<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Session API is not working for some endpoints authenticating after every hour. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595243#M529709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If ISE is getting accounting start and stop and the endpoints' IP address, and if not using device sensor, I see no reason to have that command. However, you might want to turn it on to test and verify it making some difference. It would be good to get wire captures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 May 2017 02:38:18 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-05-18T02:38:18Z</dc:date>
    <item>
      <title>Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595238#M529699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having ISE architecture with dedicated Admin, MnT and PSN. We are trying to generate report from third party tool for endpoints authenticated through ISE. For the same, we are using session API. It has been observed that for some of the endpoints, session API does not work and gives error &lt;STRONG&gt;'Session data is not available in the last 5 days.'&lt;/STRONG&gt; The periodic authentication command does present on the interface and endpoint is getting authenticated after every hour. So According to me session API should have worked. Any Guess ? Please find attachment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;for same endpoints if we send CoA with port bounce from Live session and then execute session API then we are able to achieve expected result.&lt;/LI&gt;&lt;LI&gt;The command 'aaa accounting update newinfo periodic 2880' is NOT present on global mode. Is radius interim accounting update is cause of this issue. &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If endpoint is getting authenticated after every hour (PFA) still do we need to worry about radius interim accounting messages. What is correlation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 18:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595238#M529699</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-05-11T18:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595239#M529701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From one of your pics, it looks like an ISE 2.1 deployment. In case it has at least Patch 2 applied, which fixes CSCur11333, please open a TAC case to investigate. Also, please verify that last-5-day records are present in either RADIUS auth or account reports for such endpoints.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 20:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595239#M529701</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-11T20:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595240#M529703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. we are on patch 3 so bug should not be coming into the picture.&amp;nbsp; We will open TAC case&amp;nbsp; but still curious to know below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If endpoint is getting authenticated after every hour&amp;nbsp; still do we need to worry about radius interim accounting messages. What is correlation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why session API gets working for concern endpoints if we send CoA with port bounce from Live session. What is correlation of&amp;nbsp; Radius reauth vs Coa Port bounce&amp;nbsp; with respect to Session API.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2017 21:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595240#M529703</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-05-12T21:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595241#M529704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you able to check the RADIUS auth and accounting reports on the problem endpoints. With log suppression enabled, not all authentication attempts are recorded in the ISE db but that is a good thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With port bounce, the endpoints would get new session IDs. Regardless of session IDs old or new, we should have be able obtain the results. Thus, we need a TAC engagement and get a copy of the OPS backup to dive into data analysis or it might be a side effect of other exceptions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 May 2017 22:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595241#M529704</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-12T22:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595242#M529706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for delay. I did check Radius auth and accounting reports..MAC address logs is getting showed of couple of times a day. Auth Supression is setting is completely disabled.&amp;nbsp; we will open TAC case to investigate further.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please explain / point out any doc , to answer below question &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If endpoint is getting authenticated after every hour still do we need to worry about radius interim accounting messages ?&lt;/P&gt;&lt;P&gt;In other words is 'aaa accounting update .....' command required on switch if endpoint is getting authenticated after every hour.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 May 2017 14:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595242#M529706</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-05-17T14:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595243#M529709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If ISE is getting accounting start and stop and the endpoints' IP address, and if not using device sensor, I see no reason to have that command. However, you might want to turn it on to test and verify it making some difference. It would be good to get wire captures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 May 2017 02:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595243#M529709</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-18T02:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Session API is not working for some endpoints authenticating after every hour.</title>
      <link>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595244#M529710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt; : Just to update you . TAC case &lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;682422845&amp;nbsp; has been opened to track this issue. TAC believes below bug is causing issue &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;CSCvd41050: ISE 2.1 Endpoint lookup using ERS API is very slow.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;But honestly I am not sure if above bug is real cause because we do get response from session API as &lt;STRONG&gt;'Session data is not available in the last 5 days.'&amp;nbsp; &lt;/STRONG&gt;What do you think ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 18:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/session-api-is-not-working-for-some-endpoints-authenticating/m-p/3595244#M529710</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2017-06-13T18:38:52Z</dc:date>
    </item>
  </channel>
</rss>

