<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP address in live authentication after vlan change in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205972#M126383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you check the accounting msg? if you config periodic accounting, you should see updated ip in accounting msg.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Jun 2013 15:19:32 GMT</pubDate>
    <dc:creator>Shaoqin Li</dc:creator>
    <dc:date>2013-06-24T15:19:32Z</dc:date>
    <item>
      <title>IP address in ISE live authentication after vlan change</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205971#M126340</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;on ISE live authentication dashboard we can see IP address of the client (known from FRAMED-IP-ADDRESS).&lt;/P&gt;&lt;P&gt;But what about vlan change and the situation when client gets new IP address after relocation to different vlan.&lt;/P&gt;&lt;P&gt;Live logs shows only the first IP address - client mapping (from the guest vlan), after authorization new vlan and dACL is assigned but logs don't include new IP address.&lt;/P&gt;&lt;P&gt;session ID is the same all the time.&lt;/P&gt;&lt;P&gt;so maybe ip helper or other trick?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205971#M126340</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2019-03-11T03:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: IP address in live authentication after vlan change</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205972#M126383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you check the accounting msg? if you config periodic accounting, you should see updated ip in accounting msg.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 15:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205972#M126383</guid>
      <dc:creator>Shaoqin Li</dc:creator>
      <dc:date>2013-06-24T15:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: IP address in live authentication after vlan change</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205973#M126463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx for reply. &lt;/P&gt;&lt;P&gt;I added "aaa accounting update newinfo" and I'll see tommorow how it works with anyconnect and 802.1x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meanwhile I think I must clarify what I meant &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not all logs have IP address present in live authentication (this is MAB for test only) &lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/0/1/143101-ScreenShot477.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;the situation with 802.1x and anyconnect is a bit better cause there are IP addresses but only from the first dhcp address assignment (authentication open with default ACL). Then if the policy changes vlan and the client gets new IP address from different scope we have wrong information in this log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but getting back to our MAB...&lt;/P&gt;&lt;P&gt;details of this entry looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/0/1/143103-ScreenShot474.jpg" class="jive-image" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/0/1/143104-ScreenShot475.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so this is probably the reason that no IP address is visible it was too soon for MAB to get this info and send it as framed IP address (according to this config command "radius-server attribute 8 include-in-access-req")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nevertheless clicking the accounting details (from the 2nd screenshot)&lt;/P&gt;&lt;P&gt;we see that this information is present &lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/0/1/143105-ScreenShot476.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so my first question is on which stage this column is fulfilled? only when "FRAMED-IP-ADDRESS" is send in radius-request? or from accounting? &lt;/P&gt;&lt;P&gt;maybe ISE should dynamically modify this record after each accounting newinfo message? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 16:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-address-in-ise-live-authentication-after-vlan-change/m-p/2205973#M126463</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2013-06-24T16:36:45Z</dc:date>
    </item>
  </channel>
</rss>

