cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
 
ISE 2.3 Patch 7 has been posted. This will be the last patch for the ISE 2.3 release!
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

112
Views
5
Helpful
4
Replies
Beginner

Cisco ISE Radius Accounting logs for network switches

I had setup of Cisco network Switch/Routers & Cisco ISE in network. Cisco ISE is used only for wireless users authentication.

Now my new requirement is to do only accounting Radius logs on Cisco ISE. Authentication & Authorization should be accessed via local credentials.

4 REPLIES 4
VIP Advocate

Re: Cisco ISE Radius Accounting logs for network switches

Hi

 

If I were you, I'd check whether you are even able to configure any Cisco NAS (WLC or otherwise) to only send RADIUS Accounting?   I don't think so.  And what is the NAS supposed to send when you don't have a RADIUS session created ?  RADIUS Sessions are created only after a successful RADIUS Authentication has occurred.

 

If there is no concept of authentication (using RADIUS or TACACS AAA), then how do you define the start and end of a session?

 

 

Highlighted
VIP Engager

Re: Cisco ISE Radius Accounting logs for network switches

"Misconfigured" WLC's will send radius accounting to ISE even if there is no RADIUS servers defined on the WLAN. If you enable radius on the WLAN without setting up radius servers, they send accounting to the servers defined in the global config. A customer of mine ended up with 4.7 millions endpoints (mostly guest) in the context visibility database that way.

Otherwise I agree, don't think it would accomplish the requirement.
Cisco Employee

Re: Cisco ISE Radius Accounting logs for network switches

Can you elaborate what is the intent behind using only accounting ?

Thanks,

Nidhi

Beginner

Re: Cisco ISE Radius Accounting logs for network switches

Hi Nidhi,

 

We already have PIM to login any network switch/router which uses device local credentials to login. So i don't want to change existing setup.