<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic endpoint Session ID does not contain NAS address but only zeros in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885496#M36308</link>
    <description>&lt;P&gt;I cannot tell if there is any impact, but I have noticed that the session IDs for my endpoints only have 0's at the beginning where the guide says they should be the NAS hex version of its IP address.&amp;nbsp; Am I missing something in my setup that would omit this from being added into the session-id?&lt;/P&gt;
&lt;P&gt;Thanks for any guidance that can be provided.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;sh auth sess int gi2/27 det&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface:&amp;nbsp; GigabitEthernet2/27&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 2c59.e5bb.7908&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; IPv6 Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv4 Address:&amp;nbsp; 10.203.169.133&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; xyxxyxll&amp;lt;--my loginid&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authorized&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 000000000000210300449BA4&amp;nbsp; &amp;lt;-- Leading 0's where NAS address should be???&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00004995&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xA3000B9C&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Policy:&amp;nbsp; POLICY_Gi2/27&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:44:50 GMT</pubDate>
    <dc:creator>ssschunk1</dc:creator>
    <dc:date>2019-03-11T06:44:50Z</dc:date>
    <item>
      <title>endpoint Session ID does not contain NAS address but only zeros</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885496#M36308</link>
      <description>&lt;P&gt;I cannot tell if there is any impact, but I have noticed that the session IDs for my endpoints only have 0's at the beginning where the guide says they should be the NAS hex version of its IP address.&amp;nbsp; Am I missing something in my setup that would omit this from being added into the session-id?&lt;/P&gt;
&lt;P&gt;Thanks for any guidance that can be provided.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;sh auth sess int gi2/27 det&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interface:&amp;nbsp; GigabitEthernet2/27&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 2c59.e5bb.7908&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; IPv6 Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPv4 Address:&amp;nbsp; 10.203.169.133&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; xyxxyxll&amp;lt;--my loginid&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Status:&amp;nbsp; Authorized&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 000000000000210300449BA4&amp;nbsp; &amp;lt;-- Leading 0's where NAS address should be???&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x00004995&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0xA3000B9C&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Policy:&amp;nbsp; POLICY_Gi2/27&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:44:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885496#M36308</guid>
      <dc:creator>ssschunk1</dc:creator>
      <dc:date>2019-03-11T06:44:50Z</dc:date>
    </item>
    <item>
      <title>Hard to say without seeing</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885497#M36311</link>
      <description>&lt;P&gt;Hard to say without seeing your switch config. Do you have&amp;nbsp;&lt;STRONG&gt;aaa session-id common&lt;/STRONG&gt; configured?&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2016 01:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885497#M36311</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-05-07T01:16:12Z</dc:date>
    </item>
    <item>
      <title>The short answer is: yes, aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885498#M36313</link>
      <description>&lt;P&gt;The short answer is: yes, aaa session-id common is in the config.&amp;nbsp; below is the complete aaa config&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server radius ISE-Prod&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authentication dot1x default group ISE-Prod&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;BR /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;BR /&gt;aaa authorization network default group ISE-Prod &lt;BR /&gt;aaa accounting dot1x default start-stop group ISE-Prod&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;aaa accounting network default start-stop group tacacs+&lt;BR /&gt;aaa accounting connection default start-stop group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Sat, 07 May 2016 02:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885498#M36313</guid>
      <dc:creator>ssschunk1</dc:creator>
      <dc:date>2016-05-07T02:52:22Z</dc:date>
    </item>
    <item>
      <title>When you said, 'Do you have</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885499#M36315</link>
      <description>&lt;P&gt;When you said, 'Do you have&amp;nbsp;&lt;STRONG&gt;aaa session-id common&lt;/STRONG&gt; configured?'&lt;/P&gt;
&lt;P&gt;Did you mean this command in the config?&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;Is there a radius attribute that I should add to get the info added into the Session ID?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have it in the config, so I'm assuming there is a radius attribute missing?&amp;nbsp; I have these already:&lt;/P&gt;
&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;/P&gt;
&lt;P&gt;I read about this one: but do not see it in ISE docs as needed:&lt;/P&gt;
&lt;P&gt;radius-server attribute 44 include-in-access-req &amp;lt;-- cant tell if it does anything ...doesn't change the session ID .&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 14:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-session-id-does-not-contain-nas-address-but-only-zeros/m-p/2885499#M36315</guid>
      <dc:creator>ssschunk1</dc:creator>
      <dc:date>2016-05-25T14:56:18Z</dc:date>
    </item>
  </channel>
</rss>

