12-08-2018 09:01 AM
Recently started getting auto mail from ISE messages. Using ISE VM version 2.4.0.357
We are having two node deployment. Getting mails from only one node.
Even though authentications requests are coming to second ISE box.
Alarm Name :
ISE Authentication Inactivity
Details :
No Authentications in the last 15 minutes
Description :
The ISE Policy Service nodes are not receiving Authentication requests from the Network Devices
Severity :
Warning
Suggested Actions :
Check the ISE/NAD configuration, check the network connectivity of the ISE/NAD infrastructure.
*** This message is generated by Cisco Identity Services Engine (ISE) ***
Solved! Go to Solution.
12-08-2018 10:40 AM
We also get these on one of our 2.4 deployments for no explainable reason and with no pattern. With an average of ~150k active endpoints at any given point throughout the day, It's just not possible that there is a 15 minute period with no radius authentications.
In theory this should be a critical alarm/scenario for most deployments I've worked on. It would mean that either the collector has backed up on the MNT or something far more catastrophic like simultaneously losing all the load balancers for 15+ minutes.
There were a few bugs related to the collector and syslogs in 2.4 p1/p2/p3 that could cause this alarm, but those have been addressed. Are you on 2.4 patch 4 or patch 5, and how often are you seeing this alarm?
12-08-2018 09:47 AM
I recall emails only being sent from the MnT persona, is that the one node sending the emails?
12-08-2018 11:30 AM
Yes, Mnt (Prim) is sending emails.
12-08-2018 11:30 AM
Yes, Mnt (Prim) is sending emails.
12-08-2018 10:40 AM
We also get these on one of our 2.4 deployments for no explainable reason and with no pattern. With an average of ~150k active endpoints at any given point throughout the day, It's just not possible that there is a 15 minute period with no radius authentications.
In theory this should be a critical alarm/scenario for most deployments I've worked on. It would mean that either the collector has backed up on the MNT or something far more catastrophic like simultaneously losing all the load balancers for 15+ minutes.
There were a few bugs related to the collector and syslogs in 2.4 p1/p2/p3 that could cause this alarm, but those have been addressed. Are you on 2.4 patch 4 or patch 5, and how often are you seeing this alarm?
12-08-2018 11:32 AM
They started few hours back only. Email is being triggered by Mnt (Prim) every 15 mins. Still getting mails.
We have not applied any patch to 2.4
12-08-2018 11:37 AM
12-08-2018 11:30 AM
12-08-2018 11:46 AM
No backups/ vm snapshot was scheduled when it started.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide