06-30-2022 01:02 PM
Hi
i have a problem with the integration ISE and stealthwatch Pxgrid. The integration is fine but the final status in ISE client is (offline XMPP). Stealthwatch dont show the username only show the IP address (integration Stealthwatch with Active Directory is fine) and (integration ISE with Active Directory is fine).
It is the live log on ise
smc-150-232@xgrid.cisco.com Client offline
(SMC-150-232 is the stealthwatch manager console)
Solved! Go to Solution.
06-30-2022 06:01 PM
06-30-2022 03:54 PM
What version of ISE? What version of Stealthwatch?
What troubleshooting have you done?
Was this working before? If so, what changed?
06-30-2022 06:01 PM
06-30-2022 07:46 PM
SNA 7.4.1 integration with ISE 2.7 should be using pxGrid version 2 with WebSocket instead of XMPP.
If you haven't already done so, I would suggest reviewing the Secure Network Analytics (formerly Stealthwatch) ISE Configuration Guide.
Some of the most common issues I've seen involve either certificate trust issues between the ISE pxGrid cert and the SMC cert or the 'Automatically approve new certificate-based accounts' setting is disabled in the ISE pxGrid Settings page and the client has not been manually Approved in the Administration > pxGrid Services > Client Management > Clients section.
07-01-2022 12:09 AM
the integration is fine, i have the green circle for both ISE and SMC and this is the good signal. The problem is the ultimate state show me offline (XMPP) on ISE, how i can fix this issue?
i found this link with the same problem, but the solution not solve the problem
attach images about this problem on ISE and SMC
07-03-2022 07:20 PM
As I stated in my previous response "SNA 7.4.1 integration with ISE 2.7 should be using pxGrid version 2 with WebSocket instead of XMPP."
The All Clients tab in the 2.7 pxGrid section only shows connections using XMPP (pxGrid version 1).
The Web Clients tab shows connections using WebSocket (pxGrid version 2).
Seeing (Offline) XMPP for your SMC connection is expected since it is using pxGrid version 2.
If the pxGrid connection status on the SMC side shows Connected, you should see your SMC client in the Web Clients tab in ISE with a Status = ON.
07-03-2022 07:27 PM
07-18-2022 10:28 PM
07-19-2022 04:38 PM
There are a lot of moving parts to this solution, and simply providing screenshots from SMC is not sufficient enough information to provide any meaningful assistance.
The MAC address information from ISE requires that ISE has the IP-MAC binding. This would come from IP Device Tracking on the switch as described in the ISE Secure Wired Access Prescriptive Deployment Guide.
The User attributed to the flow record would require that ISE gets the username from an 802.1x User authentication session. Is there a successful user auth session in ISE related to this MAC address?
The rest of the details on the User Info page (email address, location, etc) would have to come from the direct integration between SMC and Active Directory.
07-19-2022 04:48 PM
07-19-2022 05:00 PM
I've provided all the suggestions I can based on the limited details supplied.
I would suggest opening a TAC case to investigate in more detail on both the ISE and SNA platforms.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide