<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send syslog for each new WMI session (passive id) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3701078#M494251</link>
    <description>&lt;P&gt;Hi Krish,&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;/P&gt;
&lt;P&gt;My use case is different - as mentioned ISE is not doing any authentication - with Easy Connect it does.&lt;/P&gt;
&lt;P&gt;So i do assume the answer is: ISE is not able to send syslog for passively discovered mappings/sessions, but only for those for which authentication is done.&lt;/P&gt;
&lt;P&gt;Correct ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2018 10:51:49 GMT</pubDate>
    <dc:creator>Michal Garcarz</dc:creator>
    <dc:date>2018-09-05T10:51:49Z</dc:date>
    <item>
      <title>Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3700713#M494249</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;Could you confirm: is it possible for ISE to send syslog message for every new WMI session discovered passively ?&lt;/P&gt;
&lt;P&gt;As far as i see in my Splunk: it's NOT. Passiveid service is just for service (not for dataplane/sessions).&lt;/P&gt;
&lt;P&gt;(i have almost all components configured to send syslogs to Splunk).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please confirm - maybe i am missing something.&lt;/P&gt;
&lt;P&gt;ISE not doing any authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 19:50:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3700713#M494249</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2018-09-04T19:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3700797#M494250</link>
      <description>&lt;P&gt;is your flow similar to the one described in this nicely written Techzone article? If so, the answer is Yes.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Configure-EasyConnect-on-ISE-2-1/ta-p/842096" target="_blank"&gt;https://techzone.cisco.com/t5/Identity-Services-Engine-ISE/Configure-EasyConnect-on-ISE-2-1/ta-p/842096&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Do you have access to ISE &amp;amp; did you check the Live logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Krish&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 22:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3700797#M494250</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-09-04T22:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3701078#M494251</link>
      <description>&lt;P&gt;Hi Krish,&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;/P&gt;
&lt;P&gt;My use case is different - as mentioned ISE is not doing any authentication - with Easy Connect it does.&lt;/P&gt;
&lt;P&gt;So i do assume the answer is: ISE is not able to send syslog for passively discovered mappings/sessions, but only for those for which authentication is done.&lt;/P&gt;
&lt;P&gt;Correct ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 10:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3701078#M494251</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2018-09-05T10:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3701343#M494252</link>
      <description>&lt;P&gt;If the flow is different from what is documented in the link I sent you, then the answer depends. Can you verify what you see in ISE logs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Krish&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 16:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3701343#M494252</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-09-05T16:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3702006#M494295</link>
      <description>&lt;P&gt;I see no logs in ISE - as i have mentioned already: ISE is not doing ANY authentication &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 12:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3702006#M494295</guid>
      <dc:creator>Michal Garcarz</dc:creator>
      <dc:date>2018-09-06T12:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Send syslog for each new WMI session (passive id)</title>
      <link>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3702194#M494297</link>
      <description>&lt;P&gt;In that case no Syslogs may be available. Needs to be a new feature &amp;amp; please connect with the ISE PM team.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 15:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-syslog-for-each-new-wmi-session-passive-id/m-p/3702194#M494297</guid>
      <dc:creator>kvenkata1</dc:creator>
      <dc:date>2018-09-06T15:23:05Z</dc:date>
    </item>
  </channel>
</rss>

