10-24-2024 03:12 PM
Hi All,
We do static endpoint assignment to Identity groups in ISE. But even if endpoint is active the assignment changes to a different identity group after few hours or days.
Any idea how to troubleshoot such situation to narrow down the issue?
10-25-2024 12:53 AM
@ahmad82pkn what version of ISE and patch level are you running?
It could be a bug - https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk94725
10-25-2024 02:29 PM
10-25-2024 10:55 AM
What is it changing to? Do you use profiling that might change it?
10-25-2024 01:17 PM
10-27-2024 01:21 PM
Check the configuration change logs in ISE to see who dunnit.
Operations / Reports / Audit / Change Configuration Audit
12-06-2024 07:10 AM
It's almost certainly the profiler changing the endpoint identity group. There is at least one bug documenting this behavior. Should be fixed in 3.2 P7.
3.1 is affected by this, although, I'm not sure what triggers the bug. I know of as least one 3.1 deployment in production that just recently saw onset of this behavior after flawless operation for months.
I haven't seen anything in the release notes for 3.1, although, it looks like P10 should be coming out in January of 2025 which might contain a fix. Otherwise, if the business impact is significant enough, you may want to consider moving to 3.2.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide