This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
Hi,
Working on a use case as follows:
UserA - 192.168.1.1 (First Login)
UserA - 192.168.1.2 (Second Login)
UserA login into 192.168.1.1 after login at 192.168.1.1. Based on ISE passiveID, only first IP is registered in User-IP mapping and shared via pxGrid to FMC. Any possibility for the same UserA map to multiple IPs for concurrent login?
Currently even based on endpoint probes, the mapping will not get updated within 4 hours if user has no logout from earlier session.
Without relying on limiting concurrent login at AD and PAM solution, do we have any workaround for ISE PassiveID to get latest endpoint information? Or are there any possibility for same username mapped to 2 or more IP?
Thanks
Wing Churn
Our problem is more towards ISE-PIC. PassiveID does not reflect new IP for new login with another IP address.
If userA login from 192.168.1.1 for the first time, we receive the login message in ISE-PIC and share across to FMC via pxGrid. A second login from userA without logout from previous session at another IP address does not appear in ISE-PIC. Are there any specific tuning in ISE-PIC for concurrent/multi IP mapping?
Wing Churn