cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1739
Views
0
Helpful
2
Replies

Endpoint status in visibility remains connected after disconnect

Cloud2
Level 1
Level 1

Endpoint status in visibility remains "connected" although its already disconnected on switch side...

 

what could cause for such behavior? 

 

 

2 Accepted Solutions

Accepted Solutions

Arne Bier
VIP
VIP

Hello @Cloud2 

 

that would be due to a lack of AAA RADIUS accounting - you need to tell ISE that the session has ended by means of RADIUS Accounting (Stop).

 

In IOS/IOS-XE, add something along the lines of

 

 

aaa accounting identity default start-stop group radius-ise-group
aaa accounting update newinfo periodic 2880

 

 

The periodic 2880 means, send a RADIUS Accounting Interim Update no later than every 48 hours - it's like a keepalive to let ISE know the session is still there. If the IP address of the client were to change, then the switch will send an update anyway.

View solution in original post

Hi @Arne Bier ,

Thank you for assistance, I've added the accounting lines into switch config 

View solution in original post

2 Replies 2

Arne Bier
VIP
VIP

Hello @Cloud2 

 

that would be due to a lack of AAA RADIUS accounting - you need to tell ISE that the session has ended by means of RADIUS Accounting (Stop).

 

In IOS/IOS-XE, add something along the lines of

 

 

aaa accounting identity default start-stop group radius-ise-group
aaa accounting update newinfo periodic 2880

 

 

The periodic 2880 means, send a RADIUS Accounting Interim Update no later than every 48 hours - it's like a keepalive to let ISE know the session is still there. If the IP address of the client were to change, then the switch will send an update anyway.

Hi @Arne Bier ,

Thank you for assistance, I've added the accounting lines into switch config