<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSN profiling SNMP query timers question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688260#M521619</link>
    <description>&lt;P&gt;RADIUS accounting will also trigger SNMP poll.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, it should fall back to another PSN for polling.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 16:39:19 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2018-08-14T16:39:19Z</dc:date>
    <item>
      <title>PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688195#M521526</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please could someone explain exactly what is meant by the following two fields:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Timeout&lt;/P&gt;
&lt;P&gt;- EventTimeout&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the SNMP query profiling configuration page?&amp;nbsp; Also, are both fields in seconds?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is on ISE 2.2 patch 9. We have a number of 3850 switches with multiple units in a stack and I have a suspicion they're timing out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Dave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688195#M521526</guid>
      <dc:creator>Dave Lewis</dc:creator>
      <dc:date>2018-08-14T15:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688222#M521559</link>
      <description>&lt;P&gt;Timeout: How long ISE waits for network device to respond in milliseconds.&lt;/P&gt;
&lt;P&gt;EventTimeout: How long ISE waits to perform targeted SNMP poll for specific interface after linkup/new MAC shows up in seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the symptom you are experiencing? If you suspect delayed response from the 3850, you can try increasing the Timeout value to see if it helps. Also, suggest looking into profiling debug as well.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688222#M521559</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-14T16:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688238#M521575</link>
      <description>&lt;P&gt;What is triggering you suspicion?&amp;nbsp; ISE alarms for SNMP profiler?&amp;nbsp; That alarm is mostly useless because ISE doesn't distinguish between an SNMP failure (we would care about this) to a NAD vs. SNMP failure to a client device (which is normal and we don't care about).&amp;nbsp; In all my installs I shut off the SNMP failure alarm.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688238#M521575</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-14T16:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688245#M521591</link>
      <description>&lt;P&gt;Perfect, thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So is EventTimeout only used if ISE receives an SNMP trap from the NAD?&amp;nbsp;Or do other events also trigger a poll of a particular interface? I don't have SNMP traps being sent to PSNs currently.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Symptom is "&lt;SPAN&gt;Profiler SNMP Request Failure : Server= xxxx; NAD Address=10.x.y.z" frequently (around every 5 or 10 minutes) on multiple endpoints. I know the credentials etcetera are correct so I suspect a timeout.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have disabled the NMAP probe and I no longer see the errors about endpoints but I still receive these NAD failures.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I haven't tried enabling debugs of profiling - would we expect a significant impact on&amp;nbsp;the performance of the ISE nodes if we enable that?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On a related note - in NAD configuration - if I set a 'preferred' SNMP polling PSN what happens if that PSN is out of service (e.g. due to an upgrade or a network issue)? Does it fail-back to&amp;nbsp;using any other PSN or does it just fail?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Dave&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688245#M521591</guid>
      <dc:creator>Dave Lewis</dc:creator>
      <dc:date>2018-08-14T16:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688259#M521604</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are seeing frequent SNMP profiler alarms specifically to NADs. We were previously receiving the alarms about endpoints but since disabling NMAP probe we only get the NAD alarms now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know the credentials are correct so I suspect a timeout as my experience of 3850's is their&amp;nbsp;control plane performance degrades exponentially the more switches you have in a stack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688259#M521604</guid>
      <dc:creator>Dave Lewis</dc:creator>
      <dc:date>2018-08-14T16:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688260#M521619</link>
      <description>&lt;P&gt;RADIUS accounting will also trigger SNMP poll.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, it should fall back to another PSN for polling.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688260#M521619</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-14T16:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688277#M521624</link>
      <description>&lt;P&gt;Ah okay thanks, that makes sense then as we're also experiencing an issue where the NADs are sending accounting updates too frequently (despite having the correct update newinfo periodic command). I have a TAC case open on that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 17:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688277#M521624</guid>
      <dc:creator>Dave Lewis</dc:creator>
      <dc:date>2018-08-14T17:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688281#M521629</link>
      <description>I shut off that alarm as well. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Aug 2018 17:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3688281#M521629</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-14T17:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3717000#M521635</link>
      <description>Hi Dave, Did you get a reply from TAC about the accounting updates?&lt;BR /&gt;&lt;BR /&gt;Thanks Michael</description>
      <pubDate>Tue, 02 Oct 2018 01:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3717000#M521635</guid>
      <dc:creator>duncanmj</dc:creator>
      <dc:date>2018-10-02T01:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: PSN profiling SNMP query timers question</title>
      <link>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3718126#M521640</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the accounting updates was in a separate thread but I gave up on that with TAC, partly because it seems cosmetic and not&amp;nbsp;having a significant detrimental impact and partly because I believe the problem (in our case) is caused by printers. Specifically HP printers running old firmware that initiate and respond to dot1x EAPoL frames even when you've disabled the setting. Thus these printers each try and fail to authenticate to ISE once per minute which triggers the ISE alerts, a firmware update on the printers fixes it. I've upgraded all printer firmware in our of our offices and am no longer receiving the 'too frequent accounting updates' message from those switches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 09:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/psn-profiling-snmp-query-timers-question/m-p/3718126#M521640</guid>
      <dc:creator>Dave Lewis</dc:creator>
      <dc:date>2018-10-03T09:51:01Z</dc:date>
    </item>
  </channel>
</rss>

