<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE: Logging target in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-logging-target/m-p/4715631#M578054</link>
    <description>&lt;P&gt;How does ISE function if "&lt;SPAN&gt;Traffic between zones is prohibited."?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The logs are sent to all configured logging targets directly from each PSN.&amp;nbsp; I am not aware of a way to exclude certain log collectors on a per PSN basis.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2022 13:36:56 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2022-11-03T13:36:56Z</dc:date>
    <item>
      <title>ISE: Logging target</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-logging-target/m-p/4715456#M578049</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a cluster deployment of 6 ISEs.&lt;/P&gt;
&lt;P&gt;We have 4 zones in separate DCs with 1 PSN per zone and one Syslog collector per zone.&amp;nbsp;Traffic between zones is prohibited.&lt;/P&gt;
&lt;P&gt;Z1P &amp;gt; 1 PSN / 1 Syslog&lt;/P&gt;
&lt;P&gt;Z2P&amp;gt; 1 PSN / 1 PAN Primaire Mnt Secondaire / 1 Syslog&lt;/P&gt;
&lt;P&gt;Z1N &amp;gt; 1 PSN / 1 PAN Secondaire Mnt Primaire / 1 Syslog&lt;/P&gt;
&lt;P&gt;Z1P &amp;gt; 1 PSN / 1 Syslog&lt;/P&gt;
&lt;P&gt;We're looking for a solution so that the ISE logs reach their zone's Syslog collector without sending the flows four times.&lt;/P&gt;
&lt;P&gt;Is there a solution to this problem in an ISE version of 2.4 or 2.7?&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 09:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-logging-target/m-p/4715456#M578049</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-11-03T09:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: Logging target</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-logging-target/m-p/4715631#M578054</link>
      <description>&lt;P&gt;How does ISE function if "&lt;SPAN&gt;Traffic between zones is prohibited."?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The logs are sent to all configured logging targets directly from each PSN.&amp;nbsp; I am not aware of a way to exclude certain log collectors on a per PSN basis.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 13:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-logging-target/m-p/4715631#M578054</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-11-03T13:36:56Z</dc:date>
    </item>
  </channel>
</rss>

