<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 Licence usage exploding in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4111023#M561469</link>
    <description>&lt;P&gt;The bug link you posted shows ISE 2.4 patch 6 in the 'Known Fixed Releases' section and the Release Notes also list that bug ID in the fixes.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/release_notes/b_ise_24_rn.html#id_98767" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/release_notes/b_ise_24_rn.html#id_98767&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have patch 6 or higher installed but the same symptom exists, it is likely not the same root cause as that particular bug. If that's the case, you might need to open a TAC case to investigate in more detail.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jun 2020 22:56:21 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-06-29T22:56:21Z</dc:date>
    <item>
      <title>ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4105511#M561285</link>
      <description>&lt;P&gt;Hello Cisco ISE experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are suffering now the second time from a continous license usage increase&lt;/P&gt;&lt;P&gt;in this important big hospital with around 2500 Radius WLAN Clients:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="License increase.JPG" style="width: 487px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77093i395D3DB9E33B2108/image-size/large?v=v2&amp;amp;px=999" role="button" title="License increase.JPG" alt="License increase.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After crossing our bought 4000 licences I was noticed by an alarm again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last time the trouble went up to around 14.000 just 2 days befor xmas.&lt;/P&gt;&lt;P&gt;Leaving me with only 2 days to go to solve the problem before ISE would stop working.&lt;/P&gt;&lt;P&gt;It took me several days and sleepless nights until&lt;/P&gt;&lt;P&gt;Cisco TAC did the following to cure the situation last time:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perform steps in order:&lt;/P&gt;&lt;P&gt;o&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [3]Purge M&amp;amp;T Operational Data&lt;/P&gt;&lt;P&gt;o&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]Reset M&amp;amp;T Database&lt;/P&gt;&lt;P&gt;Then:&lt;/P&gt;&lt;P&gt;o&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]Reset M&amp;amp;T Session Database&lt;/P&gt;&lt;P&gt;o&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]Rebuild M&amp;amp;T Unusable Indexes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my feeling the ise does not free again licences after WLAN clients disconnect.&lt;/P&gt;&lt;P&gt;Are there any known bugs around this problem ?&lt;/P&gt;&lt;P&gt;And who can advise what to do ?&lt;/P&gt;&lt;P&gt;Is this problem solved meanwhile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise what to do.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Wini&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 10:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4105511#M561285</guid>
      <dc:creator>derobbacher</dc:creator>
      <dc:date>2020-06-18T10:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4106164#M561307</link>
      <description>&lt;P&gt;do you have RADIUS Accounting enabled on your NAS's?&amp;nbsp; And if so, is it working (i.e. shared secret correct and reaching ISE etc.)? It's usually the case that ISE cannot manage the sessions because it has no idea about whether or not the client is still active. RADIUS accounting is your only hope.&lt;/P&gt;
&lt;P&gt;If RADIUS accounting is enabled and working (and Interim-Updates are set to either 0 (for Cisco gear) or perhaps 3600 seconds) then ISE should be getting some information about those sessions at least on that interval)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Failing that, it might be a bug - I think there have been bugs related to ISE no releasing licenses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might also consider whether you have clients that are doing MAC randomization (e.g. newer Android clients) - back in the day it was only Apple that randomized the Wi-Fi MAC address in their &lt;STRONG&gt;probe requests&lt;/STRONG&gt;&amp;nbsp;(which NAC doesn't care about)- but Android and Windows 10 can now randomize even once the Wi-Fi station is associated. That plays all sorts of havoc with NAC solutions that rely on the MAC address of an endpoint being deterministic/stable. I don't know how ISE handles that - I have not looked into it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 07:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4106164#M561307</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-06-19T07:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4107866#M561366</link>
      <description>&lt;P&gt;1) Make sure accounting is set up correctly.You can get accounting report from ISE and compare number of starts to stops&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Get the authentication report from ISE and check for stale connections&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) If you use any ssid with mab , once user passed mab auth it will consume base license.This could be an issue if random users attempt to connect to guest ssid .It is perhaps better to put an extra layer of auth on the guest ssid otherwise some random user can cause base license consumption and also deplete your guest dhcp pool.&lt;/P&gt;&lt;P&gt;4)I dont think Mac randomization will play&amp;nbsp; role here. afaik , mac randomization is used during probing only so I doubt that can be the issue here.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 09:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4107866#M561366</guid>
      <dc:creator>yogesh2009</dc:creator>
      <dc:date>2020-06-23T09:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4107928#M561368</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/169070"&gt;@yogesh2009&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MAC randomization is probably not the cause here but I flagged it because newer Android devices are now allowing the MAC address to be randomized AFTER association - that means, it's no longer used only during probing. Have a quick read of &lt;A href="https://source.android.com/devices/tech/connect/wifi-mac-randomization" target="_self"&gt;this Android article&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Same thing in Windows 10 - &lt;A href="https://winaero.com/blog/enable-random-mac-address-in-windows-10-for-wi-fi-adapter/" target="_self"&gt;have a read here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is already causing some issues with MAB authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Cisco BU wrote a nice article on it - there is a bit mask in the MAC OUI that indicates whether the MAC address is random - the Cisco employee documented a nice filter that you can use in ISE to deal with these use cases - highly recommend you&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/random-mac-address-how-to-deal-with-it-using-ise/ta-p/4049321" target="_self"&gt;check it out&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 12:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4107928#M561368</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-06-23T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108162#M561370</link>
      <description>&lt;P&gt;I'll add something on to this that an astute customer pointed out to me recently. If you set up a WLC, and define the radius servers with the "network user" box checked, then a misconfiguration on the WLAN will send radius accounting starts without even leveraging ISE for authentication. This WLAN was open auth and not 802.1x, but it still sends accounting.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ex. This WLC has two servers under radius accounting servers where "network user" is checked making them the default. The second image shows the misconfiguration. By checking the two boxes "authentication servers = enabled" and "accounting servers = enabled", and not specifying radius server 1 or 2 in the list....This sends radius accounting to ISE and also creates stales endpoint entries in the context visibility DB.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="acct-def.png" style="width: 382px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77425i212F658BCF94653B/image-dimensions/382x293?v=v2" width="382" height="293" role="button" title="acct-def.png" alt="acct-def.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="acct-aaa.png" style="width: 584px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77426i7C2614A07F9E983B/image-dimensions/584x514?v=v2" width="584" height="514" role="button" title="acct-aaa.png" alt="acct-aaa.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 17:36:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108162#M561370</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-23T17:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108178#M561371</link>
      <description>thanks for this useful info. I will definitely check it out.</description>
      <pubDate>Tue, 23 Jun 2020 18:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108178#M561371</guid>
      <dc:creator>yogesh2009</dc:creator>
      <dc:date>2020-06-23T18:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108182#M561372</link>
      <description>&lt;P&gt;I read the article and this could be a&amp;nbsp; possibility .This is why I do not like guest networks are "technically open" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108182#M561372</guid>
      <dc:creator>yogesh2009</dc:creator>
      <dc:date>2020-06-23T18:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108345#M561374</link>
      <description>&lt;P&gt;When I see this kind of config in customer networks I usually uncheck the boxes - I have not seen a valid use case for it, unless somebody is counting the number of unauthenticated guests in a RADIUS server somewhere.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to see what these records look like. Does ISE only care about accounting records for sessions where ISE was involved in the Authentication? I guess Accounting without the other two initial &lt;STRONG&gt;AA_&lt;/STRONG&gt; 's doesn't make much sense.&lt;/P&gt;
&lt;P&gt;I would have thought that ISE would at least log the accounting records (Acct Start) and then close off the record when the Acct Stop came in. In that case there should be no licensing confusion.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 22:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108345#M561374</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-06-23T22:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108391#M561376</link>
      <description>It might but I'm not 100% certain on how it behaves with this sort of misconfiguration. It needs some analysis in a lab since in this case the impact on licensing in production was not the focus but rather the massive growth of the endpoint DB. It certainly generates a lot of useless mac/endpoint entries in context visibility if there is high turn over of guests.</description>
      <pubDate>Wed, 24 Jun 2020 01:15:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4108391#M561376</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-06-24T01:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4109754#M561420</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;thank You for Your Feedback.&lt;/P&gt;&lt;P&gt;I'm not convinced, sorry.&lt;/P&gt;&lt;P&gt;Isn't this maybe Cisco Bug CSCvj50257 ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj50257" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj50257&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Symptom:&lt;BR /&gt;&lt;/STRONG&gt;Mismatch in active endpoint counter and Live Sessions&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Conditions:&lt;/STRONG&gt;&lt;BR /&gt;--- ISE 2.3 patch 2 reset and synchronized context visibility&lt;BR /&gt;--- ISE 2.4 clean install&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;None&lt;/P&gt;&lt;DIV class="lastModifiedHelp"&gt;Last Modified:&lt;/DIV&gt;&lt;DIV class="lstMdfDate"&gt;Jun 8,2020&lt;/DIV&gt;&lt;DIV class="statusInfo"&gt;&lt;DIV class="statusHelp"&gt;Status:&lt;/DIV&gt;&lt;DIV class="status"&gt;Fixed&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For me it Looks like the Problem is fixed (Status Fixed)&lt;/P&gt;&lt;P&gt;But I cannot find information about which ISE Patch or SW-Release fixed this Problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please point me to the solution for this bug ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You very much&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Wini&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 09:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4109754#M561420</guid>
      <dc:creator>derobbacher</dc:creator>
      <dc:date>2020-06-26T09:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4111023#M561469</link>
      <description>&lt;P&gt;The bug link you posted shows ISE 2.4 patch 6 in the 'Known Fixed Releases' section and the Release Notes also list that bug ID in the fixes.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/release_notes/b_ise_24_rn.html#id_98767" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/release_notes/b_ise_24_rn.html#id_98767&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have patch 6 or higher installed but the same symptom exists, it is likely not the same root cause as that particular bug. If that's the case, you might need to open a TAC case to investigate in more detail.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 22:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4111023#M561469</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-06-29T22:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Licence usage exploding</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4112403#M561503</link>
      <description>&lt;P&gt;BTW stale sessions on ISE should be removed after a maximum of 5 days&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture.html#anc7&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/support/docs/security/identity-services-engine/215419-ise-session-management-and-posture-02.jpeg" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 12:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-licence-usage-exploding/m-p/4112403#M561503</guid>
      <dc:creator>neil.woodhouse</dc:creator>
      <dc:date>2020-07-02T12:17:05Z</dc:date>
    </item>
  </channel>
</rss>

