10-28-2019 06:07 PM
I have just started to use ISE to auth VPN endpoints from my Cisco ASAs. AAA is working beautifully. I see the endpoint come through in the livelog with the Endpoint ID of the public address of the VPN client. I see the client's username. There is no MAC address and no endpoint profile.
When I look in the context visibility for this endpoint, I can't find it. I'm interested in if I see the ACIDEX attributes since I'm using Anyconnect.
Am I missing something on trying to find this endpoint in CV?
Solved! Go to Solution.
10-29-2019 08:44 AM
That is correct. I assume RADIUS profiling is enabled on the PSN? I suggest enabling packet capture to see if it is being received. This is example of ACIDEX in the RADIUS accounting:
10-29-2019 12:34 AM
Make sure to enable RADIUS accounting on ASA for the client connection.
10-29-2019 06:29 AM
10-29-2019 08:44 AM
That is correct. I assume RADIUS profiling is enabled on the PSN? I suggest enabling packet capture to see if it is being received. This is example of ACIDEX in the RADIUS accounting:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide