<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Endpoint Counter in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424433#M530532</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are deploying a new PoC enviroment and we are running in a strange problem. It seems that &lt;SPAN style="font-size: 13.3333px;"&gt;counter for the &lt;/SPAN&gt;active endpoints is not incrementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;3 nodes of ISE in PAN failover running version 2.2 and an external web server with the scope to create guest user using API integration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the guest user is authenticated from guest DB on ISE, we are able to see the authentication session on ISE from "Operation --&amp;gt; Radius --&amp;gt; Live Logs and Live Session", but under "Context Visibility -- Endpoints -- Authentication" all endpoints are in disconnected or null status.&lt;/P&gt;&lt;P&gt;I can also see that the session status in Live session tab is always setted in "Started" or "Terminated" value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anybody experiencing the same our problem? Is status session correct or we should have different value?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Andrea Tornaghi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Mar 2017 12:25:44 GMT</pubDate>
    <dc:creator>AndreaTornaghi</dc:creator>
    <dc:date>2017-03-27T12:25:44Z</dc:date>
    <item>
      <title>Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424433#M530532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are deploying a new PoC enviroment and we are running in a strange problem. It seems that &lt;SPAN style="font-size: 13.3333px;"&gt;counter for the &lt;/SPAN&gt;active endpoints is not incrementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;3 nodes of ISE in PAN failover running version 2.2 and an external web server with the scope to create guest user using API integration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the guest user is authenticated from guest DB on ISE, we are able to see the authentication session on ISE from "Operation --&amp;gt; Radius --&amp;gt; Live Logs and Live Session", but under "Context Visibility -- Endpoints -- Authentication" all endpoints are in disconnected or null status.&lt;/P&gt;&lt;P&gt;I can also see that the session status in Live session tab is always setted in "Started" or "Terminated" value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anybody experiencing the same our problem? Is status session correct or we should have different value?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Andrea Tornaghi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Mar 2017 12:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424433#M530532</guid>
      <dc:creator>AndreaTornaghi</dc:creator>
      <dc:date>2017-03-27T12:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424434#M530533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RADIUS Accounting is how ISE tracks the sessions and performs licensing counts.&lt;/P&gt;&lt;P&gt;I suspect that you are not sending RADIUS Accounting information from your NADs to ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="column"&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'courier new', courier; font-weight: bold;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa accounting dot1x default start-stop group &lt;/SPAN&gt;&lt;SPAN style="font-style: italic; font-size: 12pt; font-family: 'courier new', courier; font-weight: bold;"&gt;ISE-Group&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please see our &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/docs/DOC-68171"&gt;How To: Universal IOS Switch Config for ISE&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; under &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/docs/DOC-64012"&gt;ISE Design &amp;amp;amp; Integration Guides&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; for the full details about how to configure AAA Accounting on a switch with ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;IF it persists, verify you are using a validated version of NAD software from the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/compatibility/ise_sdt.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/compatibility/ise_sdt.html"&gt;Cisco Identity Services Engine Network Component Compatibility, Release 2.2 - Cisco&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 14:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424434#M530533</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2017-03-28T14:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424435#M530534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if, on ISE, I go in Operations -- Reports -- Endpoint and Users -- RADIUS Accounting I am able to see some logs from Accounting process (you can find an example below).&lt;/P&gt;&lt;P&gt;My NAD is WLC 5508 running version 8.2.130, and on SSID I have configured as accounting servers all PSN nodes in the same order of authentication servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked also that Accounting is enabled in Logging Categories List and it is collecting logs from LogCollector and LogCollector2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ex.&lt;/P&gt;&lt;P&gt;11004&amp;nbsp; Received RADIUS Accounting-Request&lt;/P&gt;&lt;P&gt;11017 RADIUS created a new session&lt;/P&gt;&lt;P&gt;15049 Evaluating Policy Group&lt;/P&gt;&lt;P&gt;15008 Evaluating Service Selection Policy&lt;/P&gt;&lt;P&gt;15004&amp;nbsp; Matched rule&lt;/P&gt;&lt;P&gt;22083 User/group session counters incremented on accounting start&lt;/P&gt;&lt;P&gt;11005 Returned RADIUS Accounting-Response&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 16:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424435#M530534</guid>
      <dc:creator>AndreaTornaghi</dc:creator>
      <dc:date>2017-03-28T16:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424436#M530535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be sure to enable the RADIUS Server Accounting &amp;gt; Interim Update checkbox but set Interim Interval to 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 20:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424436#M530535</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-03-28T20:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424437#M530536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chyps, you answer is correct. The problem was on WLC side. I enabled the RADIUS Server Accounting Interim update and everything is working fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 11:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424437#M530536</guid>
      <dc:creator>AndreaTornaghi</dc:creator>
      <dc:date>2017-03-29T11:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424438#M530538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig doesn’t need to be told when he is right…it’s just assumed &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Mar 2017 17:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3424438#M530538</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-03-30T17:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3717307#M530539</link>
      <description>&lt;P&gt;Hello Gents,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got exactly the same problem.&lt;/P&gt;
&lt;P&gt;My WLC is 8.0.152 and there is no indication for RADIUS&amp;gt;Accounting there will be any Interim Update checkbox. Might my firmware to old, what do you think ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lkajcsu01&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 12:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3717307#M530539</guid>
      <dc:creator>lkajcsu01</dc:creator>
      <dc:date>2018-10-02T12:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3717430#M530541</link>
      <description>&lt;P&gt;The interim accounting setting is under each WLAN. Go to WLAN -&amp;gt; Select WLAN and edit -&amp;gt; Security -&amp;gt; AAA Servers.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 14:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3717430#M530541</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-02T14:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Active Endpoint Counter</title>
      <link>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3809165#M530543</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can this command be used with Tacacs+ instead of Radius as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: 'courier new', courier; font-weight: bold;"&gt;&amp;nbsp; aaa accounting dot1x default start-stop group TACACS-Server-GROUP&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Jochen&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 16:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/active-endpoint-counter/m-p/3809165#M530543</guid>
      <dc:creator>jayage</dc:creator>
      <dc:date>2019-02-25T16:24:51Z</dc:date>
    </item>
  </channel>
</rss>

