<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MDM endpoint attributes cached in ISE for loss of connectivity? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3780218#M486305</link>
    <description>&lt;P&gt;We have a &lt;A href="https://community.cisco.com/t5/security-documents/how-to-integrate-cisco-ise-with-microsoft-sccm-for-patch/ta-p/3725035" target="_self"&gt;MDM Deployment Guide&lt;/A&gt; that outlines best practice for integration of SCCM and ISE.&amp;nbsp; As to whether or not ISE caches MDM attributes; I don't believe it does because ISE relies on SCCM to be the single source of truth when it needs compliance information for an endpoint tied to SCCM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 15:44:58 GMT</pubDate>
    <dc:creator>Timothy Abbott</dc:creator>
    <dc:date>2019-01-15T15:44:58Z</dc:date>
    <item>
      <title>MDM endpoint attributes cached in ISE for loss of connectivity?</title>
      <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3779549#M486298</link>
      <description>&lt;P&gt;Hi TME team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does ISE cache endpoint attributes related to MDM checks (like MDM.DeviceRegisterStatus) in the event that the MDM server becomes unreachable? If so, how long are they cached?&lt;/P&gt;
&lt;P&gt;I'm doing some customer testing with SCCM and ISE 2.2 p9 and getting some inconsistent behaviour, so I need to know what the expected behaviour is for this scenario?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we have any validated best practices for design or policy configuration (e.g. using the 'MDM.ServerReachable' condition match) to mitigate endpoint authZ issues in the event that connectivity is lost to the MDM server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 20:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3779549#M486298</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2019-01-14T20:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: MDM endpoint attributes cached in ISE for loss of connectivity?</title>
      <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3779848#M486303</link>
      <description>Hi, &lt;BR /&gt;&lt;BR /&gt;Dont know if the following document will help or not, &lt;BR /&gt;but i can consider it as best practice and have all info needed for integration &lt;BR /&gt;&lt;A href="https://cisco-marketing.hosted.jivesoftware.com/servlet/JiveServlet/previewBody/71727-102-1-139077/How%20to%20Integrate%20Microsoft%20SCCM%20with%20ISE%202.1.pptx.pdf" target="_blank"&gt;https://cisco-marketing.hosted.jivesoftware.com/servlet/JiveServlet/previewBody/71727-102-1-139077/How%20to%20Integrate%20Microsoft%20SCCM%20with%20ISE%202.1.pptx.pdf&lt;/A&gt;</description>
      <pubDate>Tue, 15 Jan 2019 07:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3779848#M486303</guid>
      <dc:creator>ma.alsaffar</dc:creator>
      <dc:date>2019-01-15T07:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: MDM endpoint attributes cached in ISE for loss of connectivity?</title>
      <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3780218#M486305</link>
      <description>&lt;P&gt;We have a &lt;A href="https://community.cisco.com/t5/security-documents/how-to-integrate-cisco-ise-with-microsoft-sccm-for-patch/ta-p/3725035" target="_self"&gt;MDM Deployment Guide&lt;/A&gt; that outlines best practice for integration of SCCM and ISE.&amp;nbsp; As to whether or not ISE caches MDM attributes; I don't believe it does because ISE relies on SCCM to be the single source of truth when it needs compliance information for an endpoint tied to SCCM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3780218#M486305</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2019-01-15T15:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: MDM endpoint attributes cached in ISE for loss of connectivity?</title>
      <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3781547#M486306</link>
      <description>&lt;P&gt;Thanks Tim. That would have been my expectation as well, but that's not what I've found in my testing.&lt;/P&gt;
&lt;P&gt;I created some Monitor Only rules to track the attributes for ServerReachable and DeviceRegister easier in the logs. I tested both before and after blocking network connectivity from the ISE nodes to the SCCM server and found the following:&lt;/P&gt;
&lt;P&gt;Before blocking SCCM:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sccm-reachable.png" style="width: 416px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27997i68BE970118BCF5AF/image-size/large?v=v2&amp;amp;px=999" role="button" title="sccm-reachable.png" alt="sccm-reachable.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After blocking SCCM:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sccm-unreachable.png" style="width: 419px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27996iB22DD905ECA9E0A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="sccm-unreachable.png" alt="sccm-unreachable.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even more odd, if I disconnect and delete the endpoint from Context Visibility then reconnect it, the new session shows 'SCCM Reachable' even though the PSN still has no network connectivity to SCCM.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sccm-endpoint-deleted.png" style="width: 445px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27999i332879F682C8A5AC/image-size/large?v=v2&amp;amp;px=999" role="button" title="sccm-endpoint-deleted.png" alt="sccm-endpoint-deleted.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know if this has anything to do with the bug fixed in P13 around Context Visibility not updating correctly, so I may have to test again with P13 applied. If I see the same behaviour, I might have to open a TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/359830"&gt;@Nidhi&lt;/a&gt;, any input here?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 22:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3781547#M486306</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2019-01-16T22:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: MDM endpoint attributes cached in ISE for loss of connectivity?</title>
      <link>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3781924#M486307</link>
      <description>&lt;P&gt;Hello Greg,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does look like it is getting saved in Cache.&amp;nbsp; you might be hitting&amp;nbsp;&lt;FONT&gt;&lt;STRONG&gt;&lt;A href="https://cdetsng.cisco.com/webui/#view=CSCvn70558" target="_blank"&gt;CSCvn70558&lt;/A&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG id="headline"&gt;MDMServerReachable does not work for SCCM MDM again&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;FONT size="1"&gt;&lt;A title="Help" href="http://wwwin.cisco.com/ops/infra/pds/cbms/cdets/legend.shtml" target="_blank"&gt;&lt;IMG src="https://cdetsweb-prd.cisco.com/apps/files/xslt/help.png" border="0" width="15" height="15" /&gt;&lt;/A&gt;&lt;/FONT&gt;This issue was observed internally as well. There was a fix done for caching issue for MDM. I suggest 2 things here -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1- Raise a TAC case so that they can suggest you the right patch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2- Include MDMServerReachable also in your Policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 10:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mdm-endpoint-attributes-cached-in-ise-for-loss-of-connectivity/m-p/3781924#M486307</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2019-01-17T10:31:01Z</dc:date>
    </item>
  </channel>
</rss>

