<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE context visibility in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066221#M559640</link>
    <description>&lt;P&gt;Hi Anurag,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that after I added an endpoint (PC with MAB) to the switch that doesn't appear to the CV and the command suggested by you , now the switch is shown to the CV. But what about the routers ? I cannot configure a endpoint to a port of a router ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Apr 2020 08:56:13 GMT</pubDate>
    <dc:creator>armandi10</dc:creator>
    <dc:date>2020-04-15T08:56:13Z</dc:date>
    <item>
      <title>ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4065897#M559607</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have set up a Cisco ISE 2.6 patch and we started to do the configuration. One of the thing we have see these times is that some of network devices are not shown in the Context Visibility and some are shown. We are using Radius for the Administration of the devices and the authentication process works. Anyone has had the same problem ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Armand&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 22:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4065897#M559607</guid>
      <dc:creator>ArmandXhafa3045</dc:creator>
      <dc:date>2020-04-14T22:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4065987#M559614</link>
      <description>Hi, starting by verifying the accounting config on the NAD devices and&lt;BR /&gt;interim accounting is enabled. Also, make sure that accounting messages are&lt;BR /&gt;received by ISE.&lt;BR /&gt;&lt;BR /&gt;I am assuming that your NAD devices are added to ISE already.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Apr 2020 02:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4065987#M559614</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-04-15T02:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066133#M559627</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for replying. Here are the command for accounting i have used:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group ISE-AAA local&lt;BR /&gt;aaa authentication dot1x default group ISE-AAA local&lt;BR /&gt;aaa authorization exec default local if-authenticated&lt;BR /&gt;aaa authorization network auth-list group ISE-AAA local&lt;BR /&gt;aaa authorization auth-proxy default group ISE-AAA local&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE-AAA&lt;BR /&gt;aaa accounting network default start-stop group ISE-AAA&lt;BR /&gt;aaa accounting system default start-stop group ISE-AAA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server dead-criteria time 30 tries 3&lt;BR /&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646 key 7 15200A080D3F386879616663&lt;BR /&gt;radius-server deadtime 10&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it doesn't work. May have to add something else ?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 06:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066133#M559627</guid>
      <dc:creator>ArmandXhafa3045</dc:creator>
      <dc:date>2020-04-15T06:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066175#M559633</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1033273"&gt;@ArmandXhafa3045&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest you add accounting exec command as well, since you are doing Device Administration as well:&lt;/P&gt;
&lt;P&gt;aaa accounting exec default start-stop group SERVER-GROUP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Secondly, I would compare the device which is showing in CV (Context Visibility) and the one not showing.&lt;/P&gt;
&lt;P&gt;Check things like:&lt;/P&gt;
&lt;P&gt;Are any endpoints connecting to the working and not connecting to the non-working ones?&lt;/P&gt;
&lt;P&gt;Does the non-working device ever show up in CV?&lt;/P&gt;
&lt;P&gt;Does the previously visible device no longer show up in CV?&lt;/P&gt;
&lt;P&gt;Are there any configuration discrepancies between the working and non-working ones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 07:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066175#M559633</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-04-15T07:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066221#M559640</link>
      <description>&lt;P&gt;Hi Anurag,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that after I added an endpoint (PC with MAB) to the switch that doesn't appear to the CV and the command suggested by you , now the switch is shown to the CV. But what about the routers ? I cannot configure a endpoint to a port of a router ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 08:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066221#M559640</guid>
      <dc:creator>armandi10</dc:creator>
      <dc:date>2020-04-15T08:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE context visibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066240#M559642</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/349556"&gt;@armandi10&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good to know.&lt;/P&gt;
&lt;P&gt;Routers won't show up there because you can't connect an endpoint to a router. You can only manage a router (device administration).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to understand that CV is not a place for checking the devices configured in ISE. It's just a place (talking about NADs) to show which devices have endpoints connected etc. By endpoints, we mean dot1x and MAB users.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check the complete list of devices under Administration -&amp;gt; Network Devices. To get an activity report on a device, you can refer to the different Reports under Operations.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 09:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-context-visibility/m-p/4066240#M559642</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-04-15T09:33:30Z</dc:date>
    </item>
  </channel>
</rss>

