<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Passive Identity Agent error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4697276#M577526</link>
    <description>&lt;P&gt;Hi Thomas&lt;/P&gt;
&lt;P&gt;Which logs would you expect?&lt;BR /&gt;On the Domain Controller, the line is repeated constantly within the file: CiscoISEPICAgent.&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Thomas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Oct 2022 18:35:43 GMT</pubDate>
    <dc:creator>tkiel</dc:creator>
    <dc:date>2022-10-02T18:35:43Z</dc:date>
    <item>
      <title>Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4693658#M577386</link>
      <description>&lt;P&gt;ISE PIC Agent does not return any user/IP to ISE, keeps getting this error in CiscoISEPICAgent file:&lt;BR /&gt;022-09-26 01:10:29,053 ERROR - Rest Client, Error sending mapping {user=dummyMapping, ip=192.168.12.32} to &lt;A href="https://S-CISCOISE02.domain.local:9095" target="_blank" rel="noopener"&gt;https://S-CISCOISE02.domain.local:9095&lt;/A&gt; : String was not recognized as a valid DateTime.&lt;/P&gt;
&lt;P&gt;anyone got a hint?&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 10:34:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4693658#M577386</guid>
      <dc:creator>tkiel</dc:creator>
      <dc:date>2022-09-26T10:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4693668#M577388</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317172"&gt;@tkiel&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;ISE PIC Agent does not return any user/IP to ISE, keeps getting this error in CiscoISEPICAgent file:&lt;BR /&gt;022-09-26 01:10:29,053 ERROR - Rest Client, Error sending mapping {user=dummyMapping, ip=192.168.12.32} to &lt;A href="https://S-CISCOISE02.domain.local:9095" target="_blank" rel="noopener"&gt;https://S-CISCOISE02.domain.local:9095&lt;/A&gt; : String was not recognized as a valid DateTime.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.flying-together.org/" target="_self"&gt;United Airlines Flying Together&lt;/A&gt;&lt;/P&gt;&lt;P&gt;anyone got a hint?&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Thomas&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thankful for the little by little useful exercise. Has conclusively the ordinary impact.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 05:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4693668#M577388</guid>
      <dc:creator>barrykaauamo</dc:creator>
      <dc:date>2022-09-27T05:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4697146#M577518</link>
      <description>&lt;P&gt;Call TAC to troubleshoot since you did not offer any details, logs, etc.&lt;/P&gt;
&lt;P&gt;See &lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt; for more details to provide next time.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 22:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4697146#M577518</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-10-01T22:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4697276#M577526</link>
      <description>&lt;P&gt;Hi Thomas&lt;/P&gt;
&lt;P&gt;Which logs would you expect?&lt;BR /&gt;On the Domain Controller, the line is repeated constantly within the file: CiscoISEPICAgent.&lt;/P&gt;
&lt;P&gt;Regards&lt;BR /&gt;Thomas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2022 18:35:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4697276#M577526</guid>
      <dc:creator>tkiel</dc:creator>
      <dc:date>2022-10-02T18:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4727659#M578484</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;
&lt;P&gt;do you have a solution for the problem. We have the same error on a ISE-PIC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 16:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4727659#M578484</guid>
      <dc:creator>m.trautes</dc:creator>
      <dc:date>2022-11-24T16:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4727940#M578493</link>
      <description>&lt;P&gt;Hi Michael&lt;/P&gt;
&lt;P&gt;Unfortunately not yet, it is on my todo list &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;The documentation for troubleshooting ISE-PIC is very limited and this issue is not the connection to domain controller but more likely permissions on the domain controller.&lt;/P&gt;
&lt;P&gt;Best luck&lt;BR /&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 07:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4727940#M578493</guid>
      <dc:creator>tkiel</dc:creator>
      <dc:date>2022-11-25T07:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4763589#M579436</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;
&lt;P&gt;I have the same issue here, and it's giving me this log on every user authentication, any updates so far? &lt;BR /&gt;&lt;BR /&gt;Even TAC seems to be having an issue figuring this one out, at least on the case i opened.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 21:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4763589#M579436</guid>
      <dc:creator>AugustoS.Nunes</dc:creator>
      <dc:date>2023-01-26T21:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4794862#M580505</link>
      <description>&lt;P&gt;Hello AugustoS.Nunes,&lt;/P&gt;
&lt;P&gt;Did you get any news from TAC ?&lt;BR /&gt;I currently facing the same issue.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;CiscoISEPICAgent.log&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Continuing forward event : , Verified it is not a machine account... with username batman&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT ***** Reading Event *******&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT TimeGenerated in DC UTC = 03/15/2023 16:07:02&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT user = batman&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT domain = DCOMICS&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT ip = 192.168.10.212&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT latency = 1,0109357 seconds&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT agentTimeUTC , 03/15/2023 16:07:03&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Domain Controller 192.168.10.211, EVT Received Time:15/03/2023 16:07:02, Latency:1,0109357, Computer:ad01.dcomics.lan, User:batman, Domain:DCOMICS, IP:192.168.10.212&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 DEBUG - Rest Client, Sending mapping to &lt;A href="https://isepic.dcomics.lan:9095" target="_blank" rel="noopener"&gt;https://isepic.dcomics.lan:9095&lt;/A&gt;: user=batman, ip=192.168.10.212&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,829 ERROR - Rest Client, Error sending mapping {user=batman, ip=192.168.10.212} to &lt;A href="https://isepic.dcomics.lan:9095" target="_blank" rel="noopener"&gt;https://isepic.dcomics.lan:9095&lt;/A&gt; : String was not recognized as a valid DateTime.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;FONT size="4"&gt;passiveid-agent.log&lt;/FONT&gt;&lt;/STRONG&gt;&lt;EM&gt;&lt;BR /&gt;2023-03-15 16:07:03,787 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- REST request arrived from client with hostname: ad01.dcomics.lan, ip: 192.168.10.211&lt;BR /&gt;2023-03-15 16:07:03,787 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Looking for Agent in configuration, with ip 192.168.10.211 or hostname ad01.dcomics.lan.&lt;BR /&gt;2023-03-15 16:07:03,788 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Current Agent hostname/ip in config: ad01.dcomics.lan&lt;BR /&gt;2023-03-15 16:07:03,792 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Received login event. Identity Mapping.probe = Agent , dc-host = /192.168.10.211 , Identity Mapping.server = isepic , event-operation-type = ADD , &lt;BR /&gt;2023-03-15 16:07:03,792 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Validating incoming loging event...&lt;BR /&gt;2023-03-15 16:07:03,792 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- AgentTime 1678896423 DCTime 1678896422 ISETime 1678896423&lt;BR /&gt;2023-03-15 16:07:03,792 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Building login event to be published to session directory.&lt;BR /&gt;2023-03-15 16:07:03,792 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- retrieving user's additional informaion from Active Directory.&lt;BR /&gt;2023-03-15 16:07:03,833 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- recording login event into local log.&lt;BR /&gt;2023-03-15 16:07:03,836 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Forwarded login event to session directory. Identity Mapping.id-src-first-port = -1 , Identity Mapping.dc-domainname = dcomics.lan , Identity Mapping.id-src-port-start = -1 , Identity Mapping.probe = Agent , Identity Mapping.id-src-port-end = -1 , Identity Mapping.event-user-name = batman , Identity Mapping.dc-host = /192.168.10.211 , Identity Mapping.agentId =&amp;nbsp; , Identity Mapping.server = isepic , Identity Mapping.event-ip-address = 192.168.10.212 , &lt;BR /&gt;2023-03-15 16:07:03,836 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Publishing identity mapping event. Identity Mapping.id-src-first-port = -1 , Identity Mapping.dc-domainname = dcomics.lan , Identity Mapping.id-src-port-start = -1 , Identity Mapping.probe = Agent , Identity Mapping.id-src-port-end = -1 , Identity Mapping.event-user-name = batman , Identity Mapping.dc-host = /192.168.10.211 , Identity Mapping.agentId =&amp;nbsp; , Identity Mapping.server = isepic , event-operation-type = ADD , Identity Mapping.event-ip-address = 192.168.10.212 , &lt;BR /&gt;2023-03-15 16:07:03,836 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Details 192.168.10.212&lt;BR /&gt;2023-03-15 16:07:03,836 DEBUG&amp;nbsp; [Grizzly-worker(3)][[]] com.cisco.idc.agent-probe- Going to publish login event...&lt;BR /&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;On ISE-PIC, live Sessions stays empty...&lt;/P&gt;
&lt;P&gt;Thank you !&lt;/P&gt;
&lt;P&gt;[Edit]Added passiveid-agent.log from ISE-PIC&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 16:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4794862#M580505</guid>
      <dc:creator>stephane.merl</dc:creator>
      <dc:date>2023-03-15T16:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4794899#M580509</link>
      <description>&lt;P&gt;Hello Stephane,&lt;/P&gt;&lt;P&gt;I am on my personal account right now, but yes!&lt;BR /&gt;&lt;BR /&gt;The issue seems to be with the Endpoint Check on ISE-PIC and FMC 7.2 which started dealing with "Unreachable" endpoints sent by ISE, basically ISE check's if the endpoint is active with this feature enabled (by default) through WMI and if isn't able to get a response comes back as "Unreachable" and starting on FMC 7.2, it "discards" this users and don't add them to the Active Sessions database.&lt;BR /&gt;&lt;BR /&gt;The only two ways to resolve this seams to be from disabling the Endpoint Check on ISE-PIC (Providers&amp;gt;Endpoint Check) or let ISE-PIC connect through WMI on the workstations. We disabled the endpoint check and everything in fine now!&lt;BR /&gt;&lt;BR /&gt;Also in regards to this log on the ISE Agent, a patch has to by applied to fix this since seems to be a bug, haven't try it yet but it's on our roadmap to do!&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,829 ERROR - Rest Client, Error sending mapping {user=batman, ip=192.168.10.212} to &lt;A href="https://isepic.dcomics.lan:9095" target="_blank" rel="noopener nofollow noreferrer"&gt;https://isepic.dcomics.lan:9095&lt;/A&gt; : String was not recognized as a valid DateTime.&lt;BR /&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;SPAN class=""&gt;CSCwd45843&lt;/SPAN&gt; &amp;gt; &lt;A href="https://software.cisco.com/download/home/283801620/type/283802505/release/HP-CSCwd45843" target="_blank" rel="noopener"&gt;https://software.cisco.com/download/home/283801620/type/283802505/release/HP-CSCwd45843&lt;/A&gt;&lt;BR /&gt;Confirmed by TAC that can by applied on ISE-PIC even if it's an ISE download.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 17:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/4794899#M580509</guid>
      <dc:creator>ASN</dc:creator>
      <dc:date>2023-03-15T17:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Passive Identity Agent error</title>
      <link>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/5154706#M591027</link>
      <description>&lt;P&gt;Hello stephane.merl&lt;BR /&gt;&lt;BR /&gt;I hope you doing well.&lt;/P&gt;
&lt;P&gt;Could you tell me how you enable this output logs in&amp;nbsp;&lt;STRONG&gt;CiscoISEPICAgent.log?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 &lt;STRONG&gt;DEBUG - Continuing forward event&lt;/STRONG&gt; : , Verified it is not a machine account... with username batman&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 &lt;STRONG&gt;DEBUG - Domain Controller 192.168.10.211, EVT ***** Reading Event *******&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 &lt;STRONG&gt;DEBUG - Domain Controller&lt;/STRONG&gt; 192.168.10.211,&lt;STRONG&gt; EVT TimeGenerated in DC UTC =&lt;/STRONG&gt; 03/15/2023 16:07:02&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782 &lt;STRONG&gt;DEBUG - Domain Controller&lt;/STRONG&gt; 192.168.10.211, &lt;STRONG&gt;EVT user&lt;/STRONG&gt; = batman&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;2023-03-15 16:07:03,782&lt;STRONG&gt; DEBUG - Domain Controlle&lt;/STRONG&gt;r 192.168.10.211, &lt;STRONG&gt;EVT domain&lt;/STRONG&gt; = DCOMICS&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;best regards!!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Ronei&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 20:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/passive-identity-agent-error/m-p/5154706#M591027</guid>
      <dc:creator>ronei.amorim</dc:creator>
      <dc:date>2024-08-01T20:00:14Z</dc:date>
    </item>
  </channel>
</rss>

