01-23-2022 08:46 AM
Hi,
We've implemented a dot1x in our organization.
We are using user authentication for the endpoint devices ( Win/Macintosh ) .
We've notice that if there is an endpoint that authenticated long time a go ( lets say about 14 days ) , we cannot see his authentication properties at our NAC side.
Is there any procedure that we can make in our switches to keep that session a live ?
Sending any accounting updates which keep the session consistent until the host is disconnected?
Switch Models:
1) Cisco 2960X
2) Cisco C9200L
Thanks! .
Solved! Go to Solution.
01-23-2022 08:57 AM
What aaa accounting configuration have you configured on your switches?
You can specify the switch to send accounting information to ISE at endpoint session start and end events:
SWI(config)#aaa accounting identity default start-stop group ISE
And configure the switch to send periodic accounting updates for active sessions once every two days:
SWI(config)#aaa accounting update newinfo periodic 2880
Refer to the ISE wired prescriptive guide:
01-23-2022 08:57 AM
What aaa accounting configuration have you configured on your switches?
You can specify the switch to send accounting information to ISE at endpoint session start and end events:
SWI(config)#aaa accounting identity default start-stop group ISE
And configure the switch to send periodic accounting updates for active sessions once every two days:
SWI(config)#aaa accounting update newinfo periodic 2880
Refer to the ISE wired prescriptive guide:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide