<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Live logs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4011305#M541015</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Its a kind of annoying to see many of the following logs throughout the day in cisco ise.&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Jan 14, 2020 02:27:05.460 PM&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="text-center"&gt;&lt;IMG src="https://10.1.206.121/admin/images/statusIcon/alert_critical_n_16.png" border="0" width="15" height="15" /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&lt;DIV class="text-center"&gt;&lt;A target="_blank"&gt;&lt;IMG src="https://10.1.206.121/admin/images/statusIcon/show_details_n_16.png" border="0" width="15" height="15" /&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&lt;A target="_blank"&gt;INVALID&lt;/A&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Default &amp;gt;&amp;gt; Default&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Default&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why the switch is kept on sending access-request massages from the port, where the device had been already authenticated and working fine.&lt;/P&gt;&lt;P&gt;Moreover, this NAD is sending unnecessary requests to ISE even no device or users connect to the switch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to stop it? Please see the attached screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;MD&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2020 15:52:16 GMT</pubDate>
    <dc:creator>munish.dhiman1</dc:creator>
    <dc:date>2020-01-14T15:52:16Z</dc:date>
    <item>
      <title>Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4011305#M541015</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Its a kind of annoying to see many of the following logs throughout the day in cisco ise.&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Jan 14, 2020 02:27:05.460 PM&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="text-center"&gt;&lt;IMG src="https://10.1.206.121/admin/images/statusIcon/alert_critical_n_16.png" border="0" width="15" height="15" /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&lt;DIV class="text-center"&gt;&lt;A target="_blank"&gt;&lt;IMG src="https://10.1.206.121/admin/images/statusIcon/show_details_n_16.png" border="0" width="15" height="15" /&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&lt;A target="_blank"&gt;INVALID&lt;/A&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="cell-hover-view"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Default &amp;gt;&amp;gt; Default&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="ellipsis"&gt;Default&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why the switch is kept on sending access-request massages from the port, where the device had been already authenticated and working fine.&lt;/P&gt;&lt;P&gt;Moreover, this NAD is sending unnecessary requests to ISE even no device or users connect to the switch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to stop it? Please see the attached screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;MD&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 15:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4011305#M541015</guid>
      <dc:creator>munish.dhiman1</dc:creator>
      <dc:date>2020-01-14T15:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4013058#M541031</link>
      <description>&lt;P&gt;First of all, need to un-mask what INVALID is. ISE 2.4+ is masking the usernames of the failed authentications. ISE 2.4 has an option to disclose it temporally for 30 minutes. Once that identified, then we will try and determine why it repeating the authentications.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-16 at 2.41.48 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/65271i8B4863B5CE701A16/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-16 at 2.41.48 PM.png" alt="Screen Shot 2020-01-16 at 2.41.48 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 22:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4013058#M541031</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-01-16T22:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4013427#M541100</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well i cannot see this option in my case 2.6 ISE. Please see attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;MD&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 13:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4013427#M541100</guid>
      <dc:creator>munish.dhiman1</dc:creator>
      <dc:date>2020-01-17T13:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014071#M541114</link>
      <description>&lt;P&gt;ISE 2.6 has it under Security Settings. Note a known issue CSCvo24097 is resolved in ISE 2.6 Patch 3.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-01-18 at 6.30.19 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/65385iDA0D099C53B2D57A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-01-18 at 6.30.19 PM.png" alt="Screen Shot 2020-01-18 at 6.30.19 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2020 02:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014071#M541114</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-01-19T02:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014677#M541198</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, Now I can see the name "admin" and getting the following logs. But no one tiring to authenticate, i have configured only a single port for dot1x and MAB. Both IP-phone and laptop is working fine.. If i disconnect one of the device from that post ,it starts sending an unnecessary authentication request to the ISE. Am i doing something wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Switch port Configuration :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/8&lt;BR /&gt;description 802.1x Enabled&lt;BR /&gt;switchport access vlan 11&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 156&lt;BR /&gt;srr-queue bandwidth share 1 30 35 5&lt;BR /&gt;priority-queue out&lt;BR /&gt;authentication control-direction in&lt;BR /&gt;authentication event fail action next-method&lt;BR /&gt;authentication event server alive action reinitialize&lt;BR /&gt;authentication host-mode multi-domain&lt;BR /&gt;authentication order mab dot1x&lt;BR /&gt;authentication priority mab dot1x&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer inactivity server&lt;BR /&gt;authentication violation replace&lt;BR /&gt;mab&lt;BR /&gt;mls qos trust device cisco-phone&lt;BR /&gt;mls qos trust cos&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 10&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;spanning-tree guard root&lt;BR /&gt;service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;MD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5400 Authentication failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Failure Reason&lt;/TD&gt;&lt;TD&gt;22056 Subject not found in the applicable identity store(s)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Resolution&lt;/TD&gt;&lt;TD&gt;Check whether the subject is present in any one of the chosen identity stores. Note that some identity stores may have been skipped due to identity resoultion settings or if they do not support the current authentication protocol.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Root cause&lt;/TD&gt;&lt;TD&gt;Subject not found in the applicable identity store(s).&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;admin&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Method&lt;/TD&gt;&lt;TD&gt;PAP_ASCII&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Protocol&lt;/TD&gt;&lt;TD&gt;PAP_ASCII&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Service Type&lt;/TD&gt;&lt;TD&gt;Login&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;&lt;TD&gt;Internal Users&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;&lt;TD&gt;All_AD_Join_Points&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;&lt;TD&gt;Guest Users&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IdentityPolicyMatchedRule&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ISEPolicySetName&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IdentitySelectionMatchedRule&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IsMachineIdentity&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;DTLSSupport&lt;/TD&gt;&lt;TD&gt;Unknown&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Network Device Profile&lt;/TD&gt;&lt;TD&gt;Cisco&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;Location#All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;Device Type#All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;IPSEC&lt;/TD&gt;&lt;TD&gt;IPSEC#Is IPSEC Device#No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;RADIUS Username&lt;/TD&gt;&lt;TD&gt;admin&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Event&lt;/TD&gt;&lt;TD&gt;5400 Authentication failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Username&lt;/TD&gt;&lt;TD&gt;admin&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Id&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Endpoint Profile&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authentication Policy&lt;/TD&gt;&lt;TD&gt;Default &amp;gt;&amp;gt; Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authorization Policy&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Authorization Result&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 20 Jan 2020 14:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014677#M541198</guid>
      <dc:creator>munish.dhiman1</dc:creator>
      <dc:date>2020-01-20T14:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Live logs</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014682#M541199</link>
      <description>&lt;P&gt;Thanks, I guess i have found the root cause. I configured&amp;nbsp;automate-tester on the switch which was causing this behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;MD&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 14:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-live-logs/m-p/4014682#M541199</guid>
      <dc:creator>munish.dhiman1</dc:creator>
      <dc:date>2020-01-20T14:46:30Z</dc:date>
    </item>
  </channel>
</rss>

