Palo Alto and Cisco ISE packet issues

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto and Cisco ISE packet issues

L1 Bithead

Hi 

 

ive got an issue when a user connects on our VPN using the global protect client the connection will take nearly a minute to connect and in the backgroup create several failures on our Cisco ISE RADIUS server, before finally let the user connect.

 

I have got calls open with both Palo Alto and Cisco support but i kinda feel like im not getting anywhere, so i thought i would turn to the forums! Cisco seem to think the Palo Alto FW is not sending the packets as per RFC standards so therefore the Ciso ISE server is dropping the packets. 

 

Throughout the ongoing support calls we have done packet captures and we can see that ISE is sending state and class attributes in access accept packet but state attribute (session identification attributes) is missing in the authorize-only request packet from the PaloAlto firewall hence ISE is not able to process the request.

 

If you have a Palo Alto FW and a Cisco ISE RADIUS server do get these issues?

 

Cheers

2 REPLIES 2

Cyber Elite
Cyber Elite

@Carpetright,

Just wondering if you've followed this configuration for using the Cisco ISE with a Palo Alto. You need to include a few VSAs to get everything working correctly. 

 

 

 

https://live.paloaltonetworks.com/t5/Tutorials/Configure-Cisco-ISE-with-RADIUS-for-Palo-Alto-Network...

Yeah it was Cisco that mentioned about the VSA which have been changed but still not difference

  • 2391 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!