Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hey all,We are running a distributed ISE deployment with x2 PAN, x2 MNT, and a few PSNs.Since patching our 3.2 deployment with patch 9, we have observed increased traffic from the SMNT to specific PSNs. Destination port is 8671 which I understand it'...
Hello all, Is there a way to limit the authentication requests per network device on ISE?We already use "Suppress Repeated Failed Clients" under RADIUS but this applies per endpoint.If an attacker generates hundreds of different mac addresses, ISE is...
Hello, I need to get the last successful authentication date of an endpoint based on its mac address from ISE. This will have to be automated down the road so using the GUI Reports is not an option.After testing the API I realized it's not possible t...
Just a final update to this, TAC did not provide any meaningful response, they never identified what caused the increased traffic to the PSNs, it just normalized after a while.We ended up upgrading to 3.4P5 and things look normal now.
Thank you both.I can't open CSCwj92150 unfortunately, it says it's proprietary, and we are probably not hitting CSCwr11097 as the criteria don't seem to match. I am in contact with support so I'll mention these 2, thank you.
Hey @Arne Bier , I understand it makes sense that ISE would accept the requests as valid if they are coming from different clients. We have configured "radius-server throttle" on the switches.
Hey @thomas , thank you for the effort you have put into this, I have gone over your github and youtube videos and everything is really helpful. That being said, I am looking for something very specific i.e. the last time an endpoint was seen on ISE ...