...
ACL redirect configuration pushed from DNAC - switch couldn't update it in all the databases. below error message seen on switch : 068080: Aug 26 201909:54:47.285 UTC: %RBM-3-RBM_ERR: No binding table for tableid 0x7 af 1 -Process= "RBM CORE", ipl= 0, pid= 515 068081: Aug 26 201909:54:47.285 UTC: %RBM-3-RBM_ERR: No binding table for prefix 10.252.224.37/32af 1 tableid 7 idb 0x0 -Process= "RBM CORE", ipl= 0, pid= 515 068082: Aug 26 201909:54:47.285 UTC: %RBM-3-RBM_ERR: IP to SGT binding request 0x10000DDE failed with status 3 -Process= "RBM CORE", ipl= 0, pid= 515 068083: Aug 26 201909:54:47.272 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT. 068084: Aug 26 201909:54:47.276 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT.
customer running with IOS 16.9.3. Issue noticed in customer setup. - Posture failing for some of the Switches for new deployment - Checked on ISE, could see authentication success and redirect URL been pushed from ISE. - Facing issue when ACL POSTURE_REDIRECT pushed from DNAC and switch unable to indentify it. [2'sh Interface; hddress; r dir: WS_OP sess.ons de n GioabitEthemet2/O/10 details 0023 _ '"O _ 23ac] - Checked on the Switch, could see below error during the Failure 068083: Aug 26 201909:54:47.272 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT. 068084: Aug 26 201909:54:47.276 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT. - Removed the ACL POSTURE_REDIRECT from switch which was pushed using DNAC, reconfigured it again manually and Posture was successful for all the Client on the switch. -When we pushed this ACL from DNAC - seems like switch can't update the same in all the databases - Issue is intermittent and resloved after remove it manually and re-configure manually on switch. - Noticed same mac address having DHCP ip issue for which ACL redirect failure message on switch. - Open new bug after discuss with Sandesh Annegowda (sannegow).
- Issue is intermittent and everytime resloved after remove it manually and re-configure manually on switch
- Facing issue when ACL POSTURE_REDIRECT pushed from DNAC and switch unable to indentify it. [2'sh Interface; hddress; r dir: WS_OP sess.ons de n GioabitEthemet2/O/10 details 0023 _ '"O _ 23ac] - Checked on the Switch, could see below error during the Failure 068083: Aug 26 201909:54:47.272 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT. 068084: Aug 26 201909:54:47.276 UTC: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (0023.247e.5b91) on Interface GigabitEthernet1/0/3 AuditSessionID EEEBEC0A000077EDCD1FE915. Failure Reason: Redirect ACL Failure. Failed attribute name POSTURE_REDIRECT. - Removed the ACL POSTURE_REDIRECT from switch which was pushed using DNAC, reconfigured it again manually and Posture was successful for all the Client on the switch. -When we pushed this ACL from DNAC - seems like switch can't update the same in all the databases - Issue is intermittent and resloved after remove it manually and re-configure manually on switch. - Noticed same mac address having DHCP ip issue for which ACL redirect failure message on switch. - Open new bug after discussed with Sandesh Annegowda (sannegow).