<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and CRL Verification in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4565127#M573261</link>
    <description>&lt;P&gt;Do you have a syslog server that you export logs to?&lt;/P&gt;
&lt;P&gt;You should be seeing log messages about whether or not the CRL was added or failed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145514iD52E9AD91E1B4410/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 04:32:09 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-03-07T04:32:09Z</dc:date>
    <item>
      <title>ISE and CRL Verification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4557133#M572913</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;How can I verify that the CRL is actually downloaded in ISE, and it's being used.&lt;/P&gt;&lt;P&gt;I don't have the option to test with an endpoint that it's computer certificate is revoked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;M.G.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 10:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4557133#M572913</guid>
      <dc:creator>M.G.</dc:creator>
      <dc:date>2022-02-22T10:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and CRL Verification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4557322#M572917</link>
      <description>&lt;P&gt;&lt;SPAN&gt;How can I verify that the CRL is actually downloaded in ISE, and it's being used.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-A couple of quick options to verify:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--The radius detailed live log should contain crl information in Steps data for an authenticated session.&amp;nbsp; Same goes for OCSP if using that.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--Run a tcpdump from one of the PSNs, download pcap, search for http.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 13:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4557322#M572917</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-02-22T13:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and CRL Verification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4565127#M573261</link>
      <description>&lt;P&gt;Do you have a syslog server that you export logs to?&lt;/P&gt;
&lt;P&gt;You should be seeing log messages about whether or not the CRL was added or failed:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145514iD52E9AD91E1B4410/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 04:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4565127#M573261</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-03-07T04:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and CRL Verification</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4565130#M573264</link>
      <description>&lt;P&gt;Thank you Mike and Thomas,&lt;/P&gt;&lt;P&gt;I noticed that if CRL download is not successful you will get an alert in the Dashboard. In addition in the RADIUS live logs (depending on your config for the specific trusted certificate) , after "ISE will continue to CRL verification..." you will see "CRL verification Bypassed" in case CRL download was not successful.&lt;/P&gt;&lt;P&gt;The Syslog server messages clearly showed the addition of the CRL.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;M.G.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 04:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-crl-verification/m-p/4565130#M573264</guid>
      <dc:creator>M.G.</dc:creator>
      <dc:date>2022-03-07T04:49:22Z</dc:date>
    </item>
  </channel>
</rss>

