<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - multiple radius live log entries for same request in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857854#M472988</link>
    <description>&lt;P&gt;I see you have ~ 11 entries within the same second.&lt;/P&gt;
&lt;P&gt;First, go to [ ISE admin web UI &amp;gt; Administration &amp;gt; System &amp;gt; Logging &amp;gt; Remote Logging Targets ], verify only one target enabled per M&amp;amp;T node.&lt;/P&gt;
&lt;P&gt;Second, monitor the RADIUS requests from the network device by TCPDUMP or Use&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/check-logs-on-cisco-ise/m-p/3856121#M26727" target="_blank"&gt;Re: Check logs on Cisco ISE&lt;/A&gt;&amp;nbsp;to verify only one request sent to the ISE PSN.&lt;/P&gt;
&lt;P&gt;If neither helps, time to open a TAC case.&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2019 19:58:51 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2019-05-16T19:58:51Z</dc:date>
    <item>
      <title>Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857780#M472986</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; I am getting a vast number of seemingly duplicate entries in the Radius Live Logs.&amp;nbsp; As far as I am aware they are all for one request, and are even if it is a pass.&amp;nbsp; See attached picture.&lt;BR /&gt;&lt;BR /&gt;Any help would be appreciated.&lt;BR /&gt;&lt;BR /&gt;The attached picture I have crossed out the username, but they are all identical.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 18:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857780#M472986</guid>
      <dc:creator>nathgregory</dc:creator>
      <dc:date>2019-05-16T18:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857854#M472988</link>
      <description>&lt;P&gt;I see you have ~ 11 entries within the same second.&lt;/P&gt;
&lt;P&gt;First, go to [ ISE admin web UI &amp;gt; Administration &amp;gt; System &amp;gt; Logging &amp;gt; Remote Logging Targets ], verify only one target enabled per M&amp;amp;T node.&lt;/P&gt;
&lt;P&gt;Second, monitor the RADIUS requests from the network device by TCPDUMP or Use&amp;nbsp;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/check-logs-on-cisco-ise/m-p/3856121#M26727" target="_blank"&gt;Re: Check logs on Cisco ISE&lt;/A&gt;&amp;nbsp;to verify only one request sent to the ISE PSN.&lt;/P&gt;
&lt;P&gt;If neither helps, time to open a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 19:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857854#M472988</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-05-16T19:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857961#M472990</link>
      <description>&lt;P&gt;Hi mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be that the supplicant on end device has issue.&lt;/P&gt;&lt;P&gt;Or if it is legit radius sessiions, then you can just suppress it by following the steps below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;1. Go to Administration/Settings/Protocols/RADIUS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2. Check "Suppress successful reports"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3. You can also check "Suppress Repeated failed clients"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: There are variety of settings that you can choose there depending on what you want to set&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you've done this, the Live Logs will only show one line for specific session and it will provide the number of repeat counts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Raffy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 23:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3857961#M472990</guid>
      <dc:creator>RaffyLindogan</dc:creator>
      <dc:date>2019-05-16T23:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858176#M473079</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; TCPDump shows only one Radius request being sent.&lt;BR /&gt;&lt;BR /&gt;Why would it show multiple times in the logs though?&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 09:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858176#M473079</guid>
      <dc:creator>nathgregory</dc:creator>
      <dc:date>2019-05-17T09:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858177#M473080</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Only one Radius request was sent, but it is already selected to Suppress Succcessfull Reports.&amp;nbsp; Strange.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 09:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858177#M473080</guid>
      <dc:creator>nathgregory</dc:creator>
      <dc:date>2019-05-17T09:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858257#M473081</link>
      <description>&lt;P&gt;Hi mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it is one endpoint/user causing that then it could be issue on supplicant.&lt;/P&gt;&lt;P&gt;you can update driver of supplicant.&lt;/P&gt;&lt;P&gt;It doesnt explain though why it would appear on separate sessions if suppression for both failed and successful connections is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Raffy&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 12:13:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858257#M473081</guid>
      <dc:creator>RaffyLindogan</dc:creator>
      <dc:date>2019-05-17T12:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858271#M473082</link>
      <description>&lt;P&gt;A packet dump confirmed only on radius request was made from the supplicant to ISE.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I don't have the issue with other network devices though, just the 2700 autonomous Access Point.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 12:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858271#M473082</guid>
      <dc:creator>nathgregory</dc:creator>
      <dc:date>2019-05-17T12:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - multiple radius live log entries for same request</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858683#M473083</link>
      <description>&lt;P&gt;ISE is not restricting to use the same host in multiple logging targets.&lt;/P&gt;
&lt;P&gt;If this is not your issue, please engage TAC.&lt;/P&gt;</description>
      <pubDate>Sat, 18 May 2019 03:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-multiple-radius-live-log-entries-for-same-request/m-p/3858683#M473083</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-05-18T03:16:49Z</dc:date>
    </item>
  </channel>
</rss>

