cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7749
Views
32
Helpful
9
Replies

Disclose invalid username on ISE 2.4p3

Ping Zhou
Level 8
Level 8

Hello experts, 

 

ISE 2.4p3 masks the unknow usernames (unknown to all its identity stores) in its live log with "INVALID". I use "Administration >> Settings >> Protocols >> RADIUS >> Disclose invalid username" checkbox to display the unknowns. It lasts for 30 mins then turns off and seems there no way to adjust the duration. Can this be configured for permant on ISE 2.4p3? Thanks!

 

 

2 Accepted Solutions

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee
If there is no setting for it then it’s a feature request

Please reach out thru sales team to product management with your use case

View solution in original post

howon
Cisco Employee
Cisco Employee

Enhancement to permanently disclose username or change duration (https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvh91118) is planned with next version of ISE. We have started accepting beta registration for 2.5 if you are interested:

https://community.cisco.com/t5/network-architecture-blogs/ise-2-5-beta-registration-is-open/ba-p/3711445

 

View solution in original post

9 Replies 9

Jason Kunst
Cisco Employee
Cisco Employee
If there is no setting for it then it’s a feature request

Please reach out thru sales team to product management with your use case

I submitted an enhancement request for this on Aug 11th, Cisco Internal reference# F37407. It's not so much an enhancement request as it is the option for restoring earlier behavior.

If it worked before then escalate thru the TAC as a regression. Also work with product managers if getting any resistance and see how they can help

howon
Cisco Employee
Cisco Employee

Enhancement to permanently disclose username or change duration (https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvh91118) is planned with next version of ISE. We have started accepting beta registration for 2.5 if you are interested:

https://community.cisco.com/t5/network-architecture-blogs/ise-2-5-beta-registration-is-open/ba-p/3711445

 

cnorborg
Level 1
Level 1

Was this ever done?    I'm on a 3.X version and am seeing this in my logs during my initial configuration.   Going to Administration - System - Settings - Protocols - RADIUS, I don't see an option for this?    

Of course I am trying with TACACS and don't see a "protocol" for tacacs specifically?

As per the Admin Guide, the 'Disclose Invalid Usernames' option is available in the Administration > System > Settings > Security Settings page.

Hi @cnorborg ,

!version 2.4

In Administration > System > Settings > Protocols > RADIUS > Suppression & Reports > Authentication Details > Disclose invalid usernames

!version 2.6+

In Administration > System > Settings > Security Settings > Disclose invalid usernames

About " ...  and don't see a "protocol" for tacacs specifically ... ", there is "no protocol" for TACACS+.

Hope this helps !!!

Does anyone knows if permanently activating this option will affect global performances of the deployment? I didn't find anything about this topic on the Net...Thanks in advance for your feedbacks

There should be no performance impact by having the option enabled. The feature was added to improve security, not to improve performance.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: