cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1003
Views
10
Helpful
3
Replies

Static Group Assignment will become unchecked cisco ISE

Micinel
Level 1
Level 1

Hello guys, i have issue with registered endpoint in Cisco ISE.

I manually marked endpoint Samsung TV for a Static Group Assignment, after few days the endpoint is unchecked. Have you some tips how to fix it?

 

ISE version:

Micinel_0-1664283424791.png

 

2 Accepted Solutions

Accepted Solutions

Arne Bier
VIP
VIP

The only explanation I can see is that perhaps the endpoint was purged by a purge rule (you can look through your Reports to see what endpoint MAC addresses were purged to validate that theory) and then the endpoint was dynamically profiled.

I have never seen ISE uncheck this by itself.

You can also go through the Reports to see all the Admin activities - perhaps another admin had a hand in the game

Was the Samsung TV profile a Cisco Provided profile, or a Administrator Created profile?

View solution in original post

Damien Miller
VIP Alumni
VIP Alumni

This was a really common bug in 2.4 when using dhcp ip helpers configured to send to two different nodes. The ISE nodes would receive the DHCP request packets at the same time and disagree, instead of sorting it out, the endpoint would be "reset".  ISE 2.7 is not susceptible to the bug though as it was fixed early on in 2.4. 

I agree with Arne, purge policies are the typical cause. 

View solution in original post

3 Replies 3

Arne Bier
VIP
VIP

The only explanation I can see is that perhaps the endpoint was purged by a purge rule (you can look through your Reports to see what endpoint MAC addresses were purged to validate that theory) and then the endpoint was dynamically profiled.

I have never seen ISE uncheck this by itself.

You can also go through the Reports to see all the Admin activities - perhaps another admin had a hand in the game

Was the Samsung TV profile a Cisco Provided profile, or a Administrator Created profile?

Damien Miller
VIP Alumni
VIP Alumni

This was a really common bug in 2.4 when using dhcp ip helpers configured to send to two different nodes. The ISE nodes would receive the DHCP request packets at the same time and disagree, instead of sorting it out, the endpoint would be "reset".  ISE 2.7 is not susceptible to the bug though as it was fixed early on in 2.4. 

I agree with Arne, purge policies are the typical cause. 

I think the most secure way to ensure the devices are stuck with their group would be to create a custom profile to match those Samsung TVs.