cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
417
Views
1
Helpful
1
Replies

ISE Reporting Questions

jmcgourt@cisco.com
Cisco Employee
Cisco Employee

For ISE reporting - is it possible to generate reports on devices that tried to connect to the network, but failed authorisation? Also, is it possible to report on how many devices have specific vulnerabilities, based on passive scanning or checks from the posture client? 

1 Reply 1

hslai
Cisco Employee
Cisco Employee

On reporting endpoints failing authorization, we may run the report "RADIUS Authentications" and filter on 15039, which is Rejected per authorization profile, as the Failure Reason.

On reporting specific vulnerabilities, if they are posture checks, then we run the report "Posture Assessment by Condition" and filter on the condition names. If they are data collected by application visibility, then we use ISE Context Visibility > Application.