My little brother connected through another computer on Skype, but it's also on my Skype, the message I get: "Do even more when you're on Skype" caught my attention.No

  • ITunes on the iphone (iOS 9.2) 6s move then follow

    When I am listening to music on my iPhone - iTunes continues to play the same song again and again. It does not move to the next track, or it back to another track. This happens for albums, playlists and playing the entire library. Shuffle does nothi

  • MFP HP 1536 - NO DRIVER INSTALLED SCANNER

    HP doctor says that no driver is installed to scan; to install link brings me to e-print, (HP ePrint 2013-08-20, Version 4.5.52.12202, 56,02 M) which is the one I used for installation; I can't find the drivers to install the scanner, can anyone help

  • Iconia-W-4 restarts randomly

    Well, as the topic says the tandomly just Tablet restarts itself. I barely got enough long to update Acer drivers, uninstall factory apps I'll never use and update of windows. All this has helped stabilize some, now it testarts every 20-30 minutes in

  • Volume icon from the taskbar notification

    After that the latest version of windows update, my volume icon disappeared from my notification area of the taskbar.  I went to the right area to add back and it does not check the box for the volume icon.  How can I correct this problem and put the