<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - missing IP informations from endpoint in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4725227#M578405</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654"&gt;@StefanSeubert44470&lt;/a&gt; That is possible. You may try tweaking the settings.&lt;/P&gt;
&lt;P&gt;One reason I asked for packet captures is that we saw issues in the past that the switches were not sending accounting interim updates if they were configured to. You may also check the RADIUS accounting reports in ISE and/or tail the localStore log of the ISE PSN.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Nov 2022 12:42:55 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2022-11-21T12:42:55Z</dc:date>
    <item>
      <title>ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4723303#M578308</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;we see partial endpoints that do not contain IP information in the ISE.&lt;BR /&gt;If we check the endpoint information on the switch with&lt;BR /&gt;show auth session int gig3/0/3 detail,&lt;BR /&gt;the IP information is displayed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StefanSeubert44470_2-1668702585299.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/168327i9570BAEAE6692DF0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StefanSeubert44470_2-1668702585299.png" alt="StefanSeubert44470_2-1668702585299.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StefanSeubert44470_1-1668702547601.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/168326i3785F92CD1901711/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StefanSeubert44470_1-1668702547601.png" alt="StefanSeubert44470_1-1668702547601.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Unfortunately we have some profiling policies that make a VLAN decision based on the IP address of the endpoint.&lt;BR /&gt;Sometimes it helps to switch the port off and on, but of course this is not very practical as the clients are not online for quite a while.&lt;/P&gt;&lt;P&gt;I suspect that at the time the device is authenticated, the information is not available. Strangely enough, this also happens with endpoints that are re-authenticated. A CoA does not help here.&lt;BR /&gt;In the example we have MAB authentication, no 802.1x and the endpoint is statically addressed.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 16:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4723303#M578308</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-11-17T16:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4723336#M578315</link>
      <description>&lt;P&gt;Can you help me understand why you would try to tie a policy into an IP address?&amp;nbsp; If you're not setting the VLAN with a policy, then you'd be relying on the access vlan number assigned to the port, tied into a subnet on a layer 3 switch.&amp;nbsp; We've never used IP Addresses, in fact we try to avoid using the access vlan and try to tie all policies to vlan group names so the actual VLAN is a step away from the VLAN ID: drop a laptop into CORP in all switches and the VLAN group assignment puts it on the correct VLAN Id for that switch, no IP Address investigation required.&amp;nbsp; Then if someone changes VLANs, they just update the switch .. simple... easy .. and future-proof in case of any subnet changes or segmentation re-evaluations. I'd love to know why you need the IP address for policy assignment.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 17:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4723336#M578315</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2022-11-17T17:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724174#M578366</link>
      <description>&lt;P&gt;At the moment we migrate from Extreme NAC to ISE. In our network are a lot of different network endpoints. Round about 80% are in the correct VLAN but the last 20% are in the historical default VLAN.&lt;/P&gt;&lt;P&gt;Sometimes devices are not in the correct VLAN and use static ip addresses.&amp;nbsp;&lt;BR /&gt;We saw after migrating the first switches that we have thinclients in three different vlans. Our thin client profile move the devices to the correct VLAN but without a reboot the device don’t asked for a new ip.&amp;nbsp;&lt;BR /&gt;Another example is, that we will automate the onboarding process and saw that we have devices with the same MAC Vendor. Digiboard is a good example. Some devices are medical devices some are building automation. So we need more informations from the device to identify it correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 22:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724174#M578366</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-11-18T22:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724432#M578385</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654"&gt;@StefanSeubert44470&lt;/a&gt; Please check and confirm (1) that the switch is sending RADIUS accounting requests to ISE, and (2) that the frequency of the account requests is lower than the setting of &lt;SPAN title="Ignore repeated accounting updates within"&gt;Ignore repeated accounting updates within&lt;/SPAN&gt; N seconds. Good to perform packet captures of the RADIUS transactions to ensure the switch is sending the accounting requests, which may carry the IP updates.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-11-19 at 18.09.49.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/168540i44098AA2EB307F7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-11-19 at 18.09.49.png" alt="Screenshot 2022-11-19 at 18.09.49.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Nov 2022 02:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724432#M578385</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-20T02:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724823#M578401</link>
      <description>&lt;P&gt;Hi Hslai,&lt;/P&gt;&lt;P&gt;accounting is enabled on the switches with th edefault setting&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo periodic 2880&lt;/P&gt;&lt;P&gt;The ignore repeated accounting settings are also on the default value 5 seconds.&lt;/P&gt;&lt;P&gt;Could it be that the 5 seconds are too long?&lt;BR /&gt;So for example, device goes online, IP was not yet determined by device tarcking, MAB authentication is performed and after e.g. 2 or 3 seconds the switch would send an update, which is ignored because only after 5 seconds updates are evaluated by the ISE?&lt;/P&gt;&lt;P&gt;BR Stefan&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 08:31:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724823#M578401</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-11-21T08:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724827#M578402</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654"&gt;@StefanSeubert44470&lt;/a&gt; do you have device tracking and dhcp snooping configured on the switches?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 08:38:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4724827#M578402</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-21T08:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4725227#M578405</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1081654"&gt;@StefanSeubert44470&lt;/a&gt; That is possible. You may try tweaking the settings.&lt;/P&gt;
&lt;P&gt;One reason I asked for packet captures is that we saw issues in the past that the switches were not sending accounting interim updates if they were configured to. You may also check the RADIUS accounting reports in ISE and/or tail the localStore log of the ISE PSN.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 12:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4725227#M578405</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-21T12:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - missing IP informations from endpoint</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4725921#M578423</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;device-tracking and dhcp snooping is configured. I read your linked documentation and the only thing which is missing is the device-sensor configuration. We don´t have the filter lists active and some commands are not available.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;i´ll check if i can find a device where the issue is&amp;nbsp;reproducible and start a packet capture. If it is that the switch sends out the ip informations i´ll reduce the 5 seconds to a lower setting.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 14:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-missing-ip-informations-from-endpoint/m-p/4725921#M578423</guid>
      <dc:creator>StefanSeubert44470</dc:creator>
      <dc:date>2022-11-22T14:03:37Z</dc:date>
    </item>
  </channel>
</rss>

