<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP timeouts for ISE and MobileIron? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521286#M527431</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You shouldn’t have to.  Are you seeing connections being terminated due to timeout?  Do you have absolute timeouts configured in the ASA by chance?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Aug 2017 21:00:57 GMT</pubDate>
    <dc:creator>gbekmezi-DD</dc:creator>
    <dc:date>2017-08-24T21:00:57Z</dc:date>
    <item>
      <title>TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521285#M527430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a ISE 2.2 deployment that is integrated with MobileIron MDM solution. We have seen intermittent failures in the communication between the solutions (the manual check is always successful). Now we have found a possible cause for the problems as we have found "Deny TCP (no connection..)" logs in the firewall (ASA) that are separating the systems.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Do we have to tweek the tcp timeout values in the firewall to successfully integrate ISE and MobileIron? Does anyone have experience from this?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri,Arial,Helvetica,sans-serif,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols,EmojiFont,Apple Color Emoji,Segoe UI Emoji,NotoColorEmoji,Segoe UI Symbol,Android Emoji,EmojiSymbols;"&gt;&lt;SPAN dir="ltr" style="font-size: 12pt; font-weight: normal;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2017 07:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521285#M527430</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2017-08-24T07:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521286#M527431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You shouldn’t have to.  Are you seeing connections being terminated due to timeout?  Do you have absolute timeouts configured in the ASA by chance?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2017 21:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521286#M527431</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-08-24T21:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521287#M527432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall is not logging session termination and it is using default settings for tcp (no service-policy tweeks applied). Time out values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:05:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;timeout conn-holddown 0:00:15&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 09:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521287#M527432</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2017-08-25T09:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521288#M527433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would take a packet capture to better understand when this happens.  Take a capture on the inside and outside with an ACL to limit the capture to this traffic.  The next time you see the no connection message, look at the capture to determine if ISE, MobileIron, or the ASA is responsible for killing the connection.  Also, depending on what level your logs are being generated at, you may not see the timeout message.  You should probably increase the log level to debug while you are troubleshooting this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 17:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521288#M527433</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-08-25T17:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521289#M527434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue orginated from MobileIron. A upgrade from v9.1 to 9.4 solved the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your inputs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 07:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521289#M527434</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2017-08-31T07:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521290#M527435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for closing the loop.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 19:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521290#M527435</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-08-31T19:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521291#M527436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are having a similar issue. We have ISE 2.1 patch 5 and MobileIron 9.2 in production and 9.5 for testing. The MDM setup in ISE for both MDM platforms reports successful tests, but when we compose conditions that check the 9.2 version for device status ISE just fails the call and moves on to new rules/conditions. The same checks to the 9.5 platform pass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have documentation regarding this bug or methodology for proving this bug condition?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521291#M527436</guid>
      <dc:creator>mike.jacobs</dc:creator>
      <dc:date>2018-01-17T18:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: TCP timeouts for ISE and MobileIron?</title>
      <link>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521292#M527437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is know issue in Mobileiron API calls in Mobileiron 9.2 version and there was patch released by Mobileiron, the down side of the patch is when ever you reboot Mobileiron server the patch has to be re-applyed, and it is expected to fix in Mobileiron 9.5. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested ISE 2.1 with Mobileiron 9.2 and Mobileiorn patch and it worked for me &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now i am testing ISE 2.1 with Mobileiron 9.5 so for it is not working,&amp;nbsp; seems this combination worked for you , can you tell me what is the ISE and Mobileiron version you used including patch version please for both. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;V.Muthu &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2018 07:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tcp-timeouts-for-ise-and-mobileiron/m-p/3521292#M527437</guid>
      <dc:creator>Muthu Mani</dc:creator>
      <dc:date>2018-01-25T07:17:12Z</dc:date>
    </item>
  </channel>
</rss>

