cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1825
Views
5
Helpful
4
Replies

Cisco ISE Radius Accounting logs for network switches

Bhaskar Dussa
Level 1
Level 1

I had setup of Cisco network Switch/Routers & Cisco ISE in network. Cisco ISE is used only for wireless users authentication.

Now my new requirement is to do only accounting Radius logs on Cisco ISE. Authentication & Authorization should be accessed via local credentials.

4 Replies 4

Arne Bier
VIP
VIP

Hi

 

If I were you, I'd check whether you are even able to configure any Cisco NAS (WLC or otherwise) to only send RADIUS Accounting?   I don't think so.  And what is the NAS supposed to send when you don't have a RADIUS session created ?  RADIUS Sessions are created only after a successful RADIUS Authentication has occurred.

 

If there is no concept of authentication (using RADIUS or TACACS AAA), then how do you define the start and end of a session?

 

 

"Misconfigured" WLC's will send radius accounting to ISE even if there is no RADIUS servers defined on the WLAN. If you enable radius on the WLAN without setting up radius servers, they send accounting to the servers defined in the global config. A customer of mine ended up with 4.7 millions endpoints (mostly guest) in the context visibility database that way.

Otherwise I agree, don't think it would accomplish the requirement.

Nidhi
Cisco Employee
Cisco Employee

Can you elaborate what is the intent behind using only accounting ?

Thanks,

Nidhi

Hi Nidhi,

 

We already have PIM to login any network switch/router which uses device local credentials to login. So i don't want to change existing setup.