In diesem Dokument wird die Konfiguration des Status-Leasings in der Cisco ISE beschrieben.
Die Informationen in diesem Dokument basierend auf folgenden Software- und Hardware-Versionen:
Die Informationen in diesem Dokument beziehen sich auf Geräte in einer speziell eingerichteten Testumgebung. Alle Geräte, die in diesem Dokument benutzt wurden, begannen mit einer gelöschten (Nichterfüllungs) Konfiguration. Wenn Ihr Netzwerk in Betrieb ist, stellen Sie sicher, dass Sie die möglichen Auswirkungen aller Befehle kennen.
Statusleasing ist eine Funktion der Cisco ISE, die den letzten bekannten Compliance-Status in der DB bis zu 365 Tage speichert und sich nicht an den Endpunkt wendet, um die Konformität zu prüfen. Wenn jedoch der Statusleasing-Zeitraum abläuft, löst die Cisco ISE nicht automatisch eine erneute Authentifizierung oder eine Statusüberprüfung für den Endpunkt aus. Der Endpunkt bleibt im gleichen Compliance-Status, da dieselbe Sitzung verwendet wird. Bei der erneuten Authentifizierung des Endpunkts wird der Status ausgeführt, und die Leasedauer für den Status wird zurückgesetzt.
Posture Lease ist ein Endgeräteattribut, das in der Oracle DB und die Zeit in EPOCH gespeichert wird. Dasselbe kann anhand der Kontexttransparenz und der Oracle-Datenbank validiert werden.

Zusammen mit dem Status-Leasing gibt es eine weitere Funktion in der ISE, die den letzten bekannten Compliance-Status für die konfigurierbare Zeit (max. 200 Tage / 4800 Stunden / 288000 Minuten) zwischenspeichert, die im "Last Known Posture Compliant State" (Letzter bekannter Status, mit konformer Körperhaltung) konfiguriert wurde. Mit dieser Funktion kann die Cisco ISE den letzten Compliance-Status zwischenspeichern. Wenn ein Endpunkt im Compliance-Status für die letzte bekannte Schwachstelle nicht mehr konform ist, markiert die ISE den Endpunkt bis zum Ablauf des in der Statusrichtlinie konfigurierten Kulanzzeitraums als konform.
Letzte bekannte Statuskonformität speichert in der Oracle DB., es speichert auch in EPOCH-Zeit.
So konfigurieren Sie das Status-Lease in der Cisco ISE:
1. Navigieren Sie zu Work Centers > Posture > Settings > Posture Lease. Überprüfen Sie das Kontrollkästchen Perform posture assessment every __ Days (Statusüberprüfung alle Tage durchführen), und konfigurieren Sie die Anzahl der Tage (Tage) (1-365 Tage). In diesem Beispiel ist er auf 1 Tage festgelegt.
2. Markieren Sie den Status "Cache Last Known Posture Compliant" und konfigurieren Sie die Zeit für den Status "Last Known Posture Compliant State" (maximal 200 Tage / 4800 Stunden / 288000 Minuten). In diesem Beispiel ist sie für 2 Tage konfiguriert.

3. Der Einfachheit halber wurde nur eine Statusrichtlinie (Windows FW-Prüfung) mit einer Nachfrist von 2 Minuten aktiviert.

Der Endpunkt stellt zum ersten Mal eine Verbindung her und ist kompatibel.


ISE-PSC.log (Status in DEBUG)
In der ise-psc.log-Datei wird keine Ablaufzeit in der Datenbank angezeigt, da das EP zum ersten Mal eine Verbindung herstellt:
2024-11-30 22:55:08,485 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-8][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A000000147BE04019::::- posture expriy time retrieved from DB is "" for B4-96-91-26-EB-A1
2024-11-30 22:55:08,485 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-8][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A000000147BE04019::::- PostureExpiry value for B4-96-91-26-EB-A1 is not a number :
Das EP verarbeitet die Statusprüfung und wird konform. Sobald das EP kompatibel ist, aktualisiert die ISE die Datenbank mit einer Ablaufzeit von einem Tag (1733073953816):
2024-11-30 22:55:55,306 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A000000147BE04019:alice:::- posture_bypass_test is null fast reconnect expiry time is1733073953816 2024-12-01T22:55:54.306+0530
2024-11-30 22:55:55,307 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A000000147BE04019:alice:::- updating fast reconnect for end point B4:96:91:26:EB:A1 with 1 days of expiry time1733073953816 <------Updating posture lease in DB (EDF_POSTUREEXPIRY)
2024-11-30 22:55:55,307 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- updated posutre lease for session 08C9C50A000000177E20CE15
Darüber hinaus aktualisiert die ISE die Datenbank mit der Ablaufzeit für die Kulanzfrist von 1733160354306 (2 Tage):
2024-11-30 22:55:55,306 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000147BE04019:alice:::- Starting new thread for updateGracePeriodTime
2024-11-30 22:55:55,306 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000147BE04019:alice:::- remove user from expiry list
2024-11-30 22:55:54,306 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A000000147BE04019:alice:::- updating grace period for device with udid: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 , maclist: [B4:96:91:26:EB:A1], <---- grace period expiry time 1733160354306 <----------- Updating last known compliance status in DB (LAST_COMP_EXPIRY)
Nach der Wiederanbindung des EP wird die Sitzung direkt beschwert. Bei Aktivierung des Status-Leasings ruft die ISE die Ablaufzeit des Status von der DB ab und markiert die Sitzung als konform:

2024-11-30 23:04:17,673 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-11-30 23:04:17,673 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is enabled
2024-11-30 23:04:17,677 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Querying posture expiry time by MAC B4-96-91-26-EB-A1
2024-11-30 23:04:17,679 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture expriy time retrieved from DB is "1733073953816" for B4-96-91-26-EB-A1
2024-11-30 23:04:17,679 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture lease expiry time 1733073953816 2024-12-01T22:55:53.816+0530 for B4-96-91-26-EB-A1
2024-11-30 23:04:17,679 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- retrieved fast reconnect expiry time 1733073953816 2024-12-01T22:55:53.816+0530 for B4-96-91-26-EB-A1
2024-11-30 23:04:17,679 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- B4-96-91-26-EB-A1 is within fast reconnect expiry
2024-11-30 23:04:17,680 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.runtime.PosturePolicyUtil -:::::- User null belongs to groups NAC Group:NAC:IdentityGroups:Endpoint Identity Groups:Profiled:Workstation,NAC Group:NAC:IdentityGroups:Any
2024-11-30 23:04:17,680 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- PostureStatusPIP for mac B4-96-91-26-EB-A1 - Attribute Session.PostureStatus value is Compliant
1. Deaktivieren Sie den Status-Leasing, und aktivieren Sie Cache Last Known Posture Compliant Status with Last Known Posture Compliant State of 2 Days (Letzter bekannter Status - Statuskonform). Dieses Szenario ist auch gültig, wenn der Status-Lease abläuft und anschließend eine Verbindung zum EP hergestellt wird.

2. Nach der EP-Authentifizierung führt die ISE die Statusüberprüfung durch, da die Statusleasing-Funktion nicht aktiviert ist:
2024-12-01 18:39:50,901 DEBUG [PolicyEngineEvaluationThread-3][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-12-01 18:39:50,901 DEBUG [PolicyEngineEvaluationThread-3][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is not enabled. Posture status retrieved from LSD for B4-96-91-26-EB-A1 is Unknown
2024-12-01 18:39:50,901 DEBUG [PolicyEngineEvaluationThread-3][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- PostureStatusPIP for mac B4-96-91-26-EB-A1 - Attribute Session.PostureStatus value is Unknown
3. Sobald das EP die Anforderungen erfüllt, aktualisiert die ISE die Datenbank innerhalb der Kulanzfrist von 1733231423117 (2 Tage).
2024-12-01 18:40:23,116 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-3][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000227EB700E6:alice:::- Starting new thread for updateGracePeriodTime
2024-12-01 18:40:23,117 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-3][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000227EB700E6:alice:::- remove user from expiry list
2024-12-01 18:40:23,117 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-3][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A000000227EB700E6:alice:::- updating grace period for device with udid: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 , maclist: [B4:96:91:26:EB:A1], grace period expiry time 1733231423117 <--------------Updating last known compliance status in DB (LAST_COMP_EXPIRY)
2024-12-01 18:40:23,117 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-3][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000227EB700E6:alice:::- Starting new thread for updateLastCompExpiryTime [B4:96:91:26:EB:A1], grace period expiry time 1733057867397

Jetzt wird das EP nicht mehr beschwert. Wie in der Statusrichtlinie wird nur das Fenster FW aktiviert.
4. Deaktivieren Sie die Windows-Firewall, und schließen Sie das EP erneut an. Das EP wird nicht beschwert, jedoch wird in der Statusrichtlinie eine 2-minütige Nachfrist konfiguriert. Aus diesem Grund zeigt das Statusmodul Wechselstrom den Status In Kulanzperiode an.

5. Im RADIUS-Live-Protokoll können Sie sehen, dass das EP als Beschwerde markiert ist, obwohl die Statusüberprüfung fehlgeschlagen ist. Nach Ablauf der Kulanzfrist wurde die Sitzung nicht konform.

6. Im ise-psc.log wird angezeigt, wann das EP eine Verbindung herstellt. Da die Lease-Funktion nicht aktiviert ist, wird das LSD überprüft, um den Status abzurufen:
2024-11-30 23:26:16,482 DEBUG [PolicyEngineEvaluationThread-16][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-11-30 23:26:16,482 DEBUG [PolicyEngineEvaluationThread-16][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is not enabled. Posture status retrieved from LSD for B4-96-91-26-EB-A1 is Unknown
2024-11-30 23:26:16,483 DEBUG [PolicyEngineEvaluationThread-16][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- PostureStatusPIP for mac B4-96-91-26-EB-A1 - Attribute Session.PostureStatus value is Unknown
7. Die Statusüberprüfung wird durchgeführt und schlägt für das EP fehl. Danach überprüft die ISE die Datenbank auf den letzten CompliantExpiry-Wert, der 1733160354306 (2 Tage) beträgt.
2024-11-30 23:27:19,123 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- Last compliant expiry period for device with mac: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 has not expired lastCompliantExpiry: 1733160354306.
8. Da das letzte CompliantExpiry-Ereignis immer noch gültig ist, wird die in der Statusrichtlinie konfigurierte Kulanzfrist, die 2 Minuten beträgt, erneut überprüft.
2024-11-30 23:27:19,123 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- handleGracePeriod - calculateGracePeriod: B4-96-91-26-EB-A1.
2024-11-30 23:27:19,544 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- calculateGracePeriod - matched policy: Default_Firewall_Policy_Win with grace period: 2 for mac: B4-96-91-26-EB-A1
2024-11-30 23:27:19,544 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- calculateGracePeriod - grace period is: 2 for mac: B4-96-91-26-EB-A1
2024-11-30 23:27:19,546 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000147BE04019:alice:::- Added user with mac B4-96-91-26-EB-A1 udid 6d8a638f9acadd2851a6cd7eae947060a898ebc1 grace period list with an expiration time of 2024/11/30 23:29:19 and startTime of 2024/11/30 23:27:19 <---------------- Updating the Grace period in DB (LAST_GRACE_EXPIRY)
2024-11-30 23:27:19,546 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- handleGracePeriod - device with mac: B4-96-91-26-EB-A1 - has grace period: 2 mins.
2024-11-30 23:27:19,546 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- Device with session id: 08C9C50A0000001A7E3D5087, client mac: B4-96-91-26-EB-A1 - has grace period: 2. Marking posture status as compliant
9. Nach Ablauf der Kulanzfrist sendet das AC-Modul den ausgefallenen Bericht an die ISE. Die ISE überprüft die Kulanzfrist in der Datenbank und stellt fest, dass sie abgelaufen ist. Anschließend wird die Sitzung als nicht beschwerdefähig markiert, und LastCompExpiryTime und GracePeriodTime werden aus der DB entfernt:
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000177E20CE15:alice:::- value from cache 1732989439545 and db 1732989439545
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000177E20CE15:alice:::- getGracePeriodAndUpdate - StartTime 1732989439545
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000177E20CE15:alice:::- Calculated the GracePeriod exp in min 0
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000177E20CE15:alice:::- GracePeriod value is 0 and removeUser
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000177E20CE15:alice:::- Starting new thread for updateGracePeriodTime
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.runtime.GracePeriodManager -:08C9C50A000000177E20CE15:alice:::- remove user from expiry list
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000177E20CE15:alice:::- Starting new thread for updateLastCompExpiryTime
2024-11-30 23:29:23,289 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-4][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000177E20CE15:alice:::- Starting new thread for updateGracePeriodTime
10. Wenn sich das EP erneut verbindet und keine Beschwerde einlegt, respektiert die ISE die Gnadenfrist der Haltungspolitik nicht. Da der letzte konforme Zeitraum bereits abgelaufen ist und die Sitzung direkt als Nicht-Beschwerde aktualisiert wird.
2024-12-01 00:49:40,004 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-6][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000177E20CE15:alice:::- handleGracePeriod - Last compliant period expired for device with mac: B4-96-91-26-EB-A1.

1. In diesem Fall aktualisiert die ISE die letzteCompliance-Ablaufzeit in der Datenbank standardmäßig auf 365 Tage.
2. Da das Statusleasing nicht aktiviert ist, erfolgt eine Statusüberprüfung, und das EP wird zur Beschwerde, nachdem ISE die letzte kompatible Ablaufzeit auf 365 Tage in der Datenbank aktualisiert hat.
2024-12-01 00:58:17,191 DEBUG [PolicyEngineEvaluationThread-12][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-12-01 00:58:17,191 DEBUG [PolicyEngineEvaluationThread-12][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is not enabled. Posture status retrieved from LSD for B4-96-91-26-EB-A1 is Unknown
2024-12-01 00:58:17,191 DEBUG [PolicyEngineEvaluationThread-12][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- PostureStatusPIP for mac B4-96-91-26-EB-A1 - Attribute Session.PostureStatus value is Unknown
2024-12-01 00:58:56,722 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.PostureHandlerImpl -:08C9C50A000000147BE04019:alice:::- handleGracePeriod - Device is compliant. Removing device with mac: B4-96-91-26-EB-A1 from grace period map
2024-12-01 00:58:56,723 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A000000147BE04019:alice:::- Last cache time period is not set, setting lastCompliant expiry time to 365 days
2024-12-01 00:58:56,723 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A000000147BE04019:alice:::- updating grace period for device with udid: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 , maclist: [B4:96:91:26:EB:A1], grace period expiry time 1764530936723 <------------Updating last known compliance status in DB (LAST_COMP_EXPIRY)
2024-12-01 00:58:56,723 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-10][[]] cisco.cpm.posture.edf.PostureUdid -:08C9C50A000000147BE04019:alice:::- Starting new thread for updateLastCompExpiryTime
1. Das Aktivieren oder Deaktivieren von LSD hat keine Auswirkungen auf den Status von Leasing und Compliance, da beide Attribute in der Oracle DB gespeichert und in der gesamten Bereitstellung repliziert werden. LSD speichert hingegen begrenzte EP-Attribute im Speicher und repliziert diese auf andere PSNs.
Wenn LSD aktiviert ist:
2. Um LSD zu aktivieren, navigieren Sie zu Administration > System > Settings > Light Data Distribution > Check RADIUS Session Directory.

3. EP verbindet sich zum ersten Mal und bearbeitet die Statusprüfung. Sobald das EP die Compliance-Anforderungen erfüllt, werden das Status-Lease und die letzten bekannten Compliance-Attribute in der DB aktualisiert:
2024-12-02 19:36:43,274 DEBUG [PolicyEngineEvaluationThread-11][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is enabled
2024-12-02 19:36:43,276 WARN [PolicyEngineEvaluationThread-11][[]] cisco.cpm.posture.runtime.PostureManager -:::::- Cannot find endpoint B4-96-91-26-EB-A1 in end point DB
2024-12-02 19:36:43,276 INFO [PolicyEngineEvaluationThread-11][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- not able to find user name in posture pip for B4-96-91-26-EB-A1 08C9C50A0000002B87B7D6EC. Set posture status to unknown
2024-12-02 19:37:27,164 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-5][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A000000227EB700E6::::- posture expriy time retrieved from DB is "" for B4-96-91-26-EB-A1
2024-12-02 19:37:29,110 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-6][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A0000002B87B7D6EC:alice:::- updating grace period for device with udid: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 , maclist: [B4:96:91:26:EB:A1], grace period expiry time 1733321249110 <--------------------Updated last known compliance status in DB
2024-12-02 19:37:29,113 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-6][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A0000002B87B7D6EC:alice:::- posture_bypass_test is null fast reconnect expiry time is 1733234849113 2024-12-03T19:37:29.113+0530
2024-12-02 19:37:29,113 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-6][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A0000002B87B7D6EC:alice:::- updating fast reconnect for end point B4:96:91:26:EB:A1 with 1 days of expiry time 1733234849113 <------Updated posture lease in DB
4. Dies sind die LSD-Attribute, die über das PSN verteilt sind. In den Attributen können Sie weder den Status für Statusleasing noch den letzten Compliance-Status sehen:
2024-12-02 19:37:32,221 DEBUG [LSD-consumers-pool-28][[]] cisco.cpm.lsd.service.SessionDirectory -:::::- Updating session sessionID:[08C9C50A0000002B87B7D6EC] status:[Authenticated] randomId:[0352b361-e72a-40e7-a0c8-b1ef779f73a5] auditSessionID:[08C9C50A0000002B87B7D6EC] accountingSessionID:[null] endpointMAC:[B4-96-91-26-EB-A1] callingStationId: [B4-96-91-26-EB-A1] endpointIP:[10.197.201.180], IPv6 : [[]], psnIP:[10.127.197.170] psnFQDN: [labpsn01.vmlab.local] deviceIP:[10.197.201.8] destinationIP:[10.127.197.170] nasIP:[10.197.201.8] nasIPv6:[null] postureStatus: [Compliant] timeStamp:[1733148451] cts:security-group-tag:[7] cts:vn:[null] proxyFlow:[null] retry count : 1
5. Nun authentifizieren Sie das EP mit einem anderen PSN in der Bereitstellung. Nachdem die Authentifizierungsanforderung auf einem anderen PSN landet, können Sie sehen, wie PSN die Leasedauer von der DB abruft und die Sitzung direkt als kompatibel markiert. Dies kann aus den Live-Protokollen überprüft werden:
2024-12-02 20:08:27,449 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-12-02 20:08:27,449 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is enabled
2024-12-02 20:08:27,468 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Querying posture expiry time by MAC B4-96-91-26-EB-A1
2024-12-02 20:08:27,471 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture expriy time retrieved from DB is "1733234849113" for B4-96-91-26-EB-A1
2024-12-02 20:08:27,471 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture lease expiry time 1733234849113 2024-12-03T19:37:29.113+0530 for B4-96-91-26-EB-A1
2024-12-02 20:08:27,472 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- retrieved fast reconnect expiry time 1733234849113 2024-12-03T19:37:29.113+0530 for B4-96-91-26-EB-A1
2024-12-02 20:08:27,472 DEBUG [PolicyEngineEvaluationThread-5][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- B4-96-91-26-EB-A1 is within fast reconnect expiry

1. Um LSD zu deaktivieren, navigieren Sie zu Administration > System > Settings > Light Data Distribution > Deaktivieren Sie RADIUS Session Directory.

2. EP verbindet sich zum ersten Mal und Prozesse durch die Haltung. Sobald das EP die Compliance-Anforderungen erfüllt, werden das Status-Lease und die letzten bekannten Compliance-Attribute in der DB aktualisiert:
2024-12-02 20:40:10,417 DEBUG [PolicyEngineEvaluationThread-9][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is enabled
2024-12-02 20:40:10,423 WARN [PolicyEngineEvaluationThread-9][[]] cisco.cpm.posture.runtime.PostureManager -:::::- Cannot find endpoint B4-96-91-26-EB-A1 in end point DB
2024-12-02 20:40:10,423 INFO [PolicyEngineEvaluationThread-9][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- not able to find user name in posture pip for B4-96-91-26-EB-A1 08C9C50A0000003087F1EE30. Set posture status to unknown
2024-12-02 20:40:45,679 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.GracePeriodUtil -:08C9C50A0000002E87E4FE87:alice:::- updating grace period for device with udid: 6d8a638f9acadd2851a6cd7eae947060a898ebc1 , maclist: [B4:96:91:26:EB:A1], grace period expiry time 1733325045679<--------------------Updated last known compliance status in DB (LAST_COMP_EXPIRY)
2024-12-02 20:40:45,682 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A0000002E87E4FE87:alice:::- posture_bypass_test is null fast reconnect expiry time is 1733238645682 2024-12-03T20:40:45.682+0530
2024-12-02 20:40:45,682 DEBUG [https-jsse-nio-10.127.197.170-8445-exec-1][[]] cisco.cpm.posture.runtime.PostureManager -:08C9C50A0000002E87E4FE87:alice:::- updating fast reconnect for end point B4:96:91:26:EB:A1 with 1 days of expiry time 1733238645682<------Updated posture lease in DB (EDF_POSTUREEXPIRY)
3. Jetzt authentifizieren Sie das EP mit einem anderen PSN in der Bereitstellung. Sobald die Authentifizierungsanforderung auf einem anderen PSN landet, können Sie sehen, dass der PSN die Leasedauer des Status von der DB abruft und die Sitzung direkt als kompatibel markiert. Sie können dies aus den Live-Protokollen überprüfen:
2024-12-02 20:49:56,115 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Posture status in session is not compliant
2024-12-02 20:49:56,115 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- fast reconnect is enabled
2024-12-02 20:49:56,119 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- Querying posture expiry time by MAC B4-96-91-26-EB-A1
2024-12-02 20:49:56,123 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture expriy time retrieved from DB is "1733238645682" for B4-96-91-26-EB-A1
2024-12-02 20:49:56,123 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.runtime.PostureManager -:::::- posture lease expiry time 1733238645682 2024-12-03T20:40:45.682+0530 for B4-96-91-26-EB-A1
2024-12-02 20:49:56,123 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- retrieved fast reconnect expiry time 1733238645682 2024-12-03T20:40:45.682+0530 for B4-96-91-26-EB-A1
2024-12-02 20:49:56,123 DEBUG [PolicyEngineEvaluationThread-10][[]] cisco.cpm.posture.pip.PostureStatusPIP -:::::- B4-96-91-26-EB-A1 is within fast reconnect expiry

Anhand dieser beiden Szenarien können Sie bestätigen, dass sich LSD nicht auf das Posture Lease auswirkt.
F: Sind Posture Lease und Cached Last Known Posture unabhängig voneinander?
A : Ja, das Statusleasing kann aktiviert werden, ohne dass das letzte bekannte Posture aktiviert wird und umgekehrt. Statusleasing speichert den Endpunkt-Compliance-Status als Endpunkt-Attribut für die konfigurierte Zeitdauer. "Letzte bekannte Status zwischengespeichert" ist die Zeit, die in der Datenbank gespeichert wird, während der der Kulanzzeitraum angegeben wird, wenn der Endpunkt nicht mehr konform ist (dies ist kein Endpunkt-Attribut).
F: Werden sowohl das Posture-Lease als auch das Cached Last Known Posture über die Knoten repliziert?
A: Posture Lease ist ein Endgeräteattribut und wird über alle Knoten repliziert. Cached Last Known Posture ist kein Endpunktattribut, der Wert befindet sich jedoch in Oracle DB und wird auch auf alle Knoten repliziert.
F: Werden diese Werte durch das Neustarten des Knotens entfernt?
A: Nein, da beide in der Oracle DB gespeichert sind und das Neuladen dieser Knoten die Werte nicht entfernt.
F: Führt das Posture Lease zu Sicherheitsproblemen?
A: Wenn die Statusleasing-Funktion aktiviert ist, sucht die ISE nicht nach dem Status des Endgeräts. Dies kann ein Sicherheitsproblem verursachen, wenn der Endpunkt nicht konform ist, und ISE kann es als Beschwerde behandeln. Es wird empfohlen, die Neubewertung der Statusüberprüfung zusammen mit dem Statusleasing zu verwenden, um dieses Risiko zu minimieren.
| Überarbeitung | Veröffentlichungsdatum | Kommentare |
|---|---|---|
2.0 |
19-Aug-2026
|
Aktualisierte Einführung, Rechtschreibung, Grammatik, eingefügte horizontale Linien in separate Abschnitte zur besseren Lesbarkeit, feste URLs und CCW-Fehler. |
1.0 |
20-Mar-2025
|
Erstveröffentlichung |