<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA Integration Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450087#M536928</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you following either of our guides:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/migration-blogpost/8138"&gt;ISE 2.1 and WSA via pxGrid and CA-Signed Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68290"&gt;How To: Integrate Cisco WSA using ISE and TrustSec via pxGrid&lt;/A&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Feb 2017 22:20:42 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2017-02-06T22:20:42Z</dc:date>
    <item>
      <title>WSA Integration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450084#M536921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having some issues with WSA integration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've enabled pxGrid on ISE have the cert signed with both client and server auth.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The root cert is uploaded to the WSA. I signed the WSA client cert with the pxGrid template.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a test I get the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Checking DNS resolution of ISE pxGrid Node hostname(s) ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Success: Resolved '172.16.2.17' address: 172.16.2.17&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Validating WSA client certificate ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Success: Certificate validation successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Validating ISE pxGrid Node certificate(s) ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Success: Certificate validation successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Validating ISE Monitorting Node Admin certificate(s) ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Success: Certificate validation successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Checking connection to ISE pxGrid Node(s) ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Success: Connection to ISE pxGrid Node was successful.&lt;BR /&gt;Retrieved 17 SGTs from: 172.16.2.17&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Checking connection to ISE Monitorting Node (REST server(s)) ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana, arial, sans-serif; font-size: 11px; color: #990000;"&gt;Failure: Connection to ISE Monitorting Node timed out&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #990000; font-family: verdana, arial, sans-serif; font-size: 11px;"&gt;Test interrupted: Fatal error occurred, see details above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The WSA is showing in the client list on ISE.&lt;IMG alt="wsapcgrid.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/102930_wsapcgrid.JPG" style="height: 115px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Nov 2016 01:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450084#M536921</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-11-26T01:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Integration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450085#M536924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it working. I didn't have a DNS record setup for the ISE node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have another question.&amp;nbsp; When I connect a VPN user with anyconnect, The live log doesn't show the IP address of the VPN client. Maybe it's not included in the radius request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to get that information? I can't enforce policy if I don't know the IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Nov 2016 04:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450085#M536924</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-11-26T04:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Integration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450086#M536926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to populate the IP address for VPN users by turning on accounting on the VPN profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However that user data isn't being passed to FMC or WSA.&amp;nbsp; Windows login event are via passiveID but not the VPN logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shouldn't any session be passed over via pxGrid to WSA and FMC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 16:52:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450086#M536926</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-11-29T16:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: WSA Integration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450087#M536928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you following either of our guides:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/migration-blogpost/8138"&gt;ISE 2.1 and WSA via pxGrid and CA-Signed Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68290"&gt;How To: Integrate Cisco WSA using ISE and TrustSec via pxGrid&lt;/A&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2017 22:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-integration-issue/m-p/3450087#M536928</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2017-02-06T22:20:42Z</dc:date>
    </item>
  </channel>
</rss>

