Hello
Firmware: 25.13
Cisco ISE: 2.3.0.298
just testing the radius authentication from the dashboard to our Cisco ISE radius
Total APs: | 9 |
APs passed: | 4 |
APs failed: | 5 |
APs unreachable: | 0 |
these are same subnet, same site, same everything
each time I test I receive different results and sometime I receive an error
RADIUS attributes used:
Airespace-ACL-Name:HS-Laptop
RADIUS attributes unused:
User-Name: *domain\user*
State:ReauthSession:0a2d000fKS4uutHjQp5FArmB2ZstcLZ63zRmIXdtubIA7tDgTB4
I managed to find a good site explaining this a long time ago but I am unable to find it now so looking for help with a solution of explanation
our old Cisco ISE box (decommissioned) used to always be 100% but as I am not a Cisco ISE person I unable to to even work out the difference
and cisco forums are a mess so hoping here someone can point me in the correct direction
Working AP ISE output:
Authentication Details
Source Timestamp | 2019-09-05 09:42:20.332 |
Received Timestamp | 2019-09-05 09:42:20.333 |
Policy Server | servername |
Event | 5200 Authentication succeeded |
Username | domain\user |
Endpoint Id | 00:00:00:00:00:02 |
Calling Station Id | 00-00-00-00-00-02 |
Authentication Identity Store | HS_AD |
Authentication Method | MSCHAPV2 |
Authentication Protocol | PEAP (EAP-MSCHAPv2) |
Network Device | Meraki_AP |
Device Type | All Device Types#Meraki_AP |
Location | All Locations |
NAS IPv4 Address | 10.45.99.12 |
NAS Port Type | Wireless - IEEE 802.11 |
Authorization Profile | HS_Laptop_Permit_All |
Response Time | 19 milliseconds |
failing AP ISE output
Authentication Details
Source Timestamp | 2019-09-05 09:42:21.899 |
Received Timestamp | 2019-09-05 09:42:21.9 |
Policy Server | servername |
Event | 5400 Authentication failed |
Failure Reason | 12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist |
Resolution | Verify known NAD issues and published bugs. Verify NAD configuration. Turn debug log on DEBUG level to troubleshoot the problem. |
Root cause | Session was not found on this PSN. Possible unexpected NAD behavior. Session belongs to this PSN according to hostname but may has already been reaped by timeout. This packet arrived too late. |
Username | domain\user |
Endpoint Id | 00:00:00:00:00:02 |
Calling Station Id | 00-00-00-00-00-02 |
Network Device | Meraki_AP |
Device Type | All Device Types#Meraki_AP |
Location | All Locations |
NAS IPv4 Address | 10.45.99.13 |
NAS Port Type | Wireless - IEEE 802.11 |
Response Time | 4 milliseconds |
any help on this is greatly appreciated