<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.3 Posture - User name change detected for the session in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3739948#M488621</link>
    <description>&lt;P&gt;Evening everyone.&lt;/P&gt;
&lt;P&gt;Having an issue with temporal agent posture check for BYOD clients and I'm not sure if it's client config causing it, or something on the ISE side.&lt;/P&gt;
&lt;P&gt;What I'm seeing is that when a client connects and gets redirected to download the temporal agent, the RADIUS Live Logs show the identity as&amp;nbsp;&lt;EM&gt;user@domain&lt;/EM&gt;. Once the posture check is done and a CoA is issue, the client then appears in the live logs as just&amp;nbsp;&lt;EM&gt;user&lt;/EM&gt; rather than&amp;nbsp;&lt;EM&gt;user@domain&lt;/EM&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I look at the report for the new authorisation, it has a line that says "User name change detected for the session.Attributes for the session will be removed from the cache."&lt;/P&gt;
&lt;P&gt;What that means from a user POV is that they need to re-run the posture assessment a second time, and then after another CoA and reauth the endpoint keeps the PostureStatus attribute as either Compliant/Non-Compliant and get appropriate access.&lt;/P&gt;
&lt;P&gt;I saw bug &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCuj34004" target="_self"&gt;CSCuj34004&lt;/A&gt;&amp;nbsp;that appeared to relate to my symptoms, but the workaround doesn't seem to work in my case. The BYOD policies are ordered such that compliant/non-compliant are ahead of unknown already, but the issue persists. Furthermore, all of my authentications are user authentication - there's never a change from machine to user auth.&lt;/P&gt;
&lt;P&gt;Has anyone observed similar behaviour before? I've had a poke around my client settings on my test machine but I can't see anything that would cause it to change the username it sends for 802.1x auth, so I'm not sure if that's being influenced by the temporal agent or not, or if there's something I can do on the ISE side to work around the issue.&lt;/P&gt;
&lt;P&gt;I've attached a screenshot of the RADIUS Live Logs showing the changing identity and showing how it seems to cause me to hit he 'UNKNOWN' BYOD policy twice.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Nov 2018 11:05:53 GMT</pubDate>
    <dc:creator>David Milne</dc:creator>
    <dc:date>2018-11-06T11:05:53Z</dc:date>
    <item>
      <title>ISE 2.3 Posture - User name change detected for the session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3739948#M488621</link>
      <description>&lt;P&gt;Evening everyone.&lt;/P&gt;
&lt;P&gt;Having an issue with temporal agent posture check for BYOD clients and I'm not sure if it's client config causing it, or something on the ISE side.&lt;/P&gt;
&lt;P&gt;What I'm seeing is that when a client connects and gets redirected to download the temporal agent, the RADIUS Live Logs show the identity as&amp;nbsp;&lt;EM&gt;user@domain&lt;/EM&gt;. Once the posture check is done and a CoA is issue, the client then appears in the live logs as just&amp;nbsp;&lt;EM&gt;user&lt;/EM&gt; rather than&amp;nbsp;&lt;EM&gt;user@domain&lt;/EM&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I look at the report for the new authorisation, it has a line that says "User name change detected for the session.Attributes for the session will be removed from the cache."&lt;/P&gt;
&lt;P&gt;What that means from a user POV is that they need to re-run the posture assessment a second time, and then after another CoA and reauth the endpoint keeps the PostureStatus attribute as either Compliant/Non-Compliant and get appropriate access.&lt;/P&gt;
&lt;P&gt;I saw bug &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCuj34004" target="_self"&gt;CSCuj34004&lt;/A&gt;&amp;nbsp;that appeared to relate to my symptoms, but the workaround doesn't seem to work in my case. The BYOD policies are ordered such that compliant/non-compliant are ahead of unknown already, but the issue persists. Furthermore, all of my authentications are user authentication - there's never a change from machine to user auth.&lt;/P&gt;
&lt;P&gt;Has anyone observed similar behaviour before? I've had a poke around my client settings on my test machine but I can't see anything that would cause it to change the username it sends for 802.1x auth, so I'm not sure if that's being influenced by the temporal agent or not, or if there's something I can do on the ISE side to work around the issue.&lt;/P&gt;
&lt;P&gt;I've attached a screenshot of the RADIUS Live Logs showing the changing identity and showing how it seems to cause me to hit he 'UNKNOWN' BYOD policy twice.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 11:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3739948#M488621</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2018-11-06T11:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Posture - User name change detected for the session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3764661#M488623</link>
      <description>&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCuj34004" target="_self" rel="nofollow noopener noreferrer"&gt;CSCuj34004&lt;/A&gt;&amp;nbsp;is an old bug and should only be applicable to ISE 1.x, but not ISE 2.x.&lt;/P&gt;
&lt;P&gt;Please engage Cisco TAC to take a look and see why your DOT1X supplicant sending ISE different formats for the username and why ISE not normalizing them and treating them as the same username.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Dec 2018 22:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3764661#M488623</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-16T22:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Posture - User name change detected for the session</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3768105#M488624</link>
      <description>&lt;P&gt;It seems an issue with the Cert auth profile and TAC opening a bug on it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 23:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-posture-user-name-change-detected-for-the-session/m-p/3768105#M488624</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-21T23:01:40Z</dc:date>
    </item>
  </channel>
</rss>

