<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TLSVersion and TLSCipher in syslog message in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871825#M582796</link>
    <description>&lt;P&gt;If you go into you're remote logging target config, the default is 1024 which is too low to get the full log. If you try increasing this to 8192, you should get all the fields&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2023 14:56:59 GMT</pubDate>
    <dc:creator>M. Wisely</dc:creator>
    <dc:date>2023-07-11T14:56:59Z</dc:date>
    <item>
      <title>TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871148#M582758</link>
      <description>&lt;P&gt;I am running ISE 3.0 patch-7 and I use certificate based dot1x for authentication.&lt;/P&gt;&lt;P&gt;When the device is successfully authenticated, I see TLSversion and TLSCipher in the ISE log.&amp;nbsp; I also configure the ISE to send these messages to external syslog server; however, I capture the traffic on the ISE for syslog message and I can confirm that syslog messages from the ISE to external syslog server do NOT contain either TLSVersion or TLSCipher.&amp;nbsp; I've opened a TAC case with Cisco to investigate.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this expected?&amp;nbsp; TIA&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871148#M582758</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-07-10T15:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871570#M582783</link>
      <description>&lt;P&gt;We're running 3.1p7 and I can see the TLSversion and TLSCipher fields in logs forwarded to our external syslog server.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 09:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871570#M582783</guid>
      <dc:creator>M. Wisely</dc:creator>
      <dc:date>2023-07-11T09:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871613#M582784</link>
      <description>&lt;P&gt;The way logs are sent to an external syslog server depends on the logging categories (Administration &amp;gt; System &amp;gt; Logging) referring the external logging target. There are predefined logging categories on ISE (Failed attempts, Passed authentication, etc) which defines the format in which logs would be sent to various logging targets.&lt;/P&gt;
&lt;P&gt;ISE doesn't log TLS packet dump in it's log files itself so don't think it would sent the TLS version in dot1x authentication to external syslog server.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 10:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871613#M582784</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-07-11T10:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871812#M582795</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323120"&gt;@M. Wisely&lt;/a&gt;:&amp;nbsp; can you share the tcpdump that shows the TLSVersion in syslog?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/358459"&gt;@Nancy Saini&lt;/a&gt;:&amp;nbsp; TLSVersion does not show up in syslog output, is this expected in ISE 3.0?&amp;nbsp; Is this a new feature in ISE 3.1 and higher?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 14:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871812#M582795</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-07-11T14:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871825#M582796</link>
      <description>&lt;P&gt;If you go into you're remote logging target config, the default is 1024 which is too low to get the full log. If you try increasing this to 8192, you should get all the fields&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 14:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871825#M582796</guid>
      <dc:creator>M. Wisely</dc:creator>
      <dc:date>2023-07-11T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: TLSVersion and TLSCipher in syslog message</title>
      <link>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871879#M582797</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323120"&gt;@M. Wisely&lt;/a&gt;:&amp;nbsp; the solution you provided works like a charm.&amp;nbsp; Thank you very much.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 16:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tlsversion-and-tlscipher-in-syslog-message/m-p/4871879#M582797</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-07-11T16:12:56Z</dc:date>
    </item>
  </channel>
</rss>

