<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE: issue about connected endpoints, active sessions and Inactive in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249758#M594332</link>
    <description>&lt;P&gt;I have not seen such a huge disparity, but your analysis is correct - there is no single point of truth in ISE about active sessions. Which is concerning, since licensing depends on it, and we don't want to purchase more licenses than is necessary - but we need accurate information to make a clear purchase decision.&lt;/P&gt;
&lt;P&gt;Have you tried the Context Visibility Resync exercise?&amp;nbsp; I have done that in the past and it can often clean out a lot of junk ... at least for a while.&lt;/P&gt;
&lt;P&gt;And we must also remember, that we should check and validate that every NAD is sending at least Accounting Start/Interim/Stop to ISE - if there are no Accounting Interim requests sent to ISE, then ISE will consider a session 'dead' after 5 days of receiving the Start (and not having received a Stop yet). On IOS, best practice is to send Interims every 2880 minutes (48 hours) or sooner, if Device Sensor is used and detects a change.&lt;/P&gt;
&lt;P&gt;It's useful having a look at ISE Operational Reports to see if these Accounting Requests are being received by ISE.&amp;nbsp; In the past I have found gaps/config mistakes on devices and also buggy IOS code that didn't always send Accounting - in that case, it's not ISE's fault. Check the state of your NADs, and then also resync the Context Visibility. That might do the trick.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 21:51:22 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-01-20T21:51:22Z</dc:date>
    <item>
      <title>ISE: issue about connected endpoints, active sessions and InactiveDays</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249469#M594310</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;We know that we can get information about the number of connected endpoints to a ISE deployment we have 3 ways:&lt;/P&gt;&lt;P&gt;1)Filtering on "connected status" on Total Endpoints&lt;/P&gt;&lt;P&gt;2)Looking at the "active session" and licence counters&amp;nbsp;&lt;/P&gt;&lt;P&gt;3)Looking for endpoints with InactiveDays 0 in the Full Report from "application configure ISE" if profiler services are active on PSNs&lt;/P&gt;&lt;P&gt;Of course the 3 counters can't be exactly the same but should be very similar and in our deployment they used to be&amp;nbsp; &amp;nbsp;so at least until April 2024. Then counter 1 and 2 began to differ but this is due to a well known bug (&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj16540" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj16540&lt;/A&gt;&amp;nbsp;"&lt;BR /&gt;Cisco ISE 3.2 Patch 4 Context Visibility does not match Live Logs or Sessions."). Lat week I performed a full report when the gui was listing about 17000 Active session and 9000 connected endpoints but the number of enpoinds with elapsed days to 0 was just about 1500!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I expected a value near 9000 or 17000 not 1500!&lt;BR /&gt;Has anyone experienced a similar issue?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 09:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249469#M594310</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2025-01-20T09:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249758#M594332</link>
      <description>&lt;P&gt;I have not seen such a huge disparity, but your analysis is correct - there is no single point of truth in ISE about active sessions. Which is concerning, since licensing depends on it, and we don't want to purchase more licenses than is necessary - but we need accurate information to make a clear purchase decision.&lt;/P&gt;
&lt;P&gt;Have you tried the Context Visibility Resync exercise?&amp;nbsp; I have done that in the past and it can often clean out a lot of junk ... at least for a while.&lt;/P&gt;
&lt;P&gt;And we must also remember, that we should check and validate that every NAD is sending at least Accounting Start/Interim/Stop to ISE - if there are no Accounting Interim requests sent to ISE, then ISE will consider a session 'dead' after 5 days of receiving the Start (and not having received a Stop yet). On IOS, best practice is to send Interims every 2880 minutes (48 hours) or sooner, if Device Sensor is used and detects a change.&lt;/P&gt;
&lt;P&gt;It's useful having a look at ISE Operational Reports to see if these Accounting Requests are being received by ISE.&amp;nbsp; In the past I have found gaps/config mistakes on devices and also buggy IOS code that didn't always send Accounting - in that case, it's not ISE's fault. Check the state of your NADs, and then also resync the Context Visibility. That might do the trick.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 21:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249758#M594332</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-01-20T21:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249980#M594347</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Arne,&lt;/P&gt;&lt;P&gt;thank you for the replay: at least for one endpoint I checked deeper&amp;nbsp; it's not a NAD misconfiguration issue. I even forced a re-authentication and in context visibility I still have the correct information but performing a query exploiting dbconnect feature I saw that update time was not changed for that&amp;nbsp; point and the full report still reports a InactiveDays&amp;nbsp; &amp;gt; 0. Something happened on ISE at Jun 2024 .&amp;nbsp; I saw that dbconnect retrieves data from secondary MNT but an API query showed me that both mnts report the same number of active sessions. I gave a though&amp;nbsp; &amp;nbsp;about&amp;nbsp; context visibility resync but I have to say that context visibility seems to have the correct information so I am afraid syncing db to context would make things worse.&amp;nbsp;&lt;BR /&gt;Anyway I opened case hoping that this time TAC will be more efficient: the last case I opened took 8 months to make Cisco admit it was a bug. I think the issue is related to the profiler feature&amp;nbsp; that is in charge to update InactiveDays counter because active sessions are correct on both MNT. Unfortunately I have no idea of which is the data sourve Fullreport uses.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 08:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5249980#M594347</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2025-01-21T08:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250018#M594350</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I run fullreport on different nodes and each report is diffrent. On primary MNT there are thousands of missing endpoinds and not endpoint has elapsed day&amp;nbsp; set to 0 . What a mess ....&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 09:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250018#M594350</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2025-01-21T09:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250563#M594386</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323825"&gt;@marco.merlo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;in addition to the excellent point already made by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;, I would like to bring some numbers:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt; version &lt;STRONG&gt;3.3 P2&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;ISE Dashboard&lt;/STRONG&gt; (&lt;STRONG&gt;Total Endpoints&lt;/STRONG&gt;: &lt;STRONG&gt;258,337&lt;/STRONG&gt;&amp;nbsp;- &lt;STRONG&gt;Active Endpoints&lt;/STRONG&gt;: &lt;STRONG&gt;128,398&lt;/STRONG&gt;) :&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISE Dashboard.png" style="width: 652px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238104i82ABC88D5F362E73/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Dashboard.png" alt="ISE Dashboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;ISE Context Visibility Endpoint&lt;/STRONG&gt; (&lt;STRONG&gt;258,337 Total Rows&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISE Context Visibility Endpoints.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238105iCC7E6ACCAB33CF1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Context Visibility Endpoints.png" alt="ISE Context Visibility Endpoints.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;ISE Licensing&lt;/STRONG&gt; ... &lt;STRONG&gt;Total Consumption&lt;/STRONG&gt; of &lt;STRONG&gt;127,281&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;ISE FullReport&lt;/STRONG&gt; ... &lt;STRONG&gt;InactiveDays = 0&lt;/STRONG&gt;&amp;nbsp;with&amp;nbsp;&lt;STRONG&gt;121,074&lt;/STRONG&gt;&amp;nbsp;of &lt;STRONG&gt;258,353&lt;/STRONG&gt;&amp;nbsp;records.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISE Full Report.png" style="width: 707px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238107iCEEC3E0AF745F9C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE Full Report.png" alt="ISE Full Report.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Using&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;words "&lt;EM&gt; ... I have not seen such a huge disparity ...&lt;/EM&gt; " !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Please take a look at:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj80616" target="_blank" rel="noopener"&gt;CSCwj80616 EP details in ISE Context Visibility does not match with Radius Live Logs / Sessions during MDM flow&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CSCwj80616.png" style="width: 845px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238103i1F29475059BE32C1/image-dimensions/845x802?v=v2" width="845" height="802" role="button" title="CSCwj80616.png" alt="CSCwj80616.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;also remember that:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;The &lt;STRONG&gt;Total Endpoints&lt;/STRONG&gt; (&lt;STRONG&gt;Home &amp;gt; Dashboard&lt;/STRONG&gt;) are the &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; seen by the system since the &lt;U&gt;last&lt;/U&gt; &lt;STRONG&gt;Purge&lt;/STRONG&gt; (&lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Settings &amp;gt; Endpoint Purge&lt;/STRONG&gt;). The &lt;STRONG&gt;Total Endpoints&lt;/STRONG&gt; &lt;U&gt;count&lt;/U&gt; should be the same as the &lt;STRONG&gt;Context Visibility - Endpoints&lt;/STRONG&gt;&amp;nbsp;&lt;U&gt;Total Rows&lt;/U&gt; (that represents the &lt;STRONG&gt;ISE Internal Endpoint Store&lt;/STRONG&gt;). &lt;STRONG&gt;Total Endpoints&lt;/STRONG&gt; do NOT use &lt;STRONG&gt;License&lt;/STRONG&gt;. &lt;STRONG&gt;License&amp;nbsp;Consumption&lt;/STRONG&gt; is actually based on the &lt;STRONG&gt;Data&lt;/STRONG&gt; in &lt;STRONG&gt;MnT&lt;/STRONG&gt; and &lt;STRONG&gt;Total Endpoints/Context Visibility&lt;/STRONG&gt;&amp;nbsp;is a &lt;STRONG&gt;PAN Data&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;The &lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Endpoints and Users &amp;gt; Current Active Sessions &lt;/STRONG&gt;is &lt;U&gt;more accurate than&lt;/U&gt; &lt;STRONG&gt;Home &amp;gt; Active Endpoints Dashboard&lt;/STRONG&gt;, the &lt;STRONG&gt;1st &lt;/STRONG&gt;gets the info from &lt;STRONG&gt;MnT &lt;/STRONG&gt;(&lt;STRONG&gt;License &lt;/STRONG&gt;consumption is based on the &lt;STRONG&gt;MnT Data&lt;/STRONG&gt;), the &lt;STRONG&gt;2nd &lt;/STRONG&gt;from &lt;STRONG&gt;Context Visibility &lt;/STRONG&gt;(&lt;STRONG&gt;PAN Data&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 01:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250563#M594386</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-22T01:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250798#M594397</link>
      <description>&lt;P&gt;Thanks, you are right: In a Full Report run on Jun 2024 TotalEndpoint with inactive count 0 was compatible with the active sessions count. Yesterday I run a full report on each node at the same time: all PSNs and PANS reports&amp;nbsp; the same number lines but the the two PSNs reports about 30% fewer lines, but a dbconnect sql query for endpoints_data view reports the same count of PAN/PSNs full report and the dbcpnnect featue connects to secondary MNT Oracle Database... Maybe there is just a bug on the ruotine providing full report ....&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll try to install patch 7...&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 08:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250798#M594397</guid>
      <dc:creator>marco.merlo</dc:creator>
      <dc:date>2025-01-22T08:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: issue about connected endpoints, active sessions and Inactive</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250833#M594398</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323825"&gt;@marco.merlo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;excellent ... &lt;STRONG&gt;ISE 3.2 P7&lt;/STRONG&gt; is a very good release.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 09:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-issue-about-connected-endpoints-active-sessions-and/m-p/5250833#M594398</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-01-22T09:20:01Z</dc:date>
    </item>
  </channel>
</rss>

