11-07-2018 10:48 PM
Hi,
we have ISE 1.2x deployment, ISE not add mac address of new endpoints in Internal Endpoints IDStore due MAB after the advanced license are expired...
24209 Looking up Endpoint in Internal Endpoints IDStore...
24217 The host is not found in the internal endpoints identity store
22056 Subject not found in the applicable identity store(s)
22058 The advanced option that is configured for an unknown user is used
22060 The 'Continue' advanced option is configured in case of a failed authentication request
Is it expected issue and ISE add mac address of new endpoints in Internal Endpoints IDStore only via profiling?
Solved! Go to Solution.
11-08-2018 12:06 AM
11-07-2018 11:30 PM
11-07-2018 11:51 PM
Hi,
replication is working properly (if I can trust deployment info via GUI)
There are 2 PAN, 2 MnT and 2 PSN nodes...
If I add mac address of new endpoint manually in Internal Endpoints IDStore on PAN always are work as expected...
24209 Looking up Endpoint in Internal Endpoints IDStore
24211 Found Endpoint in Internal Endpoints IDStore
But previously ISE add mac address of new endpoint automaticly...
Thanks for your response...
11-08-2018 12:06 AM
11-08-2018 12:15 AM
11-08-2018 03:19 AM
Hi Surendra
What about customer who do not have Plus licenses and therefore have not enabled profiling (as expected) - BUT who have Cisco WLC/Switches with Device Sensor enabled? ISE Radius probe should still be running, right? You cannot disable this as far as I know.
I think what you are referring to are the other probes like DHCP, SNMP, NMAP etc.
If there is any proper documentation on this I would love to see it. it's not well documented at all and it leads to all this speculation and questions.
thanks
11-08-2018 03:39 AM
11-08-2018 04:10 AM
Customers who are not running eval license, but who have enabled base license only, and who have not enabled Profiling service on their PSN, will still have the radius probe enabled. According to former Cisco TME, Craig Hyps who sadly no longer works for Cisco, this was working as designed. Have a look here
I don't currently have access to a system that is licensed for Base only, and where I can test with a Cisco WLC using Radius Profiling for DHCP/HTTP - that would be my test case.
It would be good to have this confirmed by someone else, because now I am starting to doubt my own sanity :(
11-08-2018 04:32 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide