06-26-2019 08:24 AM
Hello,
At some Cisco talk, I've heard that sending WLC, ASA, or switches logs to the MnT is recommended for richer visibility. What are the real benefits of this and what new information can ISE take from these logs? Will not impact on the MnT node performance?
Regards.
Solved! Go to Solution.
06-29-2019 09:06 AM
There is small benefit as admin can see the logs from the switches without having to login to each switch. ISE merges the syslog event from the switch with live log. But this is not recommended beyond the pilot stage of the ISE deployment as it impacts ISE load as well as issues with session tracking. Aside from the switch, if ASA sends web access events to MnT, ISE can correlate guest users with web access events from the ASA for guest access log. If using guest access event correlation, make sure to configure ASA to only send web access event as not to overload the MnT node.
06-26-2019 08:37 AM
06-26-2019 11:53 PM
Thank you Jason,
It was at some partner training. I will skip this for the moment then.
regards.
06-26-2019 11:53 PM
Thank you Jason,
It was at some partner training. I will skip this for the moment then.
regards.
06-27-2019 11:21 AM
06-29-2019 09:06 AM
There is small benefit as admin can see the logs from the switches without having to login to each switch. ISE merges the syslog event from the switch with live log. But this is not recommended beyond the pilot stage of the ISE deployment as it impacts ISE load as well as issues with session tracking. Aside from the switch, if ASA sends web access events to MnT, ISE can correlate guest users with web access events from the ASA for guest access log. If using guest access event correlation, make sure to configure ASA to only send web access event as not to overload the MnT node.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: