Phase 6: Verification & Ops
A successful deployment is only as good as your ability to verify it and troubleshoot it when things go wrong.
Testing Connectivity
Always verify your configurations using a systematic approach.
1. Testing MAB
- Action: Connect a known "dumb" device (e.g., printer) to the port.
- Success Criteria: The device receives the correct VLAN and the ISE Live Logs show a successful MAB authentication.
2. Testing 802.1X (DOT1X)
- Action: Connect a managed laptop with a valid certificate.
- Success Criteria: The laptop successfully completes the EAP-TLS handshake, and ISE grants the expected Authorization Profile.
Validating Certificate Trust
If authentication fails, certificate issues are often the culprit.
- Check the Chain: Ensure the device presenting the certificate can reach the Root/Intermediate CA, and that ISE has the same Root/Intermediate CA in its Trusted Certificates store.
- Check Expiration: Verify that neither the device certificate nor the ISE system certificates have expired.
- Check the CN/SAN: Ensure the Subject Name or Subject Alternative Name in the certificate matches what your Certificate Authentication Profile (CAP) is looking for.
Troubleshooting Posture Compliance
If a device is being denied access due to posture:
- Check the Agent Logs: The Cisco Secure Client/AnyConnect logs on the endpoint are the first place to look for specific policy failures (e.g., "Antivirus out of date").
- Review ISE Live Logs: Look for the "Posture" status in the ISE RADIUS live logs. It will often tell you which posture policy failed.
- Verify Remediation: Ensure the device can actually reach the remediation resources (e.g., Windows Update servers) required to fix the non-compliance.
Log Analysis for Beginners
ISE provides a wealth of information in its logs. Focus on these areas:
- Live Logs (Operations > RADIUS > Live Logs): The most important tool for real-time troubleshooting. It shows every authentication attempt, the results, and the reason for any failures.
- TCP Dump (via CLI): For advanced troubleshooting, use the ISE CLI to capture packet traces to see exactly what is happening during the RADIUS/TLS handshake.
- System Logs: Useful for tracking appliance-level issues, such as service restarts or database errors.
Pro-Tip: When looking at Live Logs, pay close attention to the "Details" column. It often contains the exact error message (e.g., "Certificate expired" or "User not found") that will save you hours of guesswork.