<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Account blocking when making API requests in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616017#M574931</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE blocks nominative accounts used to launch scripts making API requests with many connections and simultaneous actions (there are about 300 devices concerned).&amp;nbsp;It's always have to do the unlocking manually.&lt;/P&gt;
&lt;P&gt;The question is whether the blocking comes from the number of connections per second or the number of actions per second and what to do to bypass this blocking (configuration or specific account to be provided?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Objet&amp;nbsp;:&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt; Information regarding account locked&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Account has been locked for internal user, userid A*******-adm.&lt;BR /&gt;This account has been locked. For this account to become unlocked, please contact your IT helpdesk.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE version is 2.4.0.357&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;José&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2022 08:39:42 GMT</pubDate>
    <dc:creator>jds5</dc:creator>
    <dc:date>2022-05-24T08:39:42Z</dc:date>
    <item>
      <title>Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616017#M574931</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE blocks nominative accounts used to launch scripts making API requests with many connections and simultaneous actions (there are about 300 devices concerned).&amp;nbsp;It's always have to do the unlocking manually.&lt;/P&gt;
&lt;P&gt;The question is whether the blocking comes from the number of connections per second or the number of actions per second and what to do to bypass this blocking (configuration or specific account to be provided?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Objet&amp;nbsp;:&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt; Information regarding account locked&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Account has been locked for internal user, userid A*******-adm.&lt;BR /&gt;This account has been locked. For this account to become unlocked, please contact your IT helpdesk.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE version is 2.4.0.357&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;José&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 08:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616017#M574931</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-05-24T08:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616489#M574934</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone confronted this type of issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tkx,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:27:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616489#M574934</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-05-24T13:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616865#M574945</link>
      <description>&lt;P&gt;The account locking is likely due to the Lock/Suspend Settings configuration found on the &lt;EM&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Admin Access &amp;gt; Authentication &amp;gt; Lock/Suspend Settings&lt;/STRONG&gt;&lt;/EM&gt; page.&lt;/P&gt;
&lt;P&gt;Have you checked the ISE logs or reports for repeated failed authentications generated by the API calls?&lt;/P&gt;
&lt;P&gt;How many concurrent ERS API calls do you have? As per the &lt;A href="https://cs.co/ise-scale" target="_blank"&gt;https://cs.co/ise-scale&lt;/A&gt; guide, ISE supports a maximum of 100 concurrent API connections.&lt;/P&gt;
&lt;P&gt;There are also various API bugs fixed in patches for 2.4. If you have not already done so, you might upgrade to the latest patch to see if the issue is resolved.&lt;/P&gt;
&lt;P&gt;You should also be aware that &lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-743964.html" target="_blank" rel="noopener"&gt;ISE 2.4 reaches End of Support in December 2022&lt;/A&gt;. You should consider upgrading to a more recent version to ensure you can receive support from Cisco TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 23:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4616865#M574945</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-05-24T23:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4620514#M575064</link>
      <description>&lt;P&gt;Thanks Greg for this information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To be more specific, the exact requirement is for API requests made to Endpoints that include ISE authentication but do not relate to the ISE directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4620514#M575064</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-05-30T12:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4620567#M575073</link>
      <description>&lt;P&gt;I do not understand what API requests you are talking about and from what to what.&lt;/P&gt;
&lt;P&gt;What API?&lt;/P&gt;
&lt;P&gt;What scenario are you trying to do? &lt;/P&gt;
&lt;P&gt;Please see &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/m-p/3704356#U3704356"&gt;&lt;/LI-MESSAGE&gt; so we have enough details to understand the problem and potentially reproduce it.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 13:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4620567#M575073</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-05-30T13:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Account blocking when making API requests</title>
      <link>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4621921#M575119</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_manage_users_external_id_stores.html#id_111765" target="_self"&gt;User Authentication Settings&lt;/A&gt;&amp;nbsp;says,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol"&gt;Lock/Suspend Account with Incorrect Login Attempts&lt;/SPAN&gt;: You can use this option to suspend or lock an account if the login attempt failed for the specified number of times. The valid range is from 3 to 20.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;The &lt;SPAN class="ph uicontrol"&gt;Account Disable Policy&lt;/SPAN&gt; tab is where you configure rules about when to disable an existing user account. &lt;SPAN class="ph"&gt;See &lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_manage_users_external_id_stores.html#id_18877" target="_blank"&gt;Disable User Accounts Globally&lt;/A&gt; for more information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 00:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/account-blocking-when-making-api-requests/m-p/4621921#M575119</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-01T00:09:38Z</dc:date>
    </item>
  </channel>
</rss>

