- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2018 10:48 PM
Hi,
we have ISE 1.2x deployment, ISE not add mac address of new endpoints in Internal Endpoints IDStore due MAB after the advanced license are expired...
24209 Looking up Endpoint in Internal Endpoints IDStore...
24217 The host is not found in the internal endpoints identity store
22056 Subject not found in the applicable identity store(s)
22058 The advanced option that is configured for an unknown user is used
22060 The 'Continue' advanced option is configured in case of a failed authentication request
Is it expected issue and ISE add mac address of new endpoints in Internal Endpoints IDStore only via profiling?
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 12:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2018 11:30 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-07-2018 11:51 PM
Hi,
replication is working properly (if I can trust deployment info via GUI)
There are 2 PAN, 2 MnT and 2 PSN nodes...
If I add mac address of new endpoint manually in Internal Endpoints IDStore on PAN always are work as expected...
24209 Looking up Endpoint in Internal Endpoints IDStore
24211 Found Endpoint in Internal Endpoints IDStore
But previously ISE add mac address of new endpoint automaticly...
Thanks for your response...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 12:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 12:15 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 03:19 AM
Hi Surendra
What about customer who do not have Plus licenses and therefore have not enabled profiling (as expected) - BUT who have Cisco WLC/Switches with Device Sensor enabled? ISE Radius probe should still be running, right? You cannot disable this as far as I know.
I think what you are referring to are the other probes like DHCP, SNMP, NMAP etc.
If there is any proper documentation on this I would love to see it. it's not well documented at all and it leads to all this speculation and questions.
thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 03:39 AM
I'm not sure what you meant when you said "ISE Radius probe should still be running, right? You cannot disable this as far as I know." You can disable RADIUS Probe under the profiling configuration which then would cause ISE to stop collecting the attributes from RADIUS requests for the endpoints and essentially stopping them from being profiled based on those attributes..
Regards,
Surendra.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 04:10 AM
Customers who are not running eval license, but who have enabled base license only, and who have not enabled Profiling service on their PSN, will still have the radius probe enabled. According to former Cisco TME, Craig Hyps who sadly no longer works for Cisco, this was working as designed. Have a look here
I don't currently have access to a system that is licensed for Base only, and where I can test with a Cisco WLC using Radius Profiling for DHCP/HTTP - that would be my test case.
It would be good to have this confirmed by someone else, because now I am starting to doubt my own sanity :(
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-08-2018 04:32 AM
