<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAC addresses being removed from identity group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204527#M592247</link>
    <description>&lt;P&gt;Can you please update us TAC solutions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 13:13:02 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-10-07T13:13:02Z</dc:date>
    <item>
      <title>MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192680#M591756</link>
      <description>&lt;P&gt;ISE 3.2 Patch 6&lt;/P&gt;&lt;P&gt;We are having a recurring issue that is really becoming a problem now with some MAC addresses dropping their identity group after being placed into one.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;1) Add MAC address to Identity group through Context Visibility -&amp;gt; Endpoints -&amp;gt; Select MAC address -&amp;gt; Edit -&amp;gt; tick Static Group Assignment and place into group&lt;/P&gt;&lt;P&gt;Context visibility Endpoints now shows the MAC address in the new group&lt;/P&gt;&lt;P&gt;2) Re-authenticate via Operations -&amp;gt; Live Sessions -&amp;gt; CoA Actions -&amp;gt; Session Reauthentication&lt;/P&gt;&lt;P&gt;3) Device re-authenticates correctly and hits the policy rule appropriate to that Identity group&lt;/P&gt;&lt;P&gt;4) Go back to Context Visibility -&amp;gt; Endpoints and refresh&lt;/P&gt;&lt;P&gt;MAC address now showing as "Unknown" even after successful authentication&lt;/P&gt;&lt;P&gt;5) Trigger re-authentication through CoA again and the device now hits the default policy rule&lt;/P&gt;&lt;P&gt;So many times we have just thought we made a mistake and forgot to import an address, so we add it this way, watch it successfully authenticate, and go away thinking we have sorted it only for it to fail the next re-authentication when the timer (12 hours) runs out. Mostly we think we just got something wrong but after much testing have proven it really is ISE losing the ID group assignment.&lt;/P&gt;&lt;P&gt;This problem does not occur on all MAC addresses, just some, but there is no rhyme or reason to which ones do this. Although I have noticed it seems to happen more on switchports with multiple MAC addresses on them such a ports with IP phones or ones where there is a 3rd party unmanaged switch on the other end like Netgear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Patch 6 had a resolved caveat that we thought might fix this:&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class=""&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi60778" target="_blank" rel="noopener"&gt;CSCwi60778&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class=""&gt;Endpoint Loses Static Identity Group Assignment after Reauthentication.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;But sadly we are still hitting this problem.&lt;/P&gt;&lt;P&gt;Has anyone else experienced this? Is there some setting somewhere to prevent static identity group assignments from being overwritten at all?&lt;/P&gt;&lt;P&gt;We performed a reset of the Context Visibility database as well to no avail:&lt;/P&gt;&lt;P&gt;So before we raise a TAC case I'm hoping someone here might be able to assist and point out where we might be going wrong.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 13:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192680#M591756</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-09-10T13:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192738#M591757</link>
      <description>&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 14 Sep 2024 16:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192738#M591757</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-14T16:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192747#M591758</link>
      <description>&lt;P&gt;Video showing the problem example above attached.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 14:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192747#M591758</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-09-10T14:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192752#M591759</link>
      <description>&lt;P&gt;Thanks MHM we have tried that but for this particular example we get a "Failed to update endpoint - concurrent error".&lt;/P&gt;&lt;P&gt;However even if that worked it is impractical to use the identity groups section to import hundreds of devices at once.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 14:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5192752#M591759</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-09-10T14:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204399#M592230</link>
      <description>&lt;P&gt;Yes i am also having the same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 09:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204399#M592230</guid>
      <dc:creator>essarahemi</dc:creator>
      <dc:date>2024-10-07T09:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204518#M592243</link>
      <description>&lt;P&gt;We currently have this being investigated by TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204518#M592243</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-10-07T13:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204527#M592247</link>
      <description>&lt;P&gt;Can you please update us TAC solutions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5204527#M592247</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-07T13:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5205446#M592296</link>
      <description>&lt;P&gt;Would love to know what they say - I'm having the same problem - and am about to upgrade to 3.3 Patch 3 - I'll let you know if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 21:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5205446#M592296</guid>
      <dc:creator>MSDOIT</dc:creator>
      <dc:date>2024-10-08T21:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5205693#M592317</link>
      <description>&lt;P&gt;We have heard nothing for two weeks now, I suspect this is quite a sticky problem for them. But it is crucial it is fixed for our particular deployment scenario.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 10:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5205693#M592317</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-10-09T10:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5208197#M592425</link>
      <description>&lt;P&gt;Patch 7 has been released on the 10th Oct which TAC have informed us should fix this problem. We will update this after approval from our change board.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/release_notes/b_ise_32_RN.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/release_notes/b_ise_32_RN.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Fingers crossed this does the trick!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 08:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5208197#M592425</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-10-14T08:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5208979#M592462</link>
      <description>&lt;P&gt;I'm cleared to apply this tonight.&amp;nbsp; I'll report back.&amp;nbsp; Did they say anything about any of the other 3.x version e.g. 3.3&amp;nbsp; or 3.4?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 11:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5208979#M592462</guid>
      <dc:creator>MSDOIT</dc:creator>
      <dc:date>2024-10-15T11:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5209023#M592464</link>
      <description>&lt;P&gt;I'm afraid not, in fact I was given to understand that this issue was 3.2 specific and the bug tracker only lists 3.2p6&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk94725" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk94725&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The previous 3.2 patch 6 had what sounded like a similar resolved caveat as mentioned in the original post, which is also in the release notes for 3.3 patch 3 so that may hopefully resolve your issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/release_notes/b_ise_33_RN.html#newfeatures33p3" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/release_notes/b_ise_33_RN.html#resolved_caveats_33p3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi60778" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi60778&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 12:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5209023#M592464</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2024-10-15T12:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5373979#M599937</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;
&lt;P&gt;I have a Cisco ISE version 3.3.0.430 pathc 2, 4, 6, 7 and it is hitting the bug.&lt;/P&gt;
&lt;P&gt;We have an authorization rule for static Identity Group. Some devices changed to Unknown or was profile (e.g as Samsung-Device).&lt;/P&gt;
&lt;P&gt;Has anyone tried with 3.4?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 23:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5373979#M599937</guid>
      <dc:creator>Jorge Luis Covenas Chiroque</dc:creator>
      <dc:date>2026-03-02T23:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5373998#M599938</link>
      <description>&lt;P&gt;Jorge,&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi60778" rel="nofollow noopener noreferrer" target="_blank"&gt;CSCwi60778&lt;/A&gt;&amp;nbsp;: This defect has been addressed in ISE 3.3 Patch 3 and above.&lt;/P&gt;
&lt;P&gt;Also, please note that manual or automated changes may have removed endpoints from the static Identity Group. Sometimes Database or synchronization issues could also cause loss of static group assignments. I would suggest you to check that as well.&lt;BR /&gt;&lt;BR /&gt;If you plant to upgrade to version ISE 3.4, do apply the patch 3 or above.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 02:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5373998#M599938</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2026-03-03T02:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: MAC addresses being removed from identity group</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5374131#M599943</link>
      <description>&lt;P&gt;Hi Jorge,&lt;/P&gt;&lt;P&gt;We have seen several patches where Cisco claimed this had been fixed only to continue having the problem. However we have found that version 3.2 patch 9 released on Christmas Day 2025 has finally fixed the problem for us. Thank you Santa.&lt;/P&gt;&lt;P&gt;Appreciate you are on version 3.3 however I can see a patch 9 for 3.3 also released on 25/12/2025 which may have the same fixes in it. It is probably worth patching up to date and see if this helps you.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 14:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-addresses-being-removed-from-identity-group/m-p/5374131#M599943</guid>
      <dc:creator>jacksonben</dc:creator>
      <dc:date>2026-03-03T14:40:59Z</dc:date>
    </item>
  </channel>
</rss>

