<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting on Current Active Sessions Guidance in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/5272201#M595525</link>
    <description>&lt;P&gt;I am still none the wiser on this topic. it should not be this complicated to understand, and we should not have to reverse engineer how ISE works. My current opinion is that there is a mixture of factors that is causing a discrepancy in the numbers seen:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;bugs in ISE (I experienced this recently where the endpoint was reset on switch, and ISE Context Visibility showed the endpoint as green/Active for around 1 second and then was grey again. The switch session was up and accounting work (proved with tcpdump).&amp;nbsp; I have to conclude that ISE has "issues"&lt;/LI&gt;
&lt;LI&gt;bugs in the IOS. Some older IOS versions don't count all the types of RADIUS packets sent and received - most notably, the Interim Updates (often shown as "0" in the "show aaa servers" output) - I have interims configured of course (standard DNAC provisioned device) and I am pretty sure they were captured in the tcpdump on ISE. However, I didn't see/capture what happens after 2880 minutes (the number of minutes until the next gratuitous interim update)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;One day when I get a few minutes spare, I might do some things&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Test all this in a lab with only active 1 endpoint and then test the theory by laser focusing on how ISE behaves&lt;/LI&gt;
&lt;LI&gt;run a python script across all the production switches to capture the output of "show active sessions | Count Auth" and then tally the numbers - compare that with what ISE reports as "Active Sessions" - then see how large the margin of error is.&amp;nbsp; The trick is to write a threaded python script that can spawn more than one SSH simultaneously, to avoid this process taking too long - especially with large numbers of switches.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2025 20:42:50 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-03-17T20:42:50Z</dc:date>
    <item>
      <title>Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626346#M575248</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to understand why ISE reports different results when I ask it how many "Active Sessions" there are for a particular type of authorized device. To help me (and ISE) to filter/report on the exact Authorization Policy Rule that I am interested in, I have given them unique names like Employee_DOT1X_LowImpact, and BYOD_DOT1X_LowImpact (just to name a few). I have also given the Result Profiles unique names (even though their results are always the same) purely to assist me (and ISE) in producing reports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ISE Dashboard reports a total number of Active Endpoints - when I click on the hyperlink it opens a nice table that I can apply my search criteria on (e.g. how many BYOD users in low impact mode are active right now). But what I find is that the results in this search are not the same as when I filter in Operations &amp;gt; Reports &amp;gt; Endpoints and Users &amp;gt; Current Active Sessions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lastly, if I perform my search again using Live Sessions, I get a different answer altogether.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How does ISE define an Active Session?&amp;nbsp; Does it mean that a RADIUS Accounting Start/Update had to have been received within the last 24 hours to be considered 'Active' in Live Sessions and Operations Report?&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Dashboard click-down method (filtered on 'Connected') seems to be the only reliable method because it doesn't seem to care about the Interim accounting in last 24 hours (that's the only explanation I have). My switches send a Interim update every 48 hours (Cisco recommendation).&lt;/P&gt;
&lt;P&gt;I have been considering lowering that Interim update to 23 hours to see if that improves (with around 15000 wired endpoints this should not cause too much accounting overhead).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thoughts welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 01:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626346#M575248</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-07T01:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626388#M575250</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;my thoughts ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;All &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; at&amp;nbsp;&lt;STRONG&gt;Home &amp;gt; &lt;U&gt;Active Endpoints&lt;/U&gt; Dashboard&lt;/STRONG&gt;&amp;nbsp;has the &lt;STRONG&gt;&lt;U&gt;Authentication&lt;/U&gt; Status&lt;/STRONG&gt;&amp;nbsp;as&lt;STRONG&gt;&amp;nbsp;Connected&lt;/STRONG&gt;, but some of then has "&lt;STRONG&gt;No Active &lt;U&gt;Sessions&lt;/U&gt;&lt;/STRONG&gt;" (I tried a &lt;STRONG&gt;CoA Session Reauth&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="NoActiveSessions.png" style="width: 759px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/153027iC404ADD6D67C507C/image-dimensions/759x161?v=v2" width="759" height="161" role="button" title="NoActiveSessions.png" alt="NoActiveSessions.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Endpoints and Users &amp;gt; &lt;U&gt;Current Active Sessions&lt;/U&gt;&lt;/STRONG&gt;&lt;SPAN&gt; has the following &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;Session Status&lt;/STRONG&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. &lt;STRONG&gt;Authenticated&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt; accepted the &lt;STRONG&gt;Session&lt;/STRONG&gt;, but did not receive &lt;STRONG&gt;RADIUS Accounting Start&lt;/STRONG&gt;. If no &lt;STRONG&gt;Accounting Start&lt;/STRONG&gt; message is received, the &lt;STRONG&gt;Session&lt;/STRONG&gt; &lt;U&gt;will be removed&lt;/U&gt; after &lt;STRONG&gt;1 hour&lt;/STRONG&gt;.&lt;/EM&gt;&lt;BR /&gt;. &lt;STRONG&gt;Started&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;ISE&lt;/STRONG&gt; received &lt;STRONG&gt;RADIUS Accounting Start&lt;/STRONG&gt;. &lt;STRONG&gt;ISE&lt;/STRONG&gt; requires &lt;STRONG&gt;Interim Accounting&lt;/STRONG&gt; message to be sent within &lt;STRONG&gt;5 days&lt;/STRONG&gt;, if not the &lt;STRONG&gt;Session&lt;/STRONG&gt; &lt;U&gt;will be removed&lt;/U&gt;.&lt;/EM&gt;&lt;BR /&gt;. &lt;STRONG&gt;Postured&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;The &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; has been &lt;STRONG&gt;Posture&lt;/STRONG&gt; checked and &lt;STRONG&gt;Compliant&lt;/STRONG&gt; using the &lt;STRONG&gt;AnyConnect Posture Module&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;The &lt;STRONG&gt;Current Active Sessions&lt;/STRONG&gt; with &lt;STRONG&gt;Session Status&lt;/STRONG&gt; of &lt;STRONG&gt;Started&lt;/STRONG&gt; or &lt;STRONG&gt;Postured&lt;/STRONG&gt; have more value for me then &lt;STRONG&gt;Authenticated&lt;/STRONG&gt; (&lt;EM&gt;that could be removed after &lt;STRONG&gt;1 hour&lt;/STRONG&gt;&lt;/EM&gt;) and since the &lt;STRONG&gt;Active Endpoints Dashboard&lt;/STRONG&gt; has&amp;nbsp;&lt;STRONG&gt;Endpoints&lt;/STRONG&gt; without a &lt;STRONG&gt;Session&lt;/STRONG&gt;,&amp;nbsp;I prefer to "trust" the &lt;STRONG&gt;Current Active Sessions [Started | Posture]&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 04:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626388#M575250</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-07T04:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626545#M575251</link>
      <description>&lt;P&gt;Thanks Marcelo - one benefit of fishing out all the "Authenticated" sessions is that those are potentially from switches where RADIUS Accounting is not configured (or misconfigured). Having said that, it's hard to tell because the RADIUS Accounting UDP packets could also be dropped/lost. But it's worthy of some focus if there are many of these.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, you highlighted that ISE refers to Active Endpoints and other times, Active Sessions.&amp;nbsp; Are you saying that an Active Endpoint is the more general term of any Endpoint that has passed authentication, but that Active Sessions are those, which also send RADIUS Accounting?&amp;nbsp; In an ideal world all Active Endpoints should also have an Active Session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 05:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4626545#M575251</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-07T05:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4627248#M575278</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;when you said "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;But it's worthy of some focus if there are many of these ("Authenticated") ...&lt;/EM&gt;&amp;nbsp;", totally agree, &lt;STRONG&gt;Authenticated&lt;/STRONG&gt; as an indication/possibility of an &lt;U&gt;issue&lt;/U&gt;, but (for me) not as a "real"&amp;nbsp;&lt;STRONG&gt;Active Session&lt;/STRONG&gt; (because at that point there is no &lt;STRONG&gt;Accounting Start&lt;/STRONG&gt;).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;when you said "&lt;EM&gt; ...&amp;nbsp;Are you saying that an &lt;STRONG&gt;Active Endpoint&lt;/STRONG&gt; is the &lt;U&gt;more general term of&lt;/U&gt; any &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; that has passed authentication, but that &lt;STRONG&gt;Active Sessions&lt;/STRONG&gt; are those, which also send &lt;STRONG&gt;RADIUS Accounting&lt;/STRONG&gt;? ...&lt;/EM&gt; ", the straight answer is &lt;STRONG&gt;yes&lt;/STRONG&gt;, whenever I checked the &lt;STRONG&gt;Active Endpoints Dashboard&lt;/STRONG&gt; there is not only &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; with &lt;STRONG&gt;Active Sessions&lt;/STRONG&gt;, but also &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; without &lt;STRONG&gt;Active Sessions&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 15:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4627248#M575278</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-07T15:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4628143#M575335</link>
      <description>&lt;P&gt;As for the ISE Reports ... those that say "current Active sessions" ... that list does not seem to reflect the real situation. What are your views on fixing that? Is my understanding correct that ISE considers only endpoints active if it has seen an accounting in last 24 hours? So if the switch is sending the accounting interims every 48 hours, then you see (or not see) endpoints, depending on what time you click on these reports. Or click on the main Live Sessions menu option.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am considering returning a session-timeout of 65565 seconds (because there are older IOS-XE versions in play ... I can't use any larger value). But this value should re-auth the wired endpoints more regularly (18 hours) and I thought it might improve the "live/active" sessions visibility in ISE. Does that make sense?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 20:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4628143#M575335</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-06-08T20:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4632089#M575481</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;the&amp;nbsp;&lt;STRONG&gt;Operations &amp;gt; Reports &amp;gt; Reports &amp;gt; Endpoints and Users &amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;Current Active Sessions&lt;/U&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;is more accurate than&amp;nbsp;&lt;STRONG&gt;Home &amp;gt;&amp;nbsp;&lt;U&gt;Active Endpoints&lt;/U&gt;&amp;nbsp;Dashboard&lt;/STRONG&gt;, the &lt;STRONG&gt;1st&lt;/STRONG&gt; gets the info from &lt;STRONG&gt;MnT&amp;nbsp;&lt;/STRONG&gt;(&lt;STRONG&gt;License&lt;/STRONG&gt; consumption is based on the &lt;STRONG&gt;MnT&lt;/STRONG&gt; data), the &lt;STRONG&gt;2nd&lt;/STRONG&gt; from &lt;STRONG&gt;Context Visibility&lt;/STRONG&gt; (&lt;STRONG&gt;PAN&lt;/STRONG&gt; data).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 22:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/4632089#M575481</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-06-14T22:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/5272148#M595524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;, I am replying to this post because this ACTIVE ENDPOINTS / ACTIVE SESSION is quite confusing for me:&lt;/P&gt;&lt;P&gt;From Dashboard -- &amp;gt; Active Endpoints (screenshot below), if I click on that number then a LIVE SESSIONS browser opens automatically.&lt;/P&gt;&lt;P&gt;So my question is: Does that number of 149494 ACTIVE ENDPOINTS mean that we have 149494 LIVE SESSIONS as well, each one of those LIVE SESSIONS falling into the ONE of the next categories:&amp;nbsp; (terminated/authenticated/authorized/started/authenticating/postured?&lt;/P&gt;&lt;P&gt;WHERE the most important SESSION STATUS would be = STARTED because a radius accounting start was sent, right?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajc_0-1742232835814.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/241866i36A093B656C8B51A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ajc_0-1742232835814.png" alt="ajc_0-1742232835814.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ajc_1-1742232960715.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/241867i50C4F498167B5ED5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ajc_1-1742232960715.png" alt="ajc_1-1742232960715.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 17:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/5272148#M595524</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2025-03-17T17:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting on Current Active Sessions Guidance</title>
      <link>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/5272201#M595525</link>
      <description>&lt;P&gt;I am still none the wiser on this topic. it should not be this complicated to understand, and we should not have to reverse engineer how ISE works. My current opinion is that there is a mixture of factors that is causing a discrepancy in the numbers seen:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;bugs in ISE (I experienced this recently where the endpoint was reset on switch, and ISE Context Visibility showed the endpoint as green/Active for around 1 second and then was grey again. The switch session was up and accounting work (proved with tcpdump).&amp;nbsp; I have to conclude that ISE has "issues"&lt;/LI&gt;
&lt;LI&gt;bugs in the IOS. Some older IOS versions don't count all the types of RADIUS packets sent and received - most notably, the Interim Updates (often shown as "0" in the "show aaa servers" output) - I have interims configured of course (standard DNAC provisioned device) and I am pretty sure they were captured in the tcpdump on ISE. However, I didn't see/capture what happens after 2880 minutes (the number of minutes until the next gratuitous interim update)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;One day when I get a few minutes spare, I might do some things&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Test all this in a lab with only active 1 endpoint and then test the theory by laser focusing on how ISE behaves&lt;/LI&gt;
&lt;LI&gt;run a python script across all the production switches to capture the output of "show active sessions | Count Auth" and then tally the numbers - compare that with what ISE reports as "Active Sessions" - then see how large the margin of error is.&amp;nbsp; The trick is to write a threaded python script that can spawn more than one SSH simultaneously, to avoid this process taking too long - especially with large numbers of switches.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 20:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/reporting-on-current-active-sessions-guidance/m-p/5272201#M595525</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-03-17T20:42:50Z</dc:date>
    </item>
  </channel>
</rss>

