<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Radius Live log is empty in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839746#M581878</link>
    <description>&lt;P&gt;I have built a 0home virtual lab and it comprises the following devices: CISCO ISE 3.2, Windows Server with CA,AD,DNS roles, and an access switch serving as NTP and NAD.&lt;/P&gt;&lt;P&gt;ISE and AD are integrated.&lt;/P&gt;&lt;P&gt;ISSUE:&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i test RADIUS authentication on the switch using&amp;nbsp; #test aaa group &amp;lt;ISEGROUP&amp;gt; &amp;lt;username&amp;gt; &amp;lt;password1&amp;gt; new-code,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i get&amp;nbsp;User successfully authenticated message which is OK,&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, i can't see the live sessions/logs ISE, It is empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;in an attempt to resolve the issue: I have disabled "&lt;SPAN&gt;ISE Messaging Service", generated CSR for ise messaging, and re-enabled ISE messaging, but it couldn't work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below are my radius configs on the switch: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server radius ISEGROUP&lt;BR /&gt;server name ISESERVER&lt;BR /&gt;ip radius source-interface Vlan1&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group ISEGROUP&lt;BR /&gt;aaa authorization network default group ISEGROUP&lt;BR /&gt;aaa authorization auth-proxy default group ISEGROUP&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting dot1x default start-stop group ISEGROUP&lt;BR /&gt;aaa accounting system default start-stop group ISEGROUP&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;BR /&gt;client 192.168.48.2 server-key PasswordISE&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip name-server 192.168.48.11&lt;BR /&gt;ip device tracking&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;ip address 192.168.48.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 192.168.48.4&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server cache expiry 1&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;radius server ISESERVER&lt;BR /&gt;address ipv4 192.168.48.2 auth-port 1812 acct-port 1813&lt;BR /&gt;key PasswordISE&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 21 May 2023 14:21:02 GMT</pubDate>
    <dc:creator>Tiroyaone72926925</dc:creator>
    <dc:date>2023-05-21T14:21:02Z</dc:date>
    <item>
      <title>Cisco ISE Radius Live log is empty</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839746#M581878</link>
      <description>&lt;P&gt;I have built a 0home virtual lab and it comprises the following devices: CISCO ISE 3.2, Windows Server with CA,AD,DNS roles, and an access switch serving as NTP and NAD.&lt;/P&gt;&lt;P&gt;ISE and AD are integrated.&lt;/P&gt;&lt;P&gt;ISSUE:&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i test RADIUS authentication on the switch using&amp;nbsp; #test aaa group &amp;lt;ISEGROUP&amp;gt; &amp;lt;username&amp;gt; &amp;lt;password1&amp;gt; new-code,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i get&amp;nbsp;User successfully authenticated message which is OK,&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, i can't see the live sessions/logs ISE, It is empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;in an attempt to resolve the issue: I have disabled "&lt;SPAN&gt;ISE Messaging Service", generated CSR for ise messaging, and re-enabled ISE messaging, but it couldn't work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below are my radius configs on the switch: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server radius ISEGROUP&lt;BR /&gt;server name ISESERVER&lt;BR /&gt;ip radius source-interface Vlan1&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group ISEGROUP&lt;BR /&gt;aaa authorization network default group ISEGROUP&lt;BR /&gt;aaa authorization auth-proxy default group ISEGROUP&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting dot1x default start-stop group ISEGROUP&lt;BR /&gt;aaa accounting system default start-stop group ISEGROUP&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;BR /&gt;client 192.168.48.2 server-key PasswordISE&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip name-server 192.168.48.11&lt;BR /&gt;ip device tracking&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;ip address 192.168.48.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 192.168.48.4&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 6 support-multiple&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server attribute 31 send nas-port-detail&lt;BR /&gt;radius-server dead-criteria time 5 tries 3&lt;BR /&gt;radius-server cache expiry 1&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;radius server ISESERVER&lt;BR /&gt;address ipv4 192.168.48.2 auth-port 1812 acct-port 1813&lt;BR /&gt;key PasswordISE&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2023 14:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839746#M581878</guid>
      <dc:creator>Tiroyaone72926925</dc:creator>
      <dc:date>2023-05-21T14:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Radius Live log is empty</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839825#M581880</link>
      <description>&lt;P&gt;Have you checked the time/timezone on the ISE CLI?.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2023 19:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839825#M581880</guid>
      <dc:creator>SHABEEB KUNHIPOCKER</dc:creator>
      <dc:date>2023-05-21T19:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Radius Live log is empty</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839863#M581881</link>
      <description>&lt;P&gt;Are you perhaps suppressing the logging of "username" (sorry ... I had to ask &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging &amp;gt; Collection Filters&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If not - Is this a standalone ISE node?&amp;nbsp; If you're seeing Queue Link Errors in the Alarms Dashboard, then you should generate a CSR to regenerate the internal ISE Root CA cert. That fixes that. It might be related to the Live Logs.&lt;/P&gt;
&lt;P&gt;Have you applied any patch to ISE 3.2 ? Patch 2 is out now - worth trying that.&lt;/P&gt;</description>
      <pubDate>Sun, 21 May 2023 20:40:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4839863#M581881</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-21T20:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Radius Live log is empty</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4840231#M581910</link>
      <description>&lt;P&gt;I am rebuilding the server, I will try your suggestion and get back to you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 13:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-radius-live-log-is-empty/m-p/4840231#M581910</guid>
      <dc:creator>Tiroyaone72926925</dc:creator>
      <dc:date>2023-05-22T13:10:50Z</dc:date>
    </item>
  </channel>
</rss>

