09-27-2022 05:57 AM
Hello guys, i have issue with registered endpoint in Cisco ISE.
I manually marked endpoint Samsung TV for a Static Group Assignment, after few days the endpoint is unchecked. Have you some tips how to fix it?
ISE version:
Solved! Go to Solution.
09-28-2022 01:50 PM
The only explanation I can see is that perhaps the endpoint was purged by a purge rule (you can look through your Reports to see what endpoint MAC addresses were purged to validate that theory) and then the endpoint was dynamically profiled.
I have never seen ISE uncheck this by itself.
You can also go through the Reports to see all the Admin activities - perhaps another admin had a hand in the game
Was the Samsung TV profile a Cisco Provided profile, or a Administrator Created profile?
09-28-2022 10:39 PM
This was a really common bug in 2.4 when using dhcp ip helpers configured to send to two different nodes. The ISE nodes would receive the DHCP request packets at the same time and disagree, instead of sorting it out, the endpoint would be "reset". ISE 2.7 is not susceptible to the bug though as it was fixed early on in 2.4.
I agree with Arne, purge policies are the typical cause.
09-28-2022 01:50 PM
The only explanation I can see is that perhaps the endpoint was purged by a purge rule (you can look through your Reports to see what endpoint MAC addresses were purged to validate that theory) and then the endpoint was dynamically profiled.
I have never seen ISE uncheck this by itself.
You can also go through the Reports to see all the Admin activities - perhaps another admin had a hand in the game
Was the Samsung TV profile a Cisco Provided profile, or a Administrator Created profile?
09-28-2022 10:39 PM
This was a really common bug in 2.4 when using dhcp ip helpers configured to send to two different nodes. The ISE nodes would receive the DHCP request packets at the same time and disagree, instead of sorting it out, the endpoint would be "reset". ISE 2.7 is not susceptible to the bug though as it was fixed early on in 2.4.
I agree with Arne, purge policies are the typical cause.
09-29-2022 01:27 AM
I think the most secure way to ensure the devices are stuck with their group would be to create a custom profile to match those Samsung TVs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide