11-09-2021 11:16 PM
Endpoint status in visibility remains "connected" although its already disconnected on switch side...
what could cause for such behavior?
Solved! Go to Solution.
11-23-2021 10:54 PM
Hello @Cloud2
that would be due to a lack of AAA RADIUS accounting - you need to tell ISE that the session has ended by means of RADIUS Accounting (Stop).
In IOS/IOS-XE, add something along the lines of
aaa accounting identity default start-stop group radius-ise-group
aaa accounting update newinfo periodic 2880
The periodic 2880 means, send a RADIUS Accounting Interim Update no later than every 48 hours - it's like a keepalive to let ISE know the session is still there. If the IP address of the client were to change, then the switch will send an update anyway.
11-24-2021 05:55 AM
Hi @Arne Bier ,
Thank you for assistance, I've added the accounting lines into switch config
11-23-2021 10:54 PM
Hello @Cloud2
that would be due to a lack of AAA RADIUS accounting - you need to tell ISE that the session has ended by means of RADIUS Accounting (Stop).
In IOS/IOS-XE, add something along the lines of
aaa accounting identity default start-stop group radius-ise-group
aaa accounting update newinfo periodic 2880
The periodic 2880 means, send a RADIUS Accounting Interim Update no later than every 48 hours - it's like a keepalive to let ISE know the session is still there. If the IP address of the client were to change, then the switch will send an update anyway.
11-24-2021 05:55 AM
Hi @Arne Bier ,
Thank you for assistance, I've added the accounting lines into switch config
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide