<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoints with failure 22056 clogging database in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endpoints-with-failure-22056-clogging-database/m-p/4914874#M583761</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291510"&gt;@Josh Morris&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strangely enough, I have seen the same thing in ISE 3.1 p3 (as it happens). But that might just be a coincidence.&lt;/P&gt;
&lt;P&gt;I saw hundreds of bogus MAC addresses learned from a single port and when I investigated the port, there was just a phone connected. Since I was not involved in the day to day operations of the network, I could only guess what happened. I purged the endpoints and will see if it re-occurs.&lt;/P&gt;
&lt;P&gt;I would not change your MAB policy to Reject/Drop if not found. That breaks MAB, because you must fail through to Authorization to allow new Endpoints to be Authorized (if an applicable Rule is matched). In a Monitor Mode and Low Impact Mode you would never fail anything in the Authorization phase - you have to handle all endpoints.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2023 21:29:13 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2023-08-30T21:29:13Z</dc:date>
    <item>
      <title>Endpoints with failure 22056 clogging database</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoints-with-failure-22056-clogging-database/m-p/4913115#M583689</link>
      <description>&lt;P&gt;ISE v3.1p3&lt;/P&gt;&lt;P&gt;I am getting thousands of endpoints clogging my context visibility. They have little-to-no attribute information and mostly seem to fail with&amp;nbsp;&lt;SPAN&gt;22056 Subject not found in the applicable identity store(s). I have purge policies in place, but I'm not able to capture all these for some reason. And funny enough, many of these (potentially bogus) MAC addresses appear to be coming from the same switchport. I have investigated the endpoints connected on this switchport and I don't see anything fishy there. No hubs, no container or virtualization software, no apparent foul play.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there another way I should be dealing with these beside regular observation, manual removal, and trying to optimize endpoint purge rules?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Edit: Here is my authentication policy for this. Its very simple, but I wonder if I should DROP instead of REJECT if User not found? Would this keep the endpoint from showing up in the CV?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JoshMorris_0-1693237575435.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/195495i4B756D9B010539AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JoshMorris_0-1693237575435.png" alt="JoshMorris_0-1693237575435.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 15:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoints-with-failure-22056-clogging-database/m-p/4913115#M583689</guid>
      <dc:creator>Josh Morris</dc:creator>
      <dc:date>2023-08-28T15:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoints with failure 22056 clogging database</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoints-with-failure-22056-clogging-database/m-p/4914874#M583761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291510"&gt;@Josh Morris&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strangely enough, I have seen the same thing in ISE 3.1 p3 (as it happens). But that might just be a coincidence.&lt;/P&gt;
&lt;P&gt;I saw hundreds of bogus MAC addresses learned from a single port and when I investigated the port, there was just a phone connected. Since I was not involved in the day to day operations of the network, I could only guess what happened. I purged the endpoints and will see if it re-occurs.&lt;/P&gt;
&lt;P&gt;I would not change your MAB policy to Reject/Drop if not found. That breaks MAB, because you must fail through to Authorization to allow new Endpoints to be Authorized (if an applicable Rule is matched). In a Monitor Mode and Low Impact Mode you would never fail anything in the Authorization phase - you have to handle all endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 21:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoints-with-failure-22056-clogging-database/m-p/4914874#M583761</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-08-30T21:29:13Z</dc:date>
    </item>
  </channel>
</rss>

