<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 GUI shows an endpoint as &amp;quot;Default&amp;quot; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020415#M454251</link>
    <description>&lt;P&gt;Are you sure it says that you are hitting the "Default" authorization policy?&amp;nbsp; Or is it the authentication policy?&amp;nbsp; Or policy set?&amp;nbsp; All of those would have a "Default".&amp;nbsp; Double check that and post a screenshot of your Live Log entry showing that and also your policy.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 18:18:41 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2020-01-29T18:18:41Z</dc:date>
    <item>
      <title>ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020381#M454249</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We run ISE 2.3 and I'm seeing a weird anomaly where the switch sees the endpoint as hitting the proper ACL &amp;amp; policy but the GUI shows it as hitting the "Default" AuthZ policy.&amp;nbsp; It matches the endpoint profile,&amp;nbsp;AD integration works and sees the user ID and proper AD computer name.&amp;nbsp; IP address gets assigned, everything looks good.&amp;nbsp; The same switchport sees the phone as well since we use the phone's interface to run the PC.&amp;nbsp; I have 34 examples of this across multiple locations so I'm hoping it's all related to one core issue.&amp;nbsp; We are in Monitor Mode so authentication open is being used on the port level config and the users can work normally.&amp;nbsp; Is this a bug in the version of ISE or the IOS version&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="left-hand-col"&gt;&lt;DIV&gt;Version&amp;nbsp;2.3.0.298&lt;/DIV&gt;&lt;DIV&gt;Installed Patches 5&lt;/DIV&gt;&lt;DIV&gt;Product Identifier (PID)&amp;nbsp;ISE-VM-K9&lt;/DIV&gt;&lt;DIV&gt;Version Identifier (VID)&amp;nbsp;V01&lt;/DIV&gt;&lt;DIV&gt;Serial Number (SN)&lt;/DIV&gt;&lt;DIV&gt;ADE-OS Version&amp;nbsp;3.0.3.030&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="right-hand-col"&gt;&lt;DIV&gt;&lt;SPAN&gt;Switch Ports Model SW Version SW Image&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;------ ----- ----- ---------- ----------&lt;BR /&gt;* 1 52 WS-C2960X-48LPS-L 15.2(4)E6 C2960X-UNIVERSALK9-M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 17:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020381#M454249</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2020-01-29T17:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020415#M454251</link>
      <description>&lt;P&gt;Are you sure it says that you are hitting the "Default" authorization policy?&amp;nbsp; Or is it the authentication policy?&amp;nbsp; Or policy set?&amp;nbsp; All of those would have a "Default".&amp;nbsp; Double check that and post a screenshot of your Live Log entry showing that and also your policy.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 18:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020415#M454251</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-01-29T18:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020484#M454254</link>
      <description>&lt;P&gt;Yes, I verified it's the AuthZ policy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 21:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020484#M454254</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2020-01-29T21:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020495#M454256</link>
      <description>&lt;P&gt;That entry shows a failure due to "Rejected per authorization profile" which makes sense since that error fires when no rule is matched and hits default at the end.&amp;nbsp; What is probably happening is that you are seeing failures AND successes for the same endpoint.&amp;nbsp; For example, MAB failing but 802.1x passes which is why the ACL gets applied properly.&amp;nbsp; In your Live Logs, filter on the Endpoint ID and see if there are any successes along with the failures.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 19:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020495#M454256</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-01-29T19:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020560#M454258</link>
      <description>&lt;P&gt;After filtering on the Endpoint ID here is what I get.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Time&lt;/TD&gt;&lt;TD&gt;Status&lt;/TD&gt;&lt;TD&gt;Repeat Count&lt;/TD&gt;&lt;TD&gt;IP Address&lt;/TD&gt;&lt;TD&gt;Network Device&lt;/TD&gt;&lt;TD&gt;Device Port&lt;/TD&gt;&lt;TD&gt;Identity&lt;/TD&gt;&lt;TD&gt;Endpoint ID&lt;/TD&gt;&lt;TD&gt;Endpoint Profile&lt;/TD&gt;&lt;TD&gt;Authentication Policy&lt;/TD&gt;&lt;TD&gt;Authorization Policy&lt;/TD&gt;&lt;TD&gt;Authorization Profiles&lt;/TD&gt;&lt;TD&gt;Identity Group&lt;/TD&gt;&lt;TD&gt;Posture Status&lt;/TD&gt;&lt;TD&gt;Server&lt;/TD&gt;&lt;TD&gt;Mdm Server Name&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;16:53.9&lt;/TD&gt;&lt;TD&gt;Session&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;10.60.48.60&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;GigabitEthernet1/0/21&lt;/TD&gt;&lt;TD&gt;host/xxx.com&lt;/TD&gt;&lt;TD&gt;14:B3:1F:04:45:D7&lt;/TD&gt;&lt;TD&gt;Windows10-Workstation&lt;/TD&gt;&lt;TD&gt;Wired &amp;gt;&amp;gt; Default&lt;/TD&gt;&lt;TD&gt;Wired &amp;gt;&amp;gt; ISE Domain Computer&lt;/TD&gt;&lt;TD&gt;ISE_MACHINES&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;16:53.0&lt;/TD&gt;&lt;TD&gt;Auth Passed&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;10.60.48.60&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;GigabitEthernet1/0/21&lt;/TD&gt;&lt;TD&gt;host/xxx.com&lt;/TD&gt;&lt;TD&gt;14:B3:1F:04:45:D7&lt;/TD&gt;&lt;TD&gt;Windows10-Workstation&lt;/TD&gt;&lt;TD&gt;Wired &amp;gt;&amp;gt; Default&lt;/TD&gt;&lt;TD&gt;Wired &amp;gt;&amp;gt; ISE Domain Computer&lt;/TD&gt;&lt;TD&gt;ISE_MACHINES&lt;/TD&gt;&lt;TD&gt;Workstation&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;CiscoISEVM01&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 29 Jan 2020 21:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020560#M454258</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2020-01-29T21:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020606#M454260</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773"&gt;@Colby LeMaire&lt;/a&gt; wrote:&lt;/P&gt;
&lt;P&gt;"What is probably happening is that you are seeing failures AND successes for the same endpoint. For example, MAB failing but 802.1x passes which is why the ACL gets applied properly."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Colby is correct. You can see in the Live Log screenshot that the Authentication Protocol is 'Lookup', which means that is a MAB session.&lt;/P&gt;
&lt;P&gt;If your switchport configuration is using Flex Auth (authentication order mab dot1x) or a similar policy map order for IBNS 2.0, it is expected behavior to see a MAB session followed by a dot1x session for the same MAC address in the Live Logs. The dot1x auth process is slower than MAB, so the MAB auth session will complete first and hit the Default rule (unless you have an AuthZ policy matching on MAB). When the dot1x session completes, it will override the MAB session for the same MAC address (if you have 'authentication priority dot1x mab') and you will see that updated session information in the Live Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 21:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020606#M454260</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-01-29T21:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020608#M454261</link>
      <description>&lt;P&gt;Here's what's weird... the switch sees the workstation as successfully identified by ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------------------------------------&lt;BR /&gt;Interface: GigabitEthernet1/0/21&lt;BR /&gt;MAC Address: 14b3.1f04.45d7&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address: 10.60.48.60&lt;BR /&gt;User-Name: host/xxx.com&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-auth&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Common Session ID: 00000000000010EE1DD30EC9&lt;BR /&gt;Acct Session ID: 0x00003E9C&lt;BR /&gt;Handle: 0x2900003E&lt;BR /&gt;Current Policy: POLICY_Gi1/0/21&lt;/P&gt;&lt;P&gt;Local Policies:&lt;BR /&gt;Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;ACS ACL: xACSACLx-&lt;FONT color="#0000FF"&gt;IP-MACHINE_ACL&lt;/FONT&gt;-5df3ede4&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;mab Stopped&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;dot1x Authc Success&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 22:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020608#M454261</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2020-01-29T22:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 GUI shows an endpoint as "Default"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020617#M454262</link>
      <description>&lt;P&gt;That's correct. With Flex Auth, the switchport will stop the MAB process when it receives and EAPOL from the endpoint. The switch will show 'dot1x AuthC Success' after the dot1x process completes.&lt;/P&gt;
&lt;P&gt;If you quickly look at the switchport auth session (or access-session, for IBNS 2.0) when the endpoint is first connected, you will see the 'MAB Auth Success' first while the dot1x process is in progress.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 22:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-gui-shows-an-endpoint-as-quot-default-quot/m-p/4020617#M454262</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-01-29T22:18:03Z</dc:date>
    </item>
  </channel>
</rss>

