<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE active sessions with no interim accounting support in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3730103#M549727</link>
    <description>&lt;P&gt;Can't seem to figure out how to do debug aaa accounting on 16.9.1 and get output.&lt;/P&gt;
&lt;P&gt;I watch an engineer once and he did some stuff and used show platform software trace message smd switch active R0, but I can't seem to get what he got.&lt;/P&gt;
&lt;P&gt;Anyway a capture shows that sometimes the update contains a Framed IP and sometimes it doesn't. Otherwise the only difference is in the bytes and packets, timestamp etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 19:09:09 GMT</pubDate>
    <dc:creator>Garry Cross</dc:creator>
    <dc:date>2018-10-22T19:09:09Z</dc:date>
    <item>
      <title>ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3348603#M549712</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I'm running into an issue with interim accounting and ISE. I have WS-C3650-48PD (03.07.05E) NADs doing 802.1x/MAB with ISE 2.3 patch 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;802.1x/MAB works fine but the ISE Active Endpoint total always looks a little on the low side. The NADs are configured to send interim accounting updates to ISE but after doing some debugs it looks like the NADs aren't sending any accounting packets to ISE other than start/stop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found the following forum post which states that bug CSCux75319 applies to 3650/3850s:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/cisco-bug-discussions/cscux75319-support-for-periodic-accounting-on-3850-switches/td-p/2921423" target="_blank"&gt;https://supportforums.cisco.com/t5/cisco-bug-discussions/cscux75319-support-for-periodic-accounting-on-3850-switches/td-p/2921423&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like ISE is not receiving any interim accounting packets for connected clients so ISE is gradually clearing these sessions. In the absence of interim accounting, is the best option to enable periodic re-authentication of clients?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3348603#M549712</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2020-02-21T18:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3349011#M549714</link>
      <description>Re-authentication should be one in this case. It won't harm if you set the&lt;BR /&gt;timers correctly as recommended by Cisco. If I recall from CLUS the were @&lt;BR /&gt;3600&lt;BR /&gt;</description>
      <pubDate>Thu, 15 Mar 2018 08:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3349011#M549714</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-03-15T08:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3349023#M549716</link>
      <description>&lt;P&gt;Thanks for the reply. I'll contact TAC in the first instance to confirm that the 3650s have an issue with interim accounting before looking at implementing re-authentication timers.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 09:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3349023#M549716</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2018-03-15T09:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368758#M549717</link>
      <description>&lt;P&gt;Hey Andy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you ever find out from the TAC what the go was here? We are using 3850's and having the same issue, we were running 3.7.5, but we have bumped some to 16.3.5b/16.3.6 and I'm seeing the same behaviour there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to avoid turning on reauth timers if possible as well.....&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 07:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368758#M549717</guid>
      <dc:creator>ayden_beeson86</dc:creator>
      <dc:date>2018-04-19T07:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368784#M549718</link>
      <description>&lt;P&gt;Hi Ayden&lt;/P&gt;
&lt;P&gt;I'm working with TAC on this just now. They requested a TCPdump from the psn node to confirm ISE wasn't receiving any interim updates from the 3650s. The capture confirmed that the switches only send start/stop. I'll keep thread updated.&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 07:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368784#M549718</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2018-04-19T07:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368791#M549719</link>
      <description>&lt;P&gt;Thanks Andy,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Keep me posted, let me know if you need another site with similar results!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Ayden&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 07:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3368791#M549719</guid>
      <dc:creator>ayden_beeson86</dc:creator>
      <dc:date>2018-04-19T07:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3409532#M549720</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm having the exact same issue, do you have any prograss in your case ?&lt;BR /&gt;Thanks,&lt;BR /&gt;Snir</description>
      <pubDate>Tue, 03 Jul 2018 09:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3409532#M549720</guid>
      <dc:creator>snir_orlanczyk</dc:creator>
      <dc:date>2018-07-03T09:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3409544#M549721</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Not as yet. I'm still working with TAC on this. They responded through my Cisco partner that they couldn't replicate this issue&amp;nbsp;with the same switch model/ios - I'm not sure if they were using new style ibns 2.0 config on their test. I'll keep the thread updated with any progress.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 10:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3409544#M549721</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2018-07-03T10:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3675165#M549722</link>
      <description>&lt;P&gt;Worked through this with TAC (for the testing I used an eval ISE 2.3 patch 3 – the authenticator switch used was a WS-C3650-48PD). We found the following behaviour with different ios versions and interim accounting enabled “aaa accounting update periodic 2”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;03.07.05E&lt;/STRONG&gt; – switch “debug radius accounting” shows no interim accounting packets sent – only start/stop. TAC said there were no plans to fix interim accounting for 3.7.X.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;03.06.08E&lt;/STRONG&gt; – switch “debug radius accounting” shows interim accounting packets being sent at the time intervals specified. TAC gave the bug id for this fix as CSCus21944 – although the notes for this bug only mention 4506/4510 models&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;16.3.6&lt;/STRONG&gt; – I have a number of WS-C3650-48FQM switches running this ios on the production network and they also don’t send interim accounting packets – only start/stop. TAC said that interim accounting is resolved in 16.9.1 – I don’t have a bug id for this and I haven’t tested this release myself.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With the cat3k (running 03.06.08E) now sending interim accounting to ISE I found the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ISE doesn't display accounting interim update packets on its reports page (&lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Endpoint and Users &amp;gt; RADIUS Accounting&lt;/STRONG&gt;) even though the switch sends interim updates and the switch receives a response from ISE.&lt;/LI&gt;
&lt;LI&gt;When I do an endpoint debug on ISE (&lt;STRONG&gt;Operations &amp;gt; Diagnostic Tools &amp;gt; Endpoint Debug&lt;/STRONG&gt;) I can see ISE receiving interim updates for a given client.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC confirmed that this is due to “bug” CSCve85449 – this behaviour is to prevent ISE getting overwhelmed with accounting packets. Although interim accounting doesn’t appear in ISE reports, ISE still uses the interim accounting packets to keep Active Endpoints up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 08:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3675165#M549722</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2018-07-26T08:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3691914#M549723</link>
      <description>&lt;P&gt;Thanks Andy that is awesome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently updated to 16.8.1a (and soon to 16.9.1, its in QA) and it looks to be fixed there, the few we are running those versions on are now sending accounting interim updates correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great news all around.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 06:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3691914#M549723</guid>
      <dc:creator>ayden_beeson86</dc:creator>
      <dc:date>2018-08-21T06:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3691991#M549724</link>
      <description>&lt;P&gt;Thanks for that Ayden. I'm testing 16.9.1 at the moment and interim accounting works as expected - interesting to know it also works with 16.8.1a&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 08:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3691991#M549724</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2018-08-21T08:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3729906#M549725</link>
      <description>&lt;P&gt;Installed 16.9.1 on 3850 and getting Interim accounting.&lt;/P&gt;
&lt;P&gt;I requested Cisco update the bug ID and list the broken and fixed versions, and add the bug to the release notes.&lt;/P&gt;
&lt;P&gt;One thing is now getting interim updates way more often than we should with either of these statements.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;aaa accounting update periodic 240 &lt;/P&gt;
&lt;P&gt;aaa accounting update periodic newinfo 240&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eg for the same endpoint&lt;/P&gt;
&lt;P&gt;11:05:24 AM&lt;BR /&gt;10:58:23 AM&lt;BR /&gt;10:39:38 AM&lt;BR /&gt;10:34:36 AM&lt;BR /&gt;10:29:21 AM&lt;BR /&gt;10:23:28 AM&lt;BR /&gt;10:12:51 AM&lt;BR /&gt;10:08:53 AM&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 15:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3729906#M549725</guid>
      <dc:creator>Garry Cross</dc:creator>
      <dc:date>2018-10-22T15:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3729914#M549726</link>
      <description>If you debug the radius accounting packets for this endpoint, are the message details changing?  "newinfo" obviously won't follow the 240 minute interim timer that is set.  One example, I've seen NADs send sub second changes because it is seeing two ip's on the same MAC. &lt;BR /&gt;&lt;BR /&gt;It would be interesting to see what is changing in the acct packets that is forcing the update, if anything.  &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 22 Oct 2018 15:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3729914#M549726</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-22T15:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE active sessions with no interim accounting support</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3730103#M549727</link>
      <description>&lt;P&gt;Can't seem to figure out how to do debug aaa accounting on 16.9.1 and get output.&lt;/P&gt;
&lt;P&gt;I watch an engineer once and he did some stuff and used show platform software trace message smd switch active R0, but I can't seem to get what he got.&lt;/P&gt;
&lt;P&gt;Anyway a capture shows that sometimes the update contains a Framed IP and sometimes it doesn't. Otherwise the only difference is in the bytes and packets, timestamp etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 19:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-active-sessions-with-no-interim-accounting-support/m-p/3730103#M549727</guid>
      <dc:creator>Garry Cross</dc:creator>
      <dc:date>2018-10-22T19:09:09Z</dc:date>
    </item>
  </channel>
</rss>

