<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE user session question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-user-session-question/m-p/3419335#M527616</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Short answer is that RADIUS Accounting will trigger Start and Stop of session.&amp;nbsp; In lieu of RADIUS Accounting, other measures are taken to manage ISE sessions.&amp;nbsp; This topic is covered in BRKSEC-3699 session (see reference presentation on CiscoLive.com).&amp;nbsp; Here is excerpt:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Clearing Stale Sessions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;RADIUS Accounting is Primary method to maintain sessions &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; color: #39393b;"&gt;–&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;If RADIUS Accounting not sent (or not received due to network or PSN load drops), ISE will rely on Session Purge operation to clear stale sessions&lt;BR /&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG style="color: #39393b; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;Automatic Purge: &lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;A purge job runs approximately every 5 minutes to clear sessions that meet any of the following criterion:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint &lt;STRONG&gt;disconnected&lt;/STRONG&gt; (Ex: failed authentication) &lt;STRONG&gt;in the last 15 minutes&lt;/STRONG&gt; (grace time allotted in case of authentication retries)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint &lt;STRONG&gt;authenticated in last hour but no accounting start or update received&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint idle&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; color: #0070c0;"&gt;—&lt;/SPAN&gt;&lt;STRONG style="color: #0070c0; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;no activity&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin-left: 15.25pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;&lt;BR /&gt;Note: Session is cleared from MnT but does not generate CoA to prevent negative impact to connected endpoints.&amp;nbsp; In other words, MnT session is no longer visible but it is possible for endpoint to still have network access, but no longer consumes license. &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;STRONG style="color: #39393b; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;Manual Purge via REST API: &lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;HTTP DELETE&lt;STRONG&gt; &lt;/STRONG&gt;API can manually delete inactive sessions. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Aug 2017 12:17:25 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-08-15T12:17:25Z</dc:date>
    <item>
      <title>ISE user session question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-user-session-question/m-p/3419334#M527615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, ISE expert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would like to ask a question about ISE concurrent user session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;customer use GGSN with ISE as radius authentication server , if our user get authenticated , does ISE keep the user sessions until the account stop message come ? or Do we have some approach to shorten the session keeping time ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;hongtao&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2017 07:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-user-session-question/m-p/3419334#M527615</guid>
      <dc:creator>Hongtao Xu</dc:creator>
      <dc:date>2017-08-15T07:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE user session question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-user-session-question/m-p/3419335#M527616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Short answer is that RADIUS Accounting will trigger Start and Stop of session.&amp;nbsp; In lieu of RADIUS Accounting, other measures are taken to manage ISE sessions.&amp;nbsp; This topic is covered in BRKSEC-3699 session (see reference presentation on CiscoLive.com).&amp;nbsp; Here is excerpt:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Clearing Stale Sessions&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;RADIUS Accounting is Primary method to maintain sessions &lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; color: #39393b;"&gt;–&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;If RADIUS Accounting not sent (or not received due to network or PSN load drops), ISE will rely on Session Purge operation to clear stale sessions&lt;BR /&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG style="color: #39393b; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;Automatic Purge: &lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;A purge job runs approximately every 5 minutes to clear sessions that meet any of the following criterion:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint &lt;STRONG&gt;disconnected&lt;/STRONG&gt; (Ex: failed authentication) &lt;STRONG&gt;in the last 15 minutes&lt;/STRONG&gt; (grace time allotted in case of authentication retries)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint &lt;STRONG&gt;authenticated in last hour but no accounting start or update received&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #0070c0;"&gt;Endpoint idle&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; color: #0070c0;"&gt;—&lt;/SPAN&gt;&lt;STRONG style="color: #0070c0; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;no activity&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin-left: 15.25pt;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;&lt;BR /&gt;Note: Session is cleared from MnT but does not generate CoA to prevent negative impact to connected endpoints.&amp;nbsp; In other words, MnT session is no longer visible but it is possible for endpoint to still have network access, but no longer consumes license. &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;STRONG style="color: #39393b; font-size: 10.0pt; font-family: 'Arial',sans-serif;"&gt;Manual Purge via REST API: &lt;/STRONG&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: #39393b;"&gt;HTTP DELETE&lt;STRONG&gt; &lt;/STRONG&gt;API can manually delete inactive sessions. &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2017 12:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-user-session-question/m-p/3419335#M527616</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-15T12:17:25Z</dc:date>
    </item>
  </channel>
</rss>

