cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
710
Views
0
Helpful
3
Replies

Why don't I see VPN endpoints in my context visibility?

Josh Morris
Level 3
Level 3

I have just started to use ISE to auth VPN endpoints from my Cisco ASAs. AAA is working beautifully. I see the endpoint come through in the livelog with the Endpoint ID of the public address of the VPN client. I see the client's username. There is no MAC address and no endpoint profile. 

 

When I look in the context visibility for this endpoint, I can't find it. I'm interested in if I see the ACIDEX attributes since I'm using Anyconnect. 

 

Am I missing something on trying to find this endpoint in CV?

1 Accepted Solution

Accepted Solutions

That is correct. I assume RADIUS profiling is enabled on the PSN? I suggest enabling packet capture to see if it is being received. This is example of ACIDEX in the RADIUS accounting:

Screen Shot 2019-10-29 at 10.42.01 AM.png

View solution in original post

3 Replies 3

howon
Cisco Employee
Cisco Employee

Make sure to enable RADIUS accounting on ASA for the client connection.

Thanks, I believe it is based on what I'm seeing. Is this not correct to get accounting info to ISE?

That is correct. I assume RADIUS profiling is enabled on the PSN? I suggest enabling packet capture to see if it is being received. This is example of ACIDEX in the RADIUS accounting:

Screen Shot 2019-10-29 at 10.42.01 AM.png