09-10-2024 06:20 AM - edited 09-10-2024 06:24 AM
ISE 3.2 Patch 6
We are having a recurring issue that is really becoming a problem now with some MAC addresses dropping their identity group after being placed into one.
Example:
1) Add MAC address to Identity group through Context Visibility -> Endpoints -> Select MAC address -> Edit -> tick Static Group Assignment and place into group
Context visibility Endpoints now shows the MAC address in the new group
2) Re-authenticate via Operations -> Live Sessions -> CoA Actions -> Session Reauthentication
3) Device re-authenticates correctly and hits the policy rule appropriate to that Identity group
4) Go back to Context Visibility -> Endpoints and refresh
MAC address now showing as "Unknown" even after successful authentication
5) Trigger re-authentication through CoA again and the device now hits the default policy rule
So many times we have just thought we made a mistake and forgot to import an address, so we add it this way, watch it successfully authenticate, and go away thinking we have sorted it only for it to fail the next re-authentication when the timer (12 hours) runs out. Mostly we think we just got something wrong but after much testing have proven it really is ISE losing the ID group assignment.
This problem does not occur on all MAC addresses, just some, but there is no rhyme or reason to which ones do this. Although I have noticed it seems to happen more on switchports with multiple MAC addresses on them such a ports with IP phones or ones where there is a 3rd party unmanaged switch on the other end like Netgear.
Patch 6 had a resolved caveat that we thought might fix this:
Endpoint Loses Static Identity Group Assignment after Reauthentication. |
But sadly we are still hitting this problem.
Has anyone else experienced this? Is there some setting somewhere to prevent static identity group assignments from being overwritten at all?
We performed a reset of the Context Visibility database as well to no avail:
So before we raise a TAC case I'm hoping someone here might be able to assist and point out where we might be going wrong.
Thanks.
09-10-2024 07:27 AM - edited 09-14-2024 09:19 AM
MHM
09-10-2024 07:43 AM
Thanks MHM we have tried that but for this particular example we get a "Failed to update endpoint - concurrent error".
However even if that worked it is impractical to use the identity groups section to import hundreds of devices at once.
09-10-2024 07:37 AM
10-07-2024 02:03 AM
Yes i am also having the same issue.
10-07-2024 06:01 AM
We currently have this being investigated by TAC.
10-07-2024 06:13 AM
Can you please update us TAC solutions.
So thanks
MHM
10-08-2024 02:58 PM
Would love to know what they say - I'm having the same problem - and am about to upgrade to 3.3 Patch 3 - I'll let you know if that helps.
10-09-2024 03:43 AM
We have heard nothing for two weeks now, I suspect this is quite a sticky problem for them. But it is crucial it is fixed for our particular deployment scenario.
10-14-2024 01:37 AM - edited 10-14-2024 01:37 AM
Patch 7 has been released on the 10th Oct which TAC have informed us should fix this problem. We will update this after approval from our change board.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/release_notes/b_ise_32_RN.html
Fingers crossed this does the trick!
10-15-2024 04:41 AM
I'm cleared to apply this tonight. I'll report back. Did they say anything about any of the other 3.x version e.g. 3.3 or 3.4?
10-15-2024 05:44 AM
I'm afraid not, in fact I was given to understand that this issue was 3.2 specific and the bug tracker only lists 3.2p6
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk94725
The previous 3.2 patch 6 had what sounded like a similar resolved caveat as mentioned in the original post, which is also in the release notes for 3.3 patch 3 so that may hopefully resolve your issue.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi60778
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide