<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Johannes- in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861369#M36873</link>
    <description>&lt;P&gt;Hi Johannes-&lt;/P&gt;
&lt;P&gt;You are correct about the license consumption:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Licenses are counted against concurrent, active sessions. An active session is one for which a RADIUS Accounting Start is received but RADIUS Accounting Stop has not yet been received.&lt;/PRE&gt;
&lt;P&gt;However, in addition to that:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Note Sessions without RADIUS activity are automatically purged from Active Session list every 5 days or if the endpoint is deleted from the system. &lt;/PRE&gt;
&lt;P&gt;This information used to be in the 1.x ISE documentation but for some reason it is not in the 2.x &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the info from 1.2:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_d_man_license.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_d_man_license.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Apr 2016 02:15:01 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2016-04-02T02:15:01Z</dc:date>
    <item>
      <title>ISE license consumption and releasing of licenses [RADIUS]</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861368#M36871</link>
      <description>&lt;P&gt;Hi ISE folks,&lt;/P&gt;
&lt;P&gt;there are a lot of ISE questions issued by me in the last time. And guess what - here's another one.&lt;/P&gt;
&lt;P&gt;I'm asking myself how the ISE license consumption and releasing of licenses actually works. At least I didn't find any good document or post on that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From what I understood, a license (no matter if base, plus, apex whatever) is consumed based on RADIUS accounting messages.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;An endpoint is authenticating and authorized successfully with 802.1X without profiling or posture or whatever (simple). The ISE knows that this endpoint should consume one base license and the base license consumption is increased by one.&lt;/P&gt;
&lt;P&gt;As soon as the client is disconnected from the network the NAD (switch, WLC) sends an accounting stop message to the ISE and the ISE releases the base license again.&lt;/P&gt;
&lt;P&gt;(am I right so far?!)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Assuming I'm right with the example above:&lt;/P&gt;
&lt;P&gt;RADIUS is not let's say really reliable. Regardless that it's using UDP (which is unreliable), RADIUS has an acknowledge mechanism built in (Accouting request / respone). But this mechanism gives up after some retries. Let's just assume a client is disconnected but the RADIUS stop message is not received by the ISE.&lt;/P&gt;
&lt;P&gt;Does the endpoint stay forever in the active session state and therefore consuming a license forever?! (let's assume there is no dot1x reauthentication timer).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Or is there some "idle timeout" mechanism for endpoint licenses?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kind of a side story here:&lt;/P&gt;
&lt;P&gt;I wrote a simple wrapper for the freeradius tool "eapol_test". From a Linux command line single EAP requests (e.g. EAP-TLS) can be issued to a RADIUS server. So the Linux client acts as 802.1X supplicant and authenticator. This is cool to quickly test the availability of the authentication server service.&lt;/P&gt;
&lt;P&gt;My simple wrapper for "eapol_test" does a "EAP" ping to measure convergence time and measure authentications per second in a lab environment. Also the wrapper can change the endpoint MAC for every RADIUS session. When I do this EAP ping in a lab my license count on the ISE is exploding, because eapol_test does not issue RADIUS accounting messages to the ISE &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers Johannes&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861368#M36871</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2019-03-11T06:38:04Z</dc:date>
    </item>
    <item>
      <title>Hi Johannes-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861369#M36873</link>
      <description>&lt;P&gt;Hi Johannes-&lt;/P&gt;
&lt;P&gt;You are correct about the license consumption:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Licenses are counted against concurrent, active sessions. An active session is one for which a RADIUS Accounting Start is received but RADIUS Accounting Stop has not yet been received.&lt;/PRE&gt;
&lt;P&gt;However, in addition to that:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Note Sessions without RADIUS activity are automatically purged from Active Session list every 5 days or if the endpoint is deleted from the system. &lt;/PRE&gt;
&lt;P&gt;This information used to be in the 1.x ISE documentation but for some reason it is not in the 2.x &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the info from 1.2:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_d_man_license.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/installation_guide/ise_ig/ise_app_d_man_license.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2016 02:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861369#M36873</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-02T02:15:01Z</dc:date>
    </item>
    <item>
      <title>Thank you again Neno :D</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861370#M36875</link>
      <description>&lt;P&gt;Thank you again Neno &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 09:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861370#M36875</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2016-04-08T09:29:46Z</dc:date>
    </item>
    <item>
      <title>Most welcome! :)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861371#M36878</link>
      <description>&lt;P&gt;Most welcome! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Neno&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 15:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861371#M36878</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-08T15:30:06Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861372#M36879</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am facing same problem, for ISE 2.0 license consumption. Can we reduce active session list from 5 days to 1 day.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 11:00:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861372#M36879</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-06-29T11:00:08Z</dc:date>
    </item>
    <item>
      <title>Hi Kamlesh-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861373#M36880</link>
      <description>&lt;P&gt;Hi Kamlesh-&lt;/P&gt;
&lt;P&gt;Unfortunately, there isn't such setting in ISE. However, keep in mind that licensing in ISE (as many other Cisco products) is on the honor system. Thus, even if you exceed the licenses, the system will continue to work and and allow additional users and hosts on the network. You will only get warning messages that you are exceeding your licenses.&lt;/P&gt;
&lt;P&gt;With that being said, make sure that your Network Access Devices are configured correctly for 802.1x. More specifically, make sure that Accounting is configured and working properly as that is what notifies ISE when a device/user logs off the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If all configs are good and you are indeed close to your license limits then you should really purchase additional licenses &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 06:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861373#M36880</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-06-30T06:57:53Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno


Kamlesh</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861374#M36881</link>
      <description>&lt;P&gt;Thanks Neno&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 11:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-license-consumption-and-releasing-of-licenses-radius/m-p/2861374#M36881</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-07-08T11:57:57Z</dc:date>
    </item>
  </channel>
</rss>

