<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2: Accounting Interim Update Reports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3712093#M252</link>
    <description>&lt;P&gt;Interesting that my observations on Accounting reports is somewhat different. I haven't had the time to investigate in detail the packets to see what AV pairs are present. Observing the reports that I get, I have observed that MAB interim accounting updates are reported and dot1x are not. These are coming from a 3850 switch on 16.9.1. device tracking is enabled. We have also in the test environment a 3750x in which case I don't get any reporting from it. I have not seen the packet capture from that switch. Our ISE environment is 2.3 with patch 4.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 13:21:57 GMT</pubDate>
    <dc:creator>Garry Cross</dc:creator>
    <dc:date>2018-09-24T13:21:57Z</dc:date>
    <item>
      <title>ISE 2.2: Accounting Interim Update Reports</title>
      <link>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3557433#M250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;ISE was not displaying Accounting Interim Update Reports until ISE Version 2.2.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;I upgraded to to ISE version 2.2 and have found that optional RFC 2866 RADIUS Accounting Framed-IP-Address(8) RADIUS Attribute is required for displaying Accounting Interim Update Reports.&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;This observation was found by looking at the collector and report DEBUG logs in detail, I stumbled across a tuple entry, SessionStateContext, consisting of {Cisco-AVPair(1): audit-session-id, Calling-Station-Id(31), Framed-IP-Address(8)}…&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Courier New';"&gt;2017-07-20 13:48:47,966 DEBUG [AcsSyslog store] cisco.mnt.collection.session.SessionStateContext: ACCTStart:Session found due to AuditSessionID&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Courier New';"&gt;2017-07-20 13:48:47,966 DEBUG [AcsSyslog store] cisco.mnt.collection.session.SessionStateContext: ACCTStart:Session found due to CallingStationID&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 1.4em; color: #333333; font-family: Arial, sans-serif; font-size: 14.4px;"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'Courier New';"&gt;2017-07-20 13:48:47,966 DEBUG [AcsSyslog store] cisco.mnt.collection.session.SessionStateContext: ACCTStart:Session found due to FramedIPAddress&lt;/SPAN&gt;&lt;/P&gt;&lt;H4 style="margin-bottom: 1.2em; font-family: Arial, sans-serif; font-weight: 300; color: #333333; font-size: 1.4em;"&gt;&lt;SPAN style="font-size: 12pt; font-family: 'times new roman', times, serif;"&gt;I would like to know if Framed-IP-Address(8) is a required RADIUS attribute in Accounting Interim Update Requests so that ISE will properly display Accounting Interim Update Reports.&lt;/SPAN&gt;&lt;/H4&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 15:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3557433#M250</guid>
      <dc:creator>david.wisnoski</dc:creator>
      <dc:date>2017-07-31T15:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2: Accounting Interim Update Reports</title>
      <link>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3557434#M251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Indeed because of this bug &lt;/P&gt;&lt;P&gt;&lt;A href="https://casto.servizi.rai.it/owa/redir.aspx?C=y48-vf4CdLOp8_DPb3VRXtsM5tbgubbOgcV8y0VNQRESBWurXIrVCA..&amp;amp;URL=https%3a%2f%2fbst.cloudapps.cisco.com%2fbugsearch%2fbug%2fCSCve85449" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve85449&lt;/A&gt;&lt;/P&gt;&lt;P&gt;my ISE 2.3 patch 1 deployment sometimes is not showing interim update in reports .&lt;/P&gt;&lt;P&gt;I did some tests both with and without Framed-IP-Address attribute .&lt;/P&gt;&lt;P&gt;+For a user that has been authenticated with eap interim updates without Framed-Ip-Address are not shown, the ones with Framed-Ip-Adress are shown&lt;/P&gt;&lt;P&gt;+For an end point authenticated with MAB interim-updates are never shown even if contain&amp;nbsp; Framed-Ip-Adress Attribute&lt;/P&gt;&lt;P&gt;+For guest users interim-updates with&amp;nbsp;&amp;nbsp; Framed-Ip-Adress Attribute are shown&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 10:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3557434#M251</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2018-03-15T10:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2: Accounting Interim Update Reports</title>
      <link>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3712093#M252</link>
      <description>&lt;P&gt;Interesting that my observations on Accounting reports is somewhat different. I haven't had the time to investigate in detail the packets to see what AV pairs are present. Observing the reports that I get, I have observed that MAB interim accounting updates are reported and dot1x are not. These are coming from a 3850 switch on 16.9.1. device tracking is enabled. We have also in the test environment a 3750x in which case I don't get any reporting from it. I have not seen the packet capture from that switch. Our ISE environment is 2.3 with patch 4.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 13:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-2-2-accounting-interim-update-reports/m-p/3712093#M252</guid>
      <dc:creator>Garry Cross</dc:creator>
      <dc:date>2018-09-24T13:21:57Z</dc:date>
    </item>
  </channel>
</rss>

