<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is username &amp;quot;dummy&amp;quot; exist by default in ISE used when testing &amp;quot;automate-tester username dummy probe-on&amp;quot;? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3947387#M456390</link>
    <description>&lt;P&gt;By default ISE will not disclose invalid usernames in the RADIUS logs.&amp;nbsp; You can turn that annoying feature off in the RADIUS settings in ISE.&amp;nbsp; As Damien said ISE can reject the authentication and the switch won't care as long as it is getting a response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I usually setup a policy set for the switch keep alives as I don't like not handling the request properly.&amp;nbsp; I set the authentication to internal user and set the user not found to Continue.&amp;nbsp; Then I put in an authorization rule to allow the access with a deny all DACL.&amp;nbsp; Once I see the successful hits in the RADIUS logs I turn on suppression for the User ID so the switch probes aren't filling up my logs.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2019 14:38:00 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2019-10-24T14:38:00Z</dc:date>
    <item>
      <title>Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942102#M456383</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the password for this CLI "automate-tester username dummy probe-on" needed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius server ise&lt;/P&gt;&lt;P&gt;automate-tester username dummy probe-on&lt;/P&gt;&lt;P&gt;key testise&lt;/P&gt;&lt;P&gt;Is "key testise" related to&amp;nbsp;automate-tester username dummy probe-on?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 01:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942102#M456383</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-10-17T01:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942132#M456386</link>
      <description>"dummy" in the "automate-tester username dummy probe-on" command is an administrator defined username, dummy can be replaced with anything.  The user does not need to exist anywhere, the switch is perfectly fine with ISE sending a radius-reject back in response to the probe. &lt;BR /&gt;&lt;BR /&gt;"key testise" is the radius shared secret that the switch uses to communicate with ISE.  You set the key "testise" to anything you want, but it has to match on the network device configured within the ISE GUI.</description>
      <pubDate>Thu, 17 Oct 2019 02:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942132#M456386</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-10-17T02:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942322#M456388</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this "dummy" is not a username configured in ISE. Basically "dummy" is going to fail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the key needs to be correct same like in ISE.&lt;/P&gt;&lt;P&gt;AM i&amp;nbsp; correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 07:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3942322#M456388</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-10-17T07:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3945317#M456389</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I check the username dummy(by filter) in the ISE live logs, can I see the failed session for user "dummy"?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3945317#M456389</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-10-22T13:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3947387#M456390</link>
      <description>&lt;P&gt;By default ISE will not disclose invalid usernames in the RADIUS logs.&amp;nbsp; You can turn that annoying feature off in the RADIUS settings in ISE.&amp;nbsp; As Damien said ISE can reject the authentication and the switch won't care as long as it is getting a response.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I usually setup a policy set for the switch keep alives as I don't like not handling the request properly.&amp;nbsp; I set the authentication to internal user and set the user not found to Continue.&amp;nbsp; Then I put in an authorization rule to allow the access with a deny all DACL.&amp;nbsp; Once I see the successful hits in the RADIUS logs I turn on suppression for the User ID so the switch probes aren't filling up my logs.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 14:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/3947387#M456390</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-10-24T14:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092341#M560689</link>
      <description>&lt;P&gt;Is it possible to share your authentication and authorization rules in your policy set?&amp;nbsp; I would like to do this as the "Invalid" errors is filling up the Live logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 19:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092341#M560689</guid>
      <dc:creator>fhowzejr2</dc:creator>
      <dc:date>2020-05-26T19:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092366#M560691</link>
      <description>&lt;P&gt;Skip the policy set and just go to Administration-&amp;gt;System-&amp;gt;Logging-&amp;gt;Collection Filters and setup a new collection filter to Filter All for the username "dummy" or whatever you are using for your switch keep-alive probes.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 19:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092366#M560691</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2020-05-26T19:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is username "dummy" exist by default in ISE used when testing "automate-tester username dummy probe-on"?</title>
      <link>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092398#M560693</link>
      <description>Thanks so much, I applied the collection filter and no longer have the clutter in Live Logs.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 26 May 2020 20:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/is-username-quot-dummy-quot-exist-by-default-in-ise-used-when/m-p/4092398#M560693</guid>
      <dc:creator>fhowzejr2</dc:creator>
      <dc:date>2020-05-26T20:32:22Z</dc:date>
    </item>
  </channel>
</rss>

