B Ise 31 RN
B Ise 31 RN
Release 3.1
First Published: 2021-08-03
Last Modified: 2025-03-18
Note Cisco ISE 3.1 OVA, ISO, and upgrade bundle files have been replaced on the Software Download site. For
more information, see Cisco ISE 3.1 Files Replaced on Software Download Site, on page 78.
For more information on these changes, see Integrate MDM and UEM Servers with Cisco ISE.
Wi-Fi Device Analytics Data from Cisco Catalyst 9800 Wireless LAN Controller
You can create profiling policies, authorization conditions, and authentication conditions and policies for
Apple, Intel, and Samsung endpoints, using device analytics data from the Cisco Wireless LAN Controllers
integrated with your Cisco ISE.
For more information, see "Wi-Fi Device Analytics Data from Cisco Catalyst 9800 Wireless LAN Controller"
in the Chapter "Asset Visibility" in the Cisco ISE Administration Guide, Release 3.1.
Cisco SNS 3715 appliance is designed for small deployments. Cisco SNS 3755 and Cisco SNS 3795 appliances
have several redundant components such as hard disks and power supplies and are suitable for larger
deployments that require highly reliable system configurations.
For more information, see the Cisco Secure Network Server 3700 Series Appliance Hardware Installation
Guide.
Note Cisco ISE 3.1 patch 6 and later versions support Cisco SNS 3700 series appliances. Hence, you cannot rollback
to ISE 3.1 after installing the first patch (ISE 3.1 patch 6 or later) on an SNS 3700 series appliance. Rollback
will fail in this case. You can re-install ISE 3.1 patch 6 or later from the CLI to recover the node.
You can configure both AnyConnect and Cisco Secure Client for your endpoints on these operating systems
but only one policy will be considered at run time for an endpoint.
Cisco ISE Release 3.1 Patch 3 supports Microsoft Intune integrations that use Microsoft Graph. To avoid any
disruption in the integration between Cisco ISE and Microsoft Intune, update your Cisco ISE to Cisco ISE
Release 3.1 Patch 3. Then, update your Cisco ISE integration in Microsoft Azure to use Microsoft Graph
instead of Azure AD Graph, before June 30, 2022. In Cisco ISE, you must update your Microsoft Intune
integrations to update the Auto Discovery URL field—Replace https://graph.windows.net<Directory
(tenant) ID> with https://graph.microsoft.com.
See Connect Microsoft Intune to Cisco ISE as a Mobile Device Management Server for more information on
the configuration steps.
• For a standalone Cisco ISE deployment, OCSP certificates are renewed automatically irrespective of
whether you install the patch through the Cisco ISE GUI or the Cisco ISE CLI.
• If you uninstall Patch 3, you have to renew the OCSP certificate manually.
This one-time OCSP certificate renewal process is because of the change in certificate hierarchy. For
more information, see Update of OCSP Responder Certificates in the "Basic Setup" chapter of the Cisco
Identity Services Engine Administrator Guide, Release 3.1.
OpenAPI Service
The following OpenAPIs have been introduced in Cisco ISE Release 3.1 Cumulative Patch 1:
• License
• Generate Self-Signed Certificate
• Patch and Hot Patch
• Deployment
For more information, see "Enable API Service" in the Chapter "Basic Setup" in Cisco ISE Administrator
Guide, Release 3.1.
OpenAPI Service
The following OpenAPIs have been introduced in Cisco ISE Release 3.1 Cumulative Patch 1:
• License
• Generate Self-Signed Certificate
• Patch and Hot Patch
• Deployment
For more information, see "Enable API Service" in the Chapter "Basic Setup" in Cisco ISE Administrator
Guide, Release 3.1.
If you choose the EST protocol, Cisco ISE will ask for additional password inputs from Android users while
issuing certificates.
For more information, see "Native Supplicant Profile Settings" in the Chapter "Compliance" in the Cisco ISE
Administrator Guide, Release 3.1.
• RBAC audit logs now include information regarding creation and deletion of existing menu access and
data access content.
• Network Access and Admin Users audit logs now include information regarding creation, edition, and
deletion of Network Access and Admin Users.
For more information, see "Export Endpoints Using CSV File" in the Chapter "Asset Visibility" in the Cisco
ISE Administrator Guide, Release 3.1.
Full Upgrade and Split Upgrade Options Added to Cisco ISE GUI
In the Administration > System > Upgrade> Upgrade Selection window, you can choose one of the
following options based on your requirements:
• Full Upgrade: Full upgrade is a multistep process that enables a complete upgrade of your Cisco ISE
deployment sequentially. This upgrades all the nodes in parallel and in lesser time compared to the split
upgrade process. Because all the nodes are upgraded parallelly, services will be down during the upgrade
process.
• Split Upgrade: Split upgrade is a multistep process that enables the upgrade of your Cisco ISE deployment
while allowing services to remain available during the upgrade process for users. With the split upgrade
option, you will be able to choose the nodes to be upgraded.
For more information, see "Upgrade a Cisco ISE Deployment from the GUI" in the Chapter "Upgrade Method"
in Cisco Identity Services Engine Upgrade Journey, Release 3.1.
OpenAPI Service
OpenAPIs are REST APIs based on HTTPS operating over port 443. From Cisco ISE 3.1 onwards, newer
APIs are available in the OpenAPI format. For more information on Cisco ISE OpenAPIs, see
https://<ise-ip>/api/swagger-ui/index.html.
The following OpenAPIs have been introduced in Cisco ISE 3.1:
• Repository Management
• Configuration Data Backup and Restore
• Certificate Management
• Policy Management
• RADIUS Policy
• TACACS+ Policy
For more information, see "Enable API Service" in the Chapter "Basic Setup" in Cisco ISE Administrator
Guide, Release 3.1.
• Red Hat
• 7.5
• 7.9
• 8.1
• 8.2
• 8.3
• 8.4
• 8.5
• 8.6
• 8.7
• 8.8
• 8.9
• 9.0
• 9.1
• 9.2
• 9.3
• SUSE
• 12.3
• 12.4
• 12.5
• 15.0
• 15.1
• 15.2
The following posture conditions are supported for Linux operating system:
• File Condition
• Application Condition
• Antimalware Condition
• Patch Management Condition
You can configure agent profiles for Linux clients. You can add client-provisioning resources for AnyConnect
Linux clients.
For more information, see the Chapter "Compliance" in Cisco ISE Administrator Guide, Release 3.1.
for the pxGrid client during client registration. An administrator can approve or deny the connection
request.
For more information about the PxGrid Client Auto Approval API, see the “pxGrid Settings” section in the
ERS SDK. You can access the ERS SDK with the following URL:
https://<ISE-Admin-Node>:9060/ers/sdk
Note Only users with ERS Admin role can access the ERS SDK.
Handle Random and Changing MAC Addresses with Mobile Device Management Servers
As a privacy measure, mobile devices and some desktop operating systems increasingly use random and
changing MAC addresses for each SSID that they connect to. In Cisco ISE, you can now work around this
problem by configuring Cisco ISE to use a unique device identifier called GUID instead of MAC addresses.
When an endpoint enrolls with a Mobile Device Management (MDM) server, the MDM server sends a
certificate with a GUID value to the endpoint. The endpoint uses this certificate for authentication with Cisco
ISE. Cisco ISE receives the GUID for the endpoint from the certificate. All communications between Cisco
ISE and the MDM server now use the GUID to identify the endpoint, ensuring accuracy and consistency
between the two systems.
For more information, see "Handle Random and Changing MAC Addresses With Mobile Device Management
Servers" in the Chapter "Secure Wired Access" in Cisco ISE Administrator Guide, Release 3.1
For more information, see the Chapter "Overview" in Cisco Identity Services Engine Upgrade Journey, Release
3.1.
For more information, see "Specific License Reservation" in the Chapter "Licensing" in the Cisco ISE
Administrator Guide, Release 3.1.
Note The output of show application status ise command reflects only the status of pxGrid 1.0 services.
System Requirements
For an uninterrupted Cisco ISE configuration, ensure that the following system requirements are fulfilled.
For more details on hardware platforms and installation of this Cisco ISE release, see the Cisco Identity
Services Engine Hardware Installation Guide.
Supported Hardware
Cisco ISE 3.1 can be installed on the following platforms:
Cisco SNS-3595-K9 (large) For appliance hardware specifications, see the Cisco Secure
Network Server Appliance Hardware Installation Guide.
Cisco SNS-3615-K9 (small)
Note • Cisco ISE 3.1 Patch 6 and later versions support Cisco SNS 3700 series appliances.
• Cisco ISE 3.1 does not support the Cisco Secured Network Server (SNS) 3515 appliance.
• Memory allocation of less than 16 GB is not supported for VM appliance configurations. In the event of
a Cisco ISE behavior issue, all the users are required to change the allocated memory to at least 16 GB
before opening a case with the Cisco Technical Assistance Center.
After installation, you can configure Cisco ISE with specific component personas such as Administration,
Monitoring, or pxGrid on the platforms that are listed in the above table. In addition to these personas, Cisco
ISE contains other types of personas within Policy Service, such as Profiling Service, Session Services,
Threat-Centric NAC Service, SXP Service for TrustSec, TACACS+ Device Admin Service, and Passive
Identity Service.
For Cisco ISE Release 3.0 and later releases, we recommend that you update to VMware ESXi 7.0.3 or
later releases.
You can deploy Cisco ISE on VMware cloud solutions on the following public cloud platforms:
• VMware cloud in Amazon Web Services (AWS): Host Cisco ISE on a software-defined data center
provided by VMware Cloud on AWS.
• Azure VMware Solution: Azure VMware Solution runs VMware workloads natively on Microsoft
Azure. You can host Cisco ISE as a VMware virtual machine.
• Google Cloud VMware Engine: Google Cloud VMware Engine runs software defined data center
by VMware on the Google Cloud. You can host Cisco ISE as a VMware virtual machine on the
software-defined data center provided by the VMware Engine.
Note From Cisco ISE 3.1, you can use the VMware migration feature to migrate virtual
machine (VM) instances (running any persona) between hosts. Cisco ISE supports
both hot and cold migration. Hot migration is also called live migration or
vMotion. Cisco ISE need not be shut down or powered off during the hot
migration. You can migrate the Cisco ISE VM without any interruption in its
availability.
You can deploy Cisco ISE natively on the following public cloud platforms:
• Amazon Web Services (AWS)
For information about the virtual machine requirements, see the Cisco Identity Services Engine Installation
Guide for your version of Cisco ISE.
• The following protocols are not supported in FIPS mode for RADIUS:
• EAP-MD5
• PAP
• CHAP
• MS-CHAPv1
• MS-CHAPv2
• LEAP
Validated Browsers
Cisco ISE 3.1 is supported on the following browsers:
• Mozilla Firefox 123, 125, 127, and later
• Mozilla Firefox ESR 102.4 and earlier versions
• Google Chrome 122, 124, 126, and later
• Microsoft Edge 122, 125, 126, and later
Note Currently, you cannot access the Cisco ISE GUI on mobile devices.
Note The supported Active Directory versions are the same for both Cisco ISE and Cisco ISE-PIC.
Cisco ISE supports Microsoft Entra ID.
Active Directory
Microsoft Windows Active Directory 2022 Windows Server 2022 with Patch
Windows10.0-KB5025230-x64-V1.006.msu
LDAP Servers
Token Servers
Any RADIUS RFC 2865-compliant token server Any version that is RFC 2865 compliant
Any SAMLv2-compliant Identity Provider Any Identity Provider version that is SAMLv2 compliant
PostgreSQL 9.0
Sybase 16.0
MySQL 6.3
Facebook Latest
1
Cisco ISE supports all the legacy features in Microsoft Windows Active Directory 2012 R2. However, the new features in
Microsoft Windows Active Directory 2012 R2, such as Protected User Groups, are not supported.
Microsoft Compliance Retrieval API Support for Ethernet MAC Address-based APIs
Microsoft Compliance Retrieval API currently does not support the Ethernet MAC attribute for MAC
address-based APIs. This limitation is addressed by Microsoft in January 2024. For wired deployments, we
recommended that you migrate to GUID-embedded certificates before upgrading to the following patches:
Cisco ISE Release 3.1 Patch 8, Cisco ISE Release 3.2 Patch 4, or Cisco ISE Release 3.3 Patch 1.
When multiple ClamWin products with 0.x version are listed in the Baseline Condition tab, if you select any
of those products and configure an antimalware condition, the preceding error message might be displayed.
In such a scenario, you must run the posture feed update one or more times to remove the multiple entries for
0.x version.
As a workaround, you can select a product from the Advanced Condition tab and configure an antimalware
condition for the ClamWin Pty Ltd vendor.
Authentication Might Fail for SNMP Users After Upgrade due to Wrong Hash Value
If you are upgrading from Cisco ISE 2.7 or earlier release to Cisco ISE 3.1, you must reconfigure the settings
for SNMP users after the upgrade. Otherwise, authentication might fail for SNMP users because of the wrong
hash value.
Use the following commands to reconfigure the settings for SNMPv3 users:
no snmp-server user <snmp user> <snmp version> <auth password> <priv password>
snmp-server user <snmp user> <snmp version> <auth password> <priv password>
in the Cisco ISE Admin CLI to enable or disable the current status of RSA_PSS signature for EAP TLS. It is
as follows:
[33]Enable/Disable/Current_status of RSA_PSS signature for EAP-TLS.
Cisco ISE Release 3.1 Patch 8 SLR registered Node shows SL registered post patch rollback
If you install Cisco ISE Release 3.1 Patch 8 or later releases on a Cisco ISE node, enable Specific License
Registration (SLR), and then roll back to an earlier release, the node is automatically registered to Smart
Licensing (SL) instead of SLR. In this case, you cannot return SLR because deregistration or update operations
will not work due to incorrect licensing configuration. This issue can be resolved through TAC intervention.
To avoid this, you must return SLR before rolling back to an earlier release. Each node has a unique code that
you must submit in the Cisco Smart Software Manager (CSSM) to return SLR. If you had enabled SLR before
installing Cisco ISE Release 3.1 Patch 8 or later, you do not have to return SLR before rolling back to an
earlier release.
Upgrade Information
Upgrading to Release 3.1
You can directly upgrade to Release 3.1 from the following Cisco ISE releases:
• 2.6
• 2.7
• 3.0
If you are on a version earlier than Cisco ISE, Release 2.6, you must first upgrade to one of the releases listed
above, and then upgrade to Release 3.1.
We recommend that you upgrade to the latest patch in the existing version before starting the upgrade.
Upgrade Packages
For information about upgrade packages and supported platforms, see Cisco ISE Software Download.
For more information, see the Cisco Identity Services Engine Upgrade Guide.
Telemetry
After installation, when you log in to the Admin portal for the first time, the Cisco ISE Telemetry banner is
displayed. Using this feature, Cisco ISE securely collects nonsensitive information about your deployment,
network access devices, profiler, and other services that you are using. This data will be used to provide better
services and more features in the forthcoming releases. By default, telemetry is enabled. To disable or modify
the account information, choose Administration > Settings > Network Settings Diagnostics > Telemetry.
The account is unique for each deployment. Each admin user need not provide it separately.
It may take up to 24 hours after the Telemetry feature is disabled for Cisco ISE to stop sharing telemetry data.
Types of data collected include Product Usage Telemetry and Cisco Support Diagnostics.
settings, see the "Specify Proxy Settings in Cisco ISE" section in the Cisco Identity Services Engine
Administrator Guide.
Client Provisioning and Posture Live Update Portals
You can download Client Provisioning resources from:
In the Cisco ISE GUI, click the Menu icon ( ) and choose Work Centers > Posture > Settings > Software
Updates > Client Provisioning.
The following software elements are available at this URL:
• Supplicant Provisioning wizards for Windows and Mac OS X native supplicants
• Windows versions of the latest Cisco ISE persistent and temporal agents
• Mac OS X versions of the latest Cisco ISE persistent agents
• ActiveX and Java Applet installer helpers
• AV/AS compliance module files
For more information on automatically downloading the software packages that are available at the Client
Provisioning Update portal to Cisco ISE, see the "Download Client Provisioning Resources Automatically"
section in the "Configure Client Provisioning" chapter in the Cisco Identity Services Engine Administrator
Guide.
You can download Posture updates from:
In the Cisco ISE GUI, click the Menu icon ( ) and choose Work Centers > Posture > Settings > Software
Updates > Posture Updates
The following software elements are available at this URL:
• Cisco-predefined checks and rules
• Windows and Mac OS X AV/AS support charts
• Cisco ISE operating system support
For more information on automatically downloading the software packages that become available at this portal
to Cisco ISE, see the "Download Posture Updates Automatically" section in the Cisco Identity Services Engine
Administrator Guide.
If you do not want to enable the automatic download capabilities, you can choose to download updates offline.
Procedure
For more information on adding the downloaded installation packages to Cisco ISE, see the "Add Client
Provisioning Resources from a Local Machine" section in the Cisco Identity Services Engine Administrator
Guide.
You can update the checks, operating system information, and antivirus and antispyware support charts for
Windows and Mac operating systems offline from an archive in your local system, using posture updates.
For offline updates, ensure that the versions of the archive files match the versions in the configuration file.
Use offline posture updates after you configure Cisco ISE and want to enable dynamic updates for the posture
policy service.
To download offline posture updates:
Procedure
Step 1 Go to https://www.cisco.com/web/secure/spa/posture-offline.html.
Step 2 Save the posture-offline.zip file to your local system. This file is used to update the operating system
information, checks, rules, and antivirus and antispyware support charts for Windows and Mac operating
systems.
Step 3 In the Cisco ISE GUI, click the Menu icon ( ) and choose Administration > System > Settings > Posture.
Step 4 Click the arrow to view the settings for posture.
Step 5 Click Updates.
The Posture Updates window is displayed.
Step 6 Click the Offline option.
Step 7 Click Browse to locate the archive file (posture-offline.zip) from the local folder in your system.
Note
The File to Update field is a mandatory field. You can select only one archive file (.zip) containing the
appropriate files. Archive files other than .zip, such as .tar, and .gz are not supported.
Configuration Prerequisites
• The relevant Cisco ISE license fees should be paid.
• The latest patches should be installed.
• Cisco ISE software capabilities should be active.
Ordering Information
For detailed Cisco ISE ordering and licensing information, see the Cisco Identity Services Engine Ordering
Guide.
These endpoint labels from Cisco AI Endpoint Analytics can be used by Cisco ISE administrators to create
custom authorization policies. You can provide the right set of access privileges to endpoints or endpoint
groups through such authorization policies.
Note If you installed a hot patch on your previous Cisco ISE release, you must roll back the hot patch before
installing a patch. Otherwise, the services might not be started due to an integrity check security issue.
Caveats
The Caveats section includes the bug ID and a short description of the bug. For details on the symptoms,
conditions, and workaround for a specific caveat, use the Cisco Bug Search Tool (BST).
Note The Open Caveats sections list the open caveats that apply to the current release and might apply to releases
earlier than Cisco ISE 3.1. A caveat that is open for an earlier release and is still unresolved applies to all
future releases until it is resolved.
Resolved Caveats
Resolved Caveats in Cisco ISE Release 3.1 - Cumulative Patch 10
Identifier Headline
CSCwn17599 SFTP server validation fails with Cisco ISE Release 3.3 Patch 3.
CSCwj54376 Evaluate Configuration Validator does not parse all NAD interfaces.
CSCwm48867 The swap-on or swap-off cron should be removed as it causes high load every 6 hours.
CSCwm10693 Cisco ISE internal users account disable policy feature does not work after one day of
inactivity.
Identifier Headline
CSCwk13234 Old Cisco ISE nodes are shown in TCP dump and debug profile configuration after
restore.
CSCwh54899 Unable to log in to Cisco ISE GUI. After entering the credentials, it hangs on checking
the credentials screen.
CSCwj71638 Policy hit count shows zero when fetched by Open API GET call.
CSCwf69715 After patch install TC-NAC adapters will be not reachable and new adapters cannot
be configured.
CSCwk47489 Cisco Identity Services Engine Arbitrary File Read and Delete Vulnerability.
CSCwh49351 The Cisco ISE admin portal SAML SSO should not redirect to another Cisco ISE node,
such as the active PSN.
CSCwm47216 Context leaks and stuck threads happen in the EWA flow involving MAB, Dot1x, and
Passive ID.
CSCwj32716 MDM configuration fails when the GUID in the client certificate is used to validate
the compliance of the device.
CSCwk07454 PSN does not update the database with the correct posture lease expiry time.
CSCwm58686 Passive session is not published to FMC as Cisco ISE tries to stitch the session.
CSCwi20027 The TrustSec deployment request fails as the CoA request gets stuck while fetching
NAD information.
CSCwj94294 Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabilities.
CSCwj94297 Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabilities.
CSCvy30859 In Cisco ISE Release 2.6, it is not possible to create static IP-SGT mapping for EPG's
imported from ACI.
CSCwk67197 Cisco ISE does not connect with external RADUIS server when proxy-state attribute
is missing.
Identifier Headline
CSCwk31930 Cisco ISE skips authentication against the child domain controller when the AD Forest
is marked offline.
CSCwk06043 Binding with SGT assigned through MAB policy is not seen in SGT bindings table.
CSCwj84724 Cisco ISE authorization profile does not persist "Security Group" data.
CSCwi59230 Non super-admin users cannot edit or delete endpoints when Cisco ISE has more than
1000 identity groups.
CSCwi72309 Cisco ISE is stuck in a profiling loop, slowing down replication, and causing errors.
CSCwm07116 For SMS gateway GET requests, the URL mapping is not visible in the guest.log.
CSCwj67089 Cisco ISE app server crashes while importing large files to secondary node through
local disk management.
CSCwk25064 SXP threads storing NULL objects in the Java heap are causing high CPU load and
utilization.
CSCwk13244 Cisco ise-messaging.log is not visible on Cisco ISE GUI for download.
CSCwj80616 Endpoint details in Cisco ISE context visibility does not match with RADIUS live logs
or sessions during MDM flow.
CSCwi59555 In Cisco ISE Release 3.2 Patch 4, the search for MAC address in the format is ignored.
CSCwd49321 Cisco ISE integration fails with Cisco pxGrid is not enabled on Cisco ISE error message
even when Cisco pxGrid is enabled in both nodes.
Identifier Headline
CSCwk75761 High CPU on admin node post accessing "Endpoint Identity Groups" page on Cisco
ISE.
CSCwh72754 Cisco ISE active directory process stuck at "Updating" which consumes 90 to 100%
CPU.
CSCwk91976 The Cisco ISE GUI does not ask confirmation of old password for password change.
CSCwm47768 Cisco ISE portals show Ukrainian when browser language is Russian.
CSCwm46079 SXP mappings is not learned for VPN users private IP.
CSCwj94305 Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabilities.
CSCwk35172 The "DumpClearOnExceed" files filling up the disk on Cisco ISE PSN nodes.
CSCwm61668 TC-NAC_Tenable throws "Scan Failed: Error in connecting to host: 403 Forbidden"
error.
CSCwk75775 The health check fails on input or output bandwidth performance check and returns a
NULL result.
CSCwj82298 Assigned logical profile is repeated in context visbility endpoint attributes and reports.
CSCwj94315 Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabilities.
CSCwm13073 With less than 3000 SGTs, Cisco ISE throws "This Custom View has exceeded the
maximum number of SGTs (3000)." error.
CSCwj89479 When joining multiple Cisco ISE nodes to the domain controller simultaneously,
duplicate accounts are created.
CSCwm73142 The app-server crashes if NAD sends radius accounting without radius settings enabled.
CSCwm51099 Sponsors from different GROUP_ACCOUNTS groups can see all users if they are in
the same OWN_ACCOUNTS.
Identifier Headline
CSCwi74567 Inconsistencies in the database cause corruption in the Cisco ISE portal.
CSCwk11836 TACACS livelogs and reports get impacted during rollback of Cisco ISE Release 3.1
Patch 8 to Patch 7.
CSCwc62131 Cisco ISE is not able to query MySQL 8.x as mysql.proc table is not implemented.
CSCwj52266 Endpoint description in the Context Visibility page is updated with the Static Identity
Group description.
CSCwm32937 Cisco ISE does not respond to specific accounting packets, resulting in an incorrect
IP update in the system.
CSCwk47465 Cisco Identity Services Engine XML External Entity Injection Vulnerability.
CSCwk52844 Insufficient page authentication across various pages such as repository and admin
groups of Cisco ISE.
CSCwk63893 UDP syslog DNS name resolution must be done in a single function call instead of
two (IPv6+IPv4).
CSCwd96743 Log collection error observed for the Server=xxxx with the log type "Radius
Authentication Passed".
CSCwm12379 Asset probe data is cleared when MAB authenticated clients reauthorize.
CSCwf24553 Umbrella defect to provide information for terminologies used in the Licensing page.
CSCwf24554 Umbrella defect to display more information on Smart Lincensing registration failure.
Identifier Headline
CSCwh92185 RADIUS Authentication report exported from the operational data purging page is
empty.
CSCwi42628 MAR cache replication fails between peer nodes for both NIC and non-NIC bonding
interfaces.
CSCwi21020 Cisco ISE messaging certificate generation does not replicate a full certificate chain
on secondary nodes.
CSCwi15914 Additional IPv6-SGT session binding is created for IPv6 link local address from SXP
ADD operation.
CSCwi88504 Missing step and resolution text in live logs for attribute.
CSCwc85211 Cisco ISE Passive ID agent error "id to load is required for loading".
CSCwh92366 Insufficient virtual machine resource alarm is observed in Cisco ISE Release 3.1 Patch
8 longevity setup.
CSCwc58608 Cisco ISE 3.2 crashes when RADIUS request is received with EAP-FAST and EAP
chaining.
CSCwf89224 Decryption of session ticket received from the client fails on Cisco ISE.
CSCwh90610 Abandoned jedis connections are not being sent back to the thread pool.
CSCwf80386 Current value of Disable_RSA_PSS environmental value is not saved after patch
installation.
CSCwh56565 PPAN rest call to MNT nodes (live logs, reports) should not be load balanced.
Identifier Headline
CSCwh79938 Cannot set preferred Domain Controllers registry value in advanced tuning.
CSCwa82035 Cisco ISE Serviceability - Include garbage collector logs, thread dump, heap dump.
CSCwi73984 Installed patches menu does not list all the patches.
CSCwh45472 Operational backups from the GUI fail to SFTP repositories if the PKI key pair pass
phrase contains the symbol +.
CSCwi66126 Updating DACL using ERS API does not modify last updated timestamp.
CSCwe92640 Cisco ISE Releases 3.1 or 3.2 are missing validation for existing routes during CLI
configuration.
CSCwh77574 Cisco ISE does not allow special characters in password while importing certificates.
CSCwh69045 Some internal users' passwords do not expire after the configured global password
expiry date.
CSCvz91952 Some Cisco ISE users are able to avoid mandatory password reset on the next login.
CSCwi38493 Advance license consumption issue is seen in Cisco ISE Release 3.1 Patch 7.
CSCvm56115 Cisco ISE allows to save the policy when an identity store is deleted from another
browser tab.
CSCwj01310 8 Node longevity - intensive garbage collection observed due to SXP component.
CSCwf38083 Cisco ISE services are stuck in initializing with secure syslog.
Identifier Headline
CSCwh71435 Cisco ISE ERS API creates enable password option of the internal users even though
enable password field is not specified.
CSCwh25160 Swap cleanup script to drop the swap area and program the cron.
CSCwc44298 Failed to delete self registration portal: throws 500 server error.
CSCwf56826 Observing cores related to jstack on the PPAN nodes of regression setup.
CSCwh42683 Read-only admin group users have full accesss when logging into Cisco ISE GUI
through SAML authentication.
CSCwe37377 Cisco ISE CRL retrieval failed alarm does not mention server on which CRL download
failed.
CSCwc33290 Unable to delete custom endpoint attributes due to malfunctioning of "trash" button.
CSCwa97036 Unable to bind Cisco ISE messaging service with SubjectAltName extension while
using wildcard certificate.
CSCwf83193 Unable to login into the secondary admin node Cisco ISE GUI using AD credentials.
CSCwe89459 Cisco ISE REST API documentation provides incorrect script while creating endpoint
group.
CSCwf25955 A match authorization profile with SGT, VN name, VLAN fields empty causes port
to crash.
CSCwh18487 Expired guest accounts don't receive SMS when they try to reactivate account.
CSCwh71273 Disabled essential license leads to limited Cisco ISE GUI page access and inability to
regenerate root CA.
CSCwh52589 During first device connection attempt, Cisco ISE does not update the Acs.Username
field with the guest username.
Identifier Headline
CSCwf68108 The OpenAPI for endpoints are not working for the existing IOT asset attributes.
CSCwf40861 When command set includes special characters, the UI shows HTML hexadecimal
instead of the character.
CSCwh50304 API query of ERS the network device component returns primary shared secrets for
primary and secondary fields.
CSCwe72097 Unable to launch sponsor portal after edits to interface on the existing portal.
CSCwd12453 Cisco ISE Release 3.1 and Release 3.0: Portal tag with special character faces validation
issues.
CSCwb63834 MNT log processor is enabled on non-MNT admin Cisco ISE node.
CSCwf22794 Inconsistency in VLAN ID results in erorr message: Not a valid ODBC dictionary.
CSCvq79397 UI pages are not loading properly with custom admin menu workcenter permissions.
CSCwh51156 Cisco ISE cannot load corrupted NAS profiles that causes authorization drops due to
failure Reasons 11007 and 15022.
CSCuz65708 Numbering issues observed for DACL entries in Firefox 45 and Chrome 72, and all
later issues.
CSCwc47799 Cisco ISE is unresponsive while importing certificate when the special character (%)
is added in the private key password field or the friendly name field.
CSCwe11676 Data is lost when accessing total compromised endpoints in Cisco ISE dashboard threat
for TC-NAC.
Identifier Headline
CSCwf72037 Cisco ISE Release 3.1: Administrator login report displays "administrator authentication
failed" in 5 min intervals.
CSCwf40128 Accept client certificate without KU purpose validation as per Cisco SSL rules.
CSCwh17448 Cisco ISE Release 3.1: Agentless posture flows fails when domain user configures for
endpoint login.
CSCwf07855 Cisco ISE SXP bindings API call returns 2xx response when the call fails.
CSCvj75157 Cisco ISE API doesn't recognize identity groups while creating user accounts.
CSCwf61673 From Cisco ISE CLI, read-only users can not run a show CPU usage command.
CSCwd57628 NAD RADIUS shared secret key is incorrect when it starts with an apostrophe on
Cisco ISE Release 3.1 Patches 1, 2, 3, 4, and 5.
CSCwc57630 Cisco ISE Release 3.2 BETA: GUI is not accesible after enabling TLS 1.0.
CSCwe10898 An endpoint's MAC address is not added to the endpoint identity group when using
grace access in the guest portal.
CSCwf22527 Context Visibility: Unable to filter endpoint custom attributes with special characters.
CSCwf96294 Cisco ISE Release 3.0: Disabled domains in allowed domains makes connection
attempts to ad_agent.log domains.
CSCwh05599 Cisco ISE sponsor portal shows invalid input error when using special characters in
the guest type name.
CSCwc53915 Cisco ISE Release 3.1 shows "error creating 1 domain controller" already exists,
although it is a new deployment.
CSCwf88944 Guest portal FQDN is mapped with IP address of the node in the database.
CSCwf17490 Post SL update, Cisco ISE licensing page shows evaluation compliance status for
consumed licenses.
CSCwd38766 Hexadecimal username stays in the database even after deleting SNMPv3 username
with "-" or "_" characters.
Identifier Headline
CSCwe74135 Cisco ISE Release 3.1 Patch 5: Attempting to delete Guest portal after PAN failover
fails.
CSCvo60450 Enhancement for encryption should only send AES256 for MS-RPC calls.
CSCvw81130 Cisco ISE Release 2.7: Unable to disable active directory diagnostic tool scheduled
tests.
CSCwe86793 Cisco ISE filter of REST ID store groups displays error processing this request.
CSCwd34685 Cisco ISE messaging service flapping between "not running" and "initializing".
CSCwf30570 Agentless posture script does not run when the endpoint is not connected to an AC
power source.
CSCwf24158 Terms and conditions checkbox disappears when portal builder is used for Cisco ISE
Release 3.0 and higher.
CSCvv90394 Cisco ISE Release 2.6 Patch 7 is not able to match "identityaccessrestricted equals
true" in authorization policy.
CSCwf94289 Cisco ISE Release 3.0 Patch 6: Policy export fails to export the policies.
CSCwh23367 In Cisco ISE Release 3.2 , the self-registered email subject line truncates everything
after the equal (=) sign on the sponsor guest portal.
CSCwf31073 Cisco ISE: "Error 400" displaying when fetching device admin network conditions
via OpenAPI.
CSCwf09393 Cisco ISE Release 3.1 services failed to start after restoring backup from Cisco ISE
Release 2.7.
CSCwc70197 Cisco ISE certificate API fails to return trusted certificate with special characters in
friendly name.
CSCwf34391 Cisco ISE EasyConnect stitching does not happen when the PassiveID syslog is received
by MnT before the active authentication syslog.
CSCwe71804 Cisco ISE Release 3.1: Key attributes is missing in session cache when third-party
network device profile is in use.
CSCwh33160 Cisco ISE is not sending SNMPv3 disk traps to configured SNMP server.
CSCvy88380 Unable to select Cisco ISE messaging usage for an existing certificate as it is grayed
out.
Identifier Headline
CSCvq43600 Even with disabled PSN persona the TACACS port 49 is still open.
CSCwh21038 Session info is not stored in timed session cache during third party posture flow.
CSCwe22841 ANC with Aruba switches sends incorrect AVP's when invoked.
CSCwf09364 The user identity group and endpoint identity group description fields have a character
limit of 1199.
CSCwe78540 IoT asset information is missing when "get all endpoints" option is in use.
CSCwc04447 Cisco ISE Release 2.7 Patch 6 is unable to filter TACACS live logs by network device
IP.
CSCwh30893 Profiling is not processing calling station ID values with the following format:
XXXXXXXXXXXX.
CSCwe43468 Static IP-SGT mapping with VN reference causes DNAC group-based policy sync to
fail.
CSCwh10401 Cisco ISE Release 3.1 Patch 5: Cannot generate pxGrid client certificate leveraging
the CSR option.
CSCwh70275 While registering node with left over certificates from deregistration, the certificates
that are currently in use get deleted.
CSCwf47038 Trash all or selected option at pxGrid policy should not touch entries for internal group.
CSCwf07444 Cisco ISE patch GUI installation is stuck on a specific Cisco ISE node in deployment.
CSCwh04251 Cisco ISE agentless posture does not support password containing a colon.
CSCwe00424 SQL exception sent to the collection failure alarm is caused by NAS-Port-id length.
CSCwe86494 Cisco ISE dispalys tomcat stacktrace when a specific URL is in use.
CSCwf80292 Cisco ISE cannot retrieve a peer certificate during EAP-TLS authentication.
CSCwf66237 "Get all endpoints" option request takes much longer time to execute since Cisco ISE
Release 2.7.
CSCwf59058 RBAC policy with custom permissions is not working when administration menu is
hidden.
CSCwe41824 Cisco ISE Release 3.2 is missing S-PAN key for PKI-based SFTP.
CSCwd82119 EAP-TLS authentication with ECDSA certificate fails on Cisco ISE Release 3.1.
Identifier Headline
CSCwf66880 Endpoint .csv file import displays "no file chosen" after selecting the file.
CSCwf26482 REST AUTH services are not running after upgrade from Cisco ISE Release 3.1 to
Release 3.2.
CSCwd17322 Cisco ISE in AWS: Health check I/O bandwidth performance check false alarm.
CSCwe27438 Launch page level help is not working for patch management, upgrade, and health
checks.
CSCwb18744 Group Based Policy Security Groups or Access Contracts with multiple backslash
characters in a row in the description causes data sync failure.
CSCwf37679 Sponsor permissions are disabled on sponsor portal when accessed from the primary
PAN persona.
CSCwc22988 Disabling "disclose invalid usernames" shows popup that states displaying app server
will restart.
CSCwe99961 Sponsored portal in Germany calendar shows Thursday (Donnerstag) as Di not Do.
CSCwf39620 Agentless posture is not working in Windows if the username starts with the special
character '$'.
CSCwf23981 Cisco ISE authorization profile displays wrong security group and VN value.
CSCwf61939 Using an apostrophe in the first name and/or last name field presents an invalid name
error.
CSCwc36589 Cisco ISE Intune MDM integration may disrupt due to end of support for MAC
address-based APIs from Intune.
CSCwf36285 The quick filter option for SXP domains is unusable if more than 25 rows are displayed.
CSCwe53550 Cisco ISE includes a version of Apache Commons FileUpload that is affected by the
vulnerabilities with CVE ID CVE-2023-24998 .
CSCwf82055 Unable to disable SHA1 for ports associated with passive ID agents.
CSCwh53159 Cisco ISE Release 3.1 Patch 7: Unable to change admin password if it contains special
character '$'.
Identifier Headline
CSCwh65018 Cisco ISE Release 3.1 Patch 5 install hangs indefinitely, and updates timesten
sys.odbc.ini for TCNAC.
CSCwb44638 Enhancement: Include a seperate log file with MNT database metrics.
CSCwf10004 Cisco ISE IP SGT static mapping is not sent to SXP domain even after shift to another
mapping group.
CSCwf21960 During upgrade, the deregister call fails to remove all the nodes from the databse.
CSCwf71870 TACACS deployment with zero day evaluation does not work after registering to smart
licensing.
CSCwf42496 Attempt to delete 'Is IPSEC Device' NDG causes all subsequent RADIUS/T+
authentications to fail.
CSCwc44622 Session gets stuck indefinitely when NAD (Meraki) misbehaves unless restarted.
CSCwf79310 Cisco ISE Release 3.1 Patch 7: No virtual networks visible under security group in
authorization profile.
CSCwh51136 Cisco ISE drops RADIUS request with the message "request from a non-wireless
device was dropped".
CSCwe37826 Unable to change the condition operator from AND to OR in posture policy condition.
CSCwf33018 Fix to the bug CSCwd35608 is causing CoA calls from UI to be sent to the wrong IP.
CSCwf19039 Cisco ISE Release 3.1 Patch 5: Agentless posture failures cause /tmp/ folder size
increase.
CSCwf22816 Authorization based on internal user ID group fails without the RADIUS-token
authorization for VPN.
CSCwf31477 Profiler is triggering a port bounce when multiple sessions exist on a switch port.
CSCwf41103 Cisco ISE Admin CLI reset-configuration fails to reset bond interfaces.
CSCwd39746 SCCM integration with Cisco ISE needs MSAL support as MS is deprecating ADAL.
CSCwf55641 German and Italian emails cannot be saved under account expiration notification in
guest type.
Identifier Headline
CSCwh28528 TopN Device and admin reports doesn't work when TACACS incoming exceeds 40M
records per day.
CSCwh41693 Cisco ISE on AWS doesn't work if metadata (IMDS) version value "V2 only" is
selected.
CSCwe12618 Cisco ISE Release 3.2:Unable to receive IP-to-SGT mappings from APIC.
CSCwe96739 TLS 1.0 or 1.1 is accepted at Cisco ISE Release 3.0 admin portal.
CSCwe03624 Smart license registration failure with "communication send error" alarms displays
intermittently.
CSCwf81550 Cisco ISE changes the MAC address format to an unacceptable MAC adress format.
CSCwf54680 Unable to edit or delete authorization profiles with parentheses in the name.
CSCwh38484 Manually deletion of the static route causes Cisco ISE to send packet with wrong MAC
in Release 3.0 patch 7.
CSCwf40265 Cisco ISE maximum session counter time limit is not working.
CSCwe87660 Cisco ISE Release 3.1: Previous version hotpatch is visible in the database.
CSCwf59005 Cisco ISE Release 3.2 Patch 3: PEAP and EAP-TLS does not work on FIPS mode.
CSCwb72948 Cisco ISE Release 3.0 Patch 4 is unable to access system certificates page for the
registered node.
CSCwf59310 Cisco ISE Release 3.1 Patch 7: GUI is missing custom attributes delivered via pxGrid
ContextIn.
CSCvv99093 Cisco ISE nodes intermittently triggers queue link alarm: cause=timeout.
CSCwh05647 Static IPv6 routes are removed after a reload in Cisco ISE Release 3.2.
CSCwb69830 RADIUS Vendor specific integer attributes are visisble as garbage in debug logs.
CSCwe30021 The syslog audit record for the certificate authentication failure is absent due to an
internal error.
Identifier Headline
CSCwi06794 The RADIUS live log delay issue caused by a problem in indexation is fixed.
CSCwh99772 All network device groups are deleted when a child item is removed from any group.
CSCwh44407 Cisco ISE Release 3.2 API: System certificate import does not work for a Cisco ISE
node in the deployment.
CSCwf26226 CPU spike due to memory leak with endpoints purge call
CSCwe37041 Internal CA certificate chain becomes invalid if the original primary PAN is removed
CSCwe25138 Cannot create identity user if the user custom attribute includes characters '$' or '++'
CSCwe80760 Unable to save launch program remediation when the parameter contains double quotes
("")
CSCwd84055 Cisco ISE Release 3.1 Azure AD autodiscovery for MDM API v3 is incorrect
CSCwe52461 Unable to enable the firewall condition in Cisco ISE Release 3.1
CSCwe37978 When you export a scheduled report of a large size, it is displayed as empty in the
repository
CSCwe37018 Cisco ISE-DNAC integration fails if there are invalid certificates in the Cisco ISE
trusted certificates store
CSCwd31414 Guest portal displays the error loading page when the reason for visit field contains
special characters
CSCwe15315 TrustSec PAC information field attribute values are lost when you import a network
device CSV template file
Identifier Headline
CSCwd97022 Cisco ISE-PIC Release 3.2 FCS: smart licensing: PIC upgrade: out of compliance
CSCwd87161 Cisco ISE Release 3.1: certificate-based login asks for license file if only the device
admin license is enabled
CSCwe63873 Qualys adapter is unable to download the knowledge base. Stuck at knowledge
download in progress
CSCwd97551 Cisco ISE cannot retrieve OU attributes from client certificate in EAP-TLS session
resumption
CSCwb28410 '/' in command arguments is not preserved after CSV import of the T+ command set
CSCwd71496 Cisco ISE does not delete sessions from all SXP mapping tables
CSCwc13859 Unable to create scheduled backup with admin user from 'system admin' admin group
CSCwe49167 Cisco ISE Release 3.2: SAML sign authentication request setting is unchecked upon
save
CSCvx15522 DNS cache enabling command in FQDN syslog popup needs correction
CSCwe49261 Cisco ISE Release 3.1: passiveID - probes agents for status of all domains being
monitored
CSCwc64480 When importing a new certificate for a portal, Cisco ISE fails to establish secure
connection
CSCwe37041 Internal CA certificate chain becomes invalid if original primary PAN is removed
CSCwe49183 Cisco ISE SAML destination attribute is missing for signed AuthnRequests
CSCwc05718 Cisco ISE debug wizard posture profile does not contain client-webapp component to
DEBUG
CSCwe54466 Sponsor portal print issue for from-first-login guest account expire details
CSCwe30606 Not able to download support bundles greater than 1 GB from the GUI
Identifier Headline
CSCwe24932 Agentless posture fails when using multiple domain users in the endpoint login
configuration
CSCwe57764 MDM: connection to Microsoft SCCM fails after Windows DCOM server hardening
for CVE-2021-26414
CSCwe43002 Read-only admin is not available for Cisco ISE admin SAML authentication
CSCwd69072 Session directory write fails with the alarm Cisco NAD using user-defined NAD profile
CSCwb79496 WMI status shows progress after mapping from agent protocol to WMI protocol
CSCwe34566 Authentication against ROPC identity store fails with RSA key generation error
CSCwd73282 Cisco ISE Release 3.1 patch 3: sponsor portal: session cookie SameSite salue is set to
none
CSCwe64558 Admin account created from network access users cannot change dark mode setting
CSCwe70975 SMS Javascript customization is not working for SMS email gateway
CSCwc99816 Cisco ISE OpenApi restore displays complete long before show command displays
complete
CSCwe45245 Smart license registration is not working. Error while enabling the smart license
CSCwe13110 Cisco ISE Release 3.1 configuration backup executed on primary MNT node
CSCwe39781 Cisco ISE does not remove SXP mapping when SGT is changed after CoA
CSCwd74898 Posture configuration detection alarms should be INFO level and reworded
CSCwd64649 Cisco DNA Center integration issue due to more internal CA certificates
Identifier Headline
CSCwe41695 Cisco ISE 3.patches 4 and 5: standalone ISE crashes if restarted after removing admin
access restriction
CSCwd63749 ISE 3.1 AD Retrieve Groups shows a blank page when loading a big number of AD
groups 400+
CSCwb77915 Toggle to enable/disable RSA PSS cipher based on policy under Allowed Protocols
CSCwd35608 ISE is sending old Audit Session ID in reath CoA after previously successful
port-bounce CoA
CSCvt62460 Unable to retrieve groups/attr from diff LDAP when defined per node
CSCwd70902 PRRT should be sending unfragmented messages to MnT if IMS is enabled to avoid
merge
CSCwd55061 ERS API internal error seen while creating existing NDG
CSCwd47111 ISE is unable to save the Subnet/IP Address Pool Name for voice vlans.
CSCwd13201 UI crashed while loading authz policy on chrome and edge browser
CSCwe07354 Radius Token Server config accepts empty host IP for Secondary Server
CSCwd57071 Self-reg portal does not support nodes fqdns for the Approve/Deny links sent to the
sponsors.
CSCvv54351 Device Administration using Radius does not consume base license
CSCwd41773 ISE 3.1: Application server crashes if CRL is downloaded frequently having size 5
MB or more.
CSCwd97606 Multiple requests for same IP+VN+VPN combinations with diff session ID creating
duplicate records
Identifier Headline
CSCwd94235 31p5 : app server and api gateway service not running
CSCwc93253 ISE - Network device captcha only prompting when filter matches only 1 Network
device
CSCwd31137 ISE scheduled radius authentication repots failed while exporting to SFTP repository
CSCwc87670 ISE 3.1 patch 3 unable to import endpoints from csv file if SAML is used
CSCvv47849 [CFD] Mapped SGT entry cleared from AuthZ Rules on ISE if SG name is modified
in Cisco DNA Center
CSCwc44580 ISE 3.1 creates cni-podman0 interface with IP 10.88.0.1 and ip route for 10.88.0.0/16
CSCwd22790 URI not Accepted as Group attribute or as Name in Assertion of attributes for SAML
IdP in 3.1/3.2
CSCvy69943 ENH: Allow Guest Portal HTTP Requests Containing Content-headers with {}
Characters
CSCwa55233 Queue Link Errors "Unknown CA" when utilizing third-party signed certificate for
IMS
Identifier Headline
CSCwc48311 ISE vPSN with IMS performance degrades by 30-40% compared to UDP syslog
CSCwd16837 ISE openAPI HTTP repo patch install fails when dir listing is disabled
CSCwe34204 ISE upgrade tab shows upgrade in progress after installing patch
CSCwe07406 Error Loading Page error is output when creating a guest account in the Self-Registered
Guest Portal
CSCwc98828 Cisco Identity Services Engine Interface Feature Insufficient Access Control
Vulnerability
CSCwd63661 ISE 3.1 p1 : Entering incorrect password on GUI shows end user agreement
CSCwe13947 OpenAPI for EP create/update should work same as ERS API in addition to providing
more functionality
CSCwd97582 ISE 3.1p5 verifies CA certificate EKU causing "unsupported certificate" error
CSCwd51409 ISE cannot retrieve repositories and scan policies of Tenable Security Center
CSCwd74560 PUT operation failing with payload via DNAC to ISE (ERS)
CSCwd15888 Not able to access Time Settings Configuration Export on ERS API
CSCwc85867 ISE Change Configuration Audit Report does not clearly indicate SGT create and
delete events
Identifier Headline
CSCwd70658 Unable to add Network Access Device. Reason: "There is an overlapping IP Address
in your device"
CSCvy33393 ISE 3.1 BH Context visibility shows \\ in username where as live logs show correct
single \
CSCwc85546 ISE 3.1 ENH "Illegal hex characters in escape (%) pattern ? For input string: ^F"
CSCwd10864 Cisco Identity Services Engine XML External Entity Injection Vulnerability
CSCwd45783 pxGrid session publishing stops when reintergrating FMC while P-PIC is down
CSCwd98296 Network Device Port Conditions -IP Addresses/Device Groups- doesn’t accept valid
port strings.
CSCwc53895 ISE 3.1 P3 SAML SSO Doesn't work if active PSN goes down
CSCwc99178 Not able to add too many Authorization Profiles with active session alarm setting
CSCwd57978 All NADs are getting deleted while doing Filter on NDG Location and IP
CSCwd13555 ISE abruptly stops consuming passive-id session from a 3rd party Syslog server
CSCwd93002 Getting System Error : Null while editing the groups and adding Name in Assertion
under SAML
CSCwc07082 "The phone number is invalid" when trying to import users from csv file.
CSCwd89657 ISE 3.1 certain SFTP servers stopped working after upgrade to patch 4/5
CSCvv02086 Add ability to disable TLS 1.0 and 1.1 on ISE PIC node
CSCwe44750 Persisting of Reprofiling result is not updating to Oracle/VCS after feed incremental
update
CSCwe63320 ISE 3.2/3.1/3.0 displays mismatched information on "Get All Endpoints" report
CSCvv54798 Context Visibility CVS exported from CLI not showing IP Addresses
Identifier Headline
CSCwc74531 ise hourly cron should cleanup the cached buffers instead of the 95% memory usage
CSCwc64346 ISE ERS SDK network device bulk request documentation is not correct
CSCwc57240 GUI not validating default value while adding custom attributes
CSCwc26241 ISE 3.2 displays the error: "TypeError: Cannot read properties of undefined (reading
'attr')"
CSCwc21400 HTTP 400 response in Repo OpenAPI when an SFTP/FTP repo user password contains
! (exclamation mark)
CSCwc85920 ISE TrustSec Logging - SGT create event is not logged to ise-psc.log file
CSCwb23853 Unable to add SAML ID provider on 3.1 p1 when we did config restore from older
ISE
CSCwc21890 Passive Easy connect does not work in ISE with Dedicated MnT nodes
CSCwb62192 scheduled backup failure when ISE indexing engine backup failed
CSCwc65821 ERS API doesn't allow for use of minus character in "Network Device Group" name.
CSCwc71060 Deleted network device groups still showing up in the policy sets
Identifier Headline
CSCwc79321 Unable to change the Identity source from internal to external RSA/RADIUS-token
server
CSCwc64275 Precheck may get timedout with optimistic locking failed in ise-psc.log on ppan
CSCwc61320 Slowness on Support Bundle page due to Download Logs page loading in the
background.
CSCwc09435 Error handling/ messaging for mobile number format not clear
CSCwc51219 CSV NAD import is rejected if += characters are at the beginning of the RADIUS
shared secret
CSCwc57294 Duplicate Manager doesn't remove packet when there is an exception in reading config
CSCwc95878 Intermittent issues with App activation or App not receiving events
CSCwc81729 "All devices were successfully deleted" after trying to delete one particular NAD by
filtering
CSCwc23997 ISE is showing Incorrect VLAN assignment Information in Authorization profile >
Attributes Details
CSCwc15013 Add serviceability & fix "Could not get a resource since the pool is exhausted" Error
on ISE 3.0
CSCwc59570 ISE sending SXP MSG size > 4096 bytes in SXP Ver 4
CSCwb53455 RMQ TLS syslogs related to internal docker ip 169.254.2.2 are sent to Audit logs
CSCwa55866 Tacacs responses are not sent sometimes with single connect enabled
CSCwb24002 ISE ERS SDK the authenticationSettings are not disabled via API call
CSCwc95075 "File path field must contain a valid file name" error when configuring file conditions
for posture.
Identifier Headline
CSCvz65945 "Invalid Length" TACACS Auth Failures within Live Logs for non-TACACS traffic
CSCwb27894 EAP-TEAP with EAP-TLS unable to match condition that has "CERTIFICATE.Issuer
- Common Name"
CSCwc74206 ISE 3.0 not saving SCCM MDM server object with new password, works when new
instance is use
CSCwb48388 Licensing only displays one reserved count if licenses reserved in CSSM have multiple
expiry dates
CSCwc50944 The change of profiling policy name is not reflected on the policy set conditions
automatically
CSCvz91479 Schema upgrade failed while modifying constraints for 3.1->3.2.0.804 upgrade
CSCwc60997 ISE: SAML flow with loadbalancer is failing due to incorrect token handling on ISE
CSCwc49580 ANC COA is sent to the NAS ip address instead of the Device ip address.
CSCwc44614 Using "Export Selected" under Network Devices aborts to login screen w/ more than
X selections
CSCwc48509 Windows Server 2022 is actually working as the target domain controller to be
monitored
CSCwc93451 Profiler should ignore non-positive RADIUS syslog messages for forwarding from
default RADIUS probe
CSCvv54351 Device Administration using Radius does not consume base license
CSCwd30994 ISE : Static default route with gateway of interfaces other than Gig 0 breaks network
connectivity
CSCwc30643 My Devices Portal doesn't open after reloading the node unless we do CRUD.
CSCwc88848 ISE 3.1 Patch 1 does not created the Rest ID/ROPC folder logs
CSCwb64656 When Essential License is disabled on the Cisco ISE GUI, the Smart Licensing Portal
does not report license consumption.
CSCwb39638 Unable to import network device configured with SNMPv3 SHA2 authorization
CSCwa61347 Cisco ISE-PIC does not forward live sessions beginning with special characters
CSCwa96229 Cisco ISE does not allow user to change the admin password without validating current
password
CSCwc00162 Certificate based admin login does not work when the client or browser send more
than one certificate
CSCvy66496 REST ID does not filter groups based on name or SID for Azure AD groups
CSCwb92006 Having a single quote (') in the middle of the password on Proxy settings causes the
page to become un-editable
CSCvv87286 Failure to import Internal CA and key from ISE 2.7P2 to 3.0
CSCwb92643 ADE-OS CLI TCP parameters fail to make changes and are no longer relevant
CSCwb88360 Disable temporary management persona on upgraded node fails in split upgrade
CSCwb19256 Ping-node call causes application server to crash (OOM exception) during CRL
validation
CSCwa97123 NTP Sync Failure Alarms with more than 2 NTP Servers Configured.
CSCwa40040 Session Directory Write failed, SQLException: String Data right truncation on ISE3.0P4
CSCwb95433 "File path field must contain a valid file name" error when file conditions are configured
for posture
CSCwa06912 High latency observed for TACACS+ requests with date or time condition in
authorization policies
CSCwb61614 Guest users (AD or internal) cannot delete or add their own devices on a specific node
CSCwb82141 Context Visibility Endpoints And NADs from an existing deployment are not removed
after Restore
CSCwc18751 Unable to download a created support bundle from GUI if logged in using the
DomainName\UserName format
CSCwa85010 SAML certificates should not be marked as Stale if PAN is removed from deployment
CSCwb59170 SHA-2 option is not available for NAD creation using REST API
CSCwb35304 Race condition causes registration or sync failure in Cisco ISE 3.1
CSCwa60903 Cisco ISE adds six additional hours to nextUpdate date for CRL
CSCwc06638 System summary does not get updated post Patch RollBack and Patch Install
CSCwa83517 Guest portal registration page shows "error loading page" error when the email address
contains apostrophe
CSCwa89443 DNA Center - ISE Integration: ISE shows an old DNAC certificate for pxGrid endpoint
CSCvz57222 Admin access is allowed for ISE GUI with secondary interfaces GigabitEthernet 1 and
Bond 1
CSCwb26965 Error when network device groups are created using REST APIs
CSCwb79056 ERS call /ers/config/sgmapping/{id} does not return SGT value for custom SGT's
CSCwb34910 Multiline issues for guest SMS notification in Cisco ISE Portal
CSCwa73860 After ppgrade, the files in the rabbitmq certificate directory show incorrect permissions
CSCwb91392 BH Healthcheck and full upgrade pre-check times out when third party CA certificate
is used for admin
CSCwb70401 Patch 2 - Services do not start due to "Integrity check failed" error
CSCwc09104 Guest redirect with authentication virtual LAN no longer works on ISE 3.1
CSCwa17925 After fixing failed pre-upgrade check, Proceed button is still not available
CSCwb86283 ISE Deployment : All nodes throw OUT_OF_SYNC error as a result of incorrect
certificate expiry check
CSCwa97357 Cisco ISE does not send $mobilenumber$ value in the SMTP API body
CSCwb37760 Sponsor Portal shows error 500 when "Allow kerberos SSO" portal setting is enabled
CSCwb94890 Key Performance Metrics report has no entries for 8 AM and 9 AM every day
CSCwb04898 Unable to restore CFG backup from linux SFTP repository if the file is owned by a
group name without space
CSCwb43007 Posture policy page does not load for SAML login
CSCwc41697 Data dump transfer between nodes fail during upgrade due to connection error
CSCwb05532 Location of "Location" and "Device Type" fields keep changing whenever Network
Devices tab is clicked
CSCwa91335 Default domain configuration in Passive-Syslog provider does not work in ISE 3.1
CSCwb01854 Upgrade External Radius Server List does not show up after upgrading to Cisco ISE
3.0 or above
CSCwb27857 Unable to login into GUI of MnT nodes using RSA 2FA in distribusted deployment
CSCwb02129 SSH to Cisco ISE fails on maually imported SSH Public Keys
CSCwb36849 Cisco ISE must avoid sending Empty Cisco AV-Pairs in access-accept packets
CSCwb32466 Unable to delete endpoint identity group created via REST API if no description is set
CSCwb57675 Cannot disable "Dedicated MnT" Option from GUI after it is enabled
CSCwa04370 Default route is removed or tied to the wrong interface after upgrading
CSCvw90778 T+ ports (49) are still open if disable Device admin process under deployment page
CSCwb11147 Improvement to logs needed with Conflict handling SGT-IP mapping with Virtual
Networks
CSCwb40942 From address to send email is invalid if it does not end with .com or .net
CSCwb96942 Application Server is stuck in the initializing state after configuration backup is restored
CSCwb98854 Cisco ISE does not update expiry date after SLR license is updated
CSCwb38069 Services fail to start after backup from old ISE vrsion 2.6 is restored
CSCwb80572 Application Server stays in Initializing state after installing Cisco ISE 3.1 Patch 3 on
Cisco ISE Patch 2
CSCwb39964 Cisco ISE can login to GUI with disabled shadow admin accounts with external identity
source
CSCwb07504 Sorting internal users based on User Identity Groups does not work in Identities under
Identity Mangement tab
CSCwc39844 Services auto restart fail with an internal error during IP address change in eth 1
CSCvk25808 Unable to edit or remove Scheduled Reports if the admin who created them is no longer
available
CSCwb93156 TrustCertQuickView gives the same information for all trusted certificates
CSCwb40131 400 Bad Request error is thrown when Internal User is enabled with external password
type using Rest API.
CSCwb32492 Application server restart on all nodes after changing the Primary PAN Admin
certificate
CSCvv02086 Add ability to disable TLS 1.0 and 1.1 on ISE PIC node
CSCwc03220 Removing an IP Access list from ISE destroys the distributed deployment
CSCwc57630 3.2 BETA : ISE GUI is not accesible after enabling TLS 1.0.
CSCwb70401 After installing patch 2 services are stuck due to "Integrity check failed" error
CSCvz91603 Unable to fetch the attributes from ODBC after upgrading to ISE 3.0 patch 3
CSCwa09113 Single Byod Flow with Internal CA failing with "12557 User Auth failed because
OCSP status is unknown" error
CSCvy99582 Upgrade from ISE 2.4 patch 13 to ISE 2.7 fails if external RADIUS server is configured
CSCwa37040 backup-logs using public key encryption on the ISE CLI does not allow for caputure
of core files
CSCvz67479 Local Log Settings tooltip on all fields shows irrelevant and unuseful Trust Certificates
CSCwa17470 ISE 3.1 SAML admin authentication fails when user assertion contains multiple values
in the "Groups" claim
CSCvz88188 TACACS authorization policy querying for username fails because username from
session cache is null
CSCwa26210 nextPage field is missing from the json response of API 'GET
/ers/config/radiusserversequence'
CSCwa20354 Node database utilization information is not properly displayed in Operational Data
Purging > Database Utilization window
CSCwa16401 Get-By-Id server sequence returns empty server list after first change made on the
sequence via GUI
CSCwa48465 Reports are unusable due to misshandling fields with multiple values
CSCvx54894 Sponsor Portal admin unable to create random guest accounts with 1 hour duration or
less
CSCvz90468 Internal users using External Password Store are getting disabled if we create users
using API flow
CSCvy84989 Enabling cookies for POST /ers/config/internaluser/ causes Identity Group(s) does not
exist error
CSCwa57705 IP-SGT mapping does not link with new network access device group
CSCvx23375 ISE authorization profiles option get truncated during editing/saving (Chrome only)
CSCwa32312 RCM and MDM flows fail because of session cache not being populated
CSCvz65576 Full upgrade not working with patch when CLI or disk repository is used
CSCwa33462 CSV NAD import is rejected due to special symbol @ at the beginning of RADIUS
shared secret
CSCvz85074 Fix for CSCvu35802 breaks AD group retrieval with certificate attribute as identity
in EAP-Chaining
CSCwa47190 AD security groups cannot have their OU end with dot character in Posture Policy
CSCwa17718 Session service unavailable for pxGrid Session Directory with dedicated MnT
CSCwa08802 ISE 3.1 on AWS gives a false negative on the DNS check for Health Checks
CSCvz83204 ISE unable to fetch the url attribute value from improper index during posture flow
CSCvz74457 ERS API does't allow for use of dot character in "Network Device Group" name or
create / update
CSCvy45345 Eap-chaining authorization failure due to machine authentication flag set to true
incorrectly
CSCvz36192 GET for dacls using /ers/config/downloadableacl does not return a value for nextPage
or previousPage
CSCwa04454 ISE 3.0 & 3.1: Device Admin License alone should allow access to all TACACS menus
CSCvy76328 IPv6 changes the Subnet to /128 when using the duplicate option from Network device
tab
CSCwa45316 MDM intune integration broken for vpn user on ISE 3.1
CSCvn27270 Unable to create network device group with name Location or Device Type
CSCwa13877 ISE displays an alarm stating an invalid response from licensing cloud
CSCwa46758 Deleted Root Network Device groups are still referenced in the Network Devices
exported CSV report
CSCwa94984 ISE API add user operation with long custom attribute string takes around 4 minutes
using Curl
CSCvw90586 Unable to change network Device group Name and Description at the same time
CSCvs55875 Existing routes are not installed in routing table after MTU change
CSCvy16894 Authorization profile throws an error when special characters are used
CSCwa20152 CoA was not initiated for switches for which matrix was not changed, hence Policy
sync failed
CSCvz83753 Empty User Custom attribute included in Authorization Advanced Attributes Settings
results in incorrect AVP
CSCwa43187 "Queue Link Error: Message=From Node1 To Node2; Cause=Timeout" error seen
when NAT is used
CSCwa59924 ISE 3.1 Patch 1: Unable to connect to ISE via SSH when FIPS is enabled
CSCwa52110 When SNMP config is set on the network device, a delay of 20 seconds is introduced
while processing SNMP record
CSCwa38023 ISE 3.1: Unable to generate pxGrid certificates with Active Directory superadmin
CSCwa32814 ISE configured with 15 Collection filters hides the 15th filter
CSCvz79518 Serviceability: "DNS Resolution Failure" alarm should show ISE server
CSCvy96761 Session cache must be updated during EAP chaining flow to handle relevant identities
CSCwa16291 Guest Portal fields causing words to be repeated for Apple VoiceOver
CSCvz90852 Success page is blank and Done button not enabled in Hotspot Guest Portals
CSCwa05404 Sessions are not removed when the Tacacs+ requests resulted in "Could not find
selected service" error
CSCvz95326 Unable to add more than one ACI IP address/hostname when trying to enable ACI
integration in ISE
CSCwa08018 ISE 3.1 - GUI is not working when IPv6 disabled globally
CSCvz93230 Guest portal does not load if hosted on a different interface from Gig0
CSCwa53499 REST ID is fetching the groups from Cloud when the connector settings page is opened
CSCwa56771 ISE 3.0p2 - Monitor All setting displays incorrectly with multiple matrices and different
views
CSCwa47221 AD security groups cannot have their OU end with dot character in Client Provisioning
Policy
CSCvz60870 High Active Directory latency during high TPS causes HOL Blocking on ADRT
CSCwa18443 Need to handle Posture expiry when 8 octet MAC is present in endpoint on the
deployment node
CSCwa67433 Cannot export SAML provider info xml file from ISE GUI
CSCvo39514 MnT log processor is not running because collector log permission.
CSCvu47280 A race condition was found in the mkhomedir tool shipped with the oddjo
CSCvu94544 ISE 3.0 BH : TACACS live logs do not give an option select Network Device IP
CSCvv96532 DOC: unknown maximum time difference for thisUpdate of OCSP response
CSCvw78289 Auth Passed live logs are not seen when using a profile name with more than 50
characters
CSCvy43246 [CFD] User unable to create a guest SSID during Portal Creation step - ISE is busy
error
CSCvy53842 Certificate Validation Syslog Message Sent During Specific Certificate Audits--ISE
CSCvy75191 Cisco Identity Services Engine XML External Entity Injection Vulnerability
CSCvy81435 ISE Guest SAML authentication fails with "Access rights validated" HTML page
CSCvy88092 CTS PAC not activating on Switch: via ISE 3.1 build 3.1.0.477
CSCvy92536 ISE 3.0 Device Admin License alone should allow access to Administration > System
> Logging menu
CSCvy93847 Possible to choose SPAN without Policy persona in NAD Send configuration changes
to device CoA
CSCvy94511 TACACs report showing duplicate entries due to EPOCH time being null
CSCvy94818 EP's incorreclty profiled as "cisco-router" due to nmap performing aggressive guesses
CSCvz00258 SessionCache not cleared for Tacacs AuthZ failures results in high heap usage and
auth latency
CSCvz01485 ISE 2.7 patch 4 unable to upload .json file for Umbrella security profile.
CSCvz05383 P1PNSBaseline: SuperMnT: on last 30days Radius Auth report takes ~5mins with
filter
CSCvz05966 ISE 2.6 p 9, Default permissions can't go back to default group Internal after adding
a new group
CSCvz07191 ISE GUI stuck at loading if AD group does not exist when using cert based auth for
GUI access
CSCvz17020 ISE GUI shows all the licenses as Out of Compliance - Smart Licensing
CSCvz20020 Okta redirection fails for first ID store and works when second ID store is assigned
CSCvz20770 Unable to see the UI pxgrid pages, if we enabled&disabled pxgrid at deployment tab
on secondary node
CSCvz27791 ISE: Application server stuck initializing after backup restore due to mdm configuration
CSCvz37623 NTP (' - ') source state description missing in ISE CLI
CSCvz43183 Sponsor Permissions are not passed to Guest REST API for "By Name" calls.
CSCvz57267 Inability to import ISE certificates issued for PAN to other nodes in spite of the SAN
field fqdn.
CSCvz61191 ISE3.1 No response when click "choose file" on import Endpoints from CSV file page.
CSCvz65182 If we set mtu greater than 1500 then the mtu value is not setting persistently across
reboot.
CSCvz67479 Local Log Settings tooltip on all fields shows irrelevant and unuseful 'Trust Certificates'
CSCvz72034 ISE 3.1:While updating Network Device from DNAC, Shared Secret/password is
empty or masked
CSCvz72208 ISE 3.1 : Authentication tab shows blank result in Context Visivility
CSCvz72225 adding FQDN in discovery host, Discovery host: invalid ip address or host name
CSCvz73445 Agentless Posture for Windows 10 devices not passing AntiMalware check -
CSCvz77482 ISE 3.0 Can't deselect the 'location' settings as part of the guest self registration portal
CSCvz85117 ISE Health Check I/O bandwidth performance check false Alarm
CSCwa00729 All NADs got deleted due to one particular NAD deletion
CSCvz86020 live log/session not showing latest data due to "too many files open" error
CSCwa12273 AD users in Super Admin group can't create/edit admin user with error "Operation is
not permitted"
CSCvz66279 Radius reports older than 7 days are empty (regression of CSCvw78289)
CSCwa04370 ISE 3.1 shows incorrect outgoing interface for the default interface if two interfaces
are configured with IP addresses and the default gateway references the subnet on eth1
CSCwa82553 ISE 3.1 default route is on the incorrect interface if bonding is configured
CSCvf61114 ERS Create/Update for "Authorization Profile" failing XML schema validation
CSCvf88737 Blank guest portal window seen in portal created in portal builder
CSCvg77872 No logo in guest approval email when portal is set to Sponsored-Guest Portal
CSCvh04231 Guest Remember Me RADIUS accounting and access accept not sending guest
username
CSCvi53134 Account used for AD join may become locked after passive-id service is enabled
CSCvm47584 Unable to configure grace period for more than 1 day because of posture lease
CSCvn25548 MnT API call with admin credentials disables the account
CSCvo56767 Error when attempting to change ISE-PIC GUI admin user settings
CSCvo75723 When running a report for endpoint purge, no reports are shown if the purged endpoint
count is 0
CSCvq44063 Incorrect DNS configuration can lead to TACACS or RADIUS authentication failure
CSCvr22065 Import NAD is failing with an error when shared secret key has special character
CSCvr76539 Changes to Network Device Groups not reflected in Change Audit logs
CSCvs24459 Unable to manage ISE internal network access users without an Identity Group
CSCvs29611 Cisco ISE 2.4 patch 5 crashing frequently and generating core files
CSCvs81248 PassiveID alarms should be triggered for inactivity for each DC separately
CSCvs81264 PSN should be capable of identifying delays in mappings from PassiveID agent
CSCvt65332 While updating the Profile Description field in Client Provisioning Resources window,
if Enter is used to create a new line, "Fail to receive server response due to the network
error" message is displayed
CSCvt94587 "Plus License is out of compliance" message seen while regenerating the ISE Root
CA
CSCvu33861 ISE 2.4 patch 6: REST API MnT query to get device by MAC address taking more
than 2 minutes
CSCvu47779 Change Configuration Audit report missing IP Address and modified properties in
CSV export
CSCvu87758 Guest password policy settings cannot be saved when set to ranges for alphabets or
numbers
CSCvu89715 Time Vs Throughput chart in ISE Health Summary report using wrong units
CSCvu91039 ISE not doing lookup for all MAC addresses causing redirectless Posture to fail
CSCvu94025 ISE should either allow IP only for syslog targets or provide DNS caching
CSCvu97657 ISE 2.4 Application server going to Initializing state on enabling endpoint debugs
CSCvv09127 Guest API allows restricted sponsor to create guest accounts even for the unallowed
guest type
CSCvv10683 Session cache for dropped session not getting cleared and causing High CPU on the
PSNs
CSCvv14001 Authorization profile not saved with proper attributes when Security Group selected
under common tasks
CSCvv14390 Max Sessions Limit is not working for Users and Groups
CSCvv19065 Not able to see the guest identity in the DNAC Assurance window
CSCvv27690 While renewing ISE certificate for HTTPS, EAP, DTLS, PORTAL, only Portal and
Admin roles gets applied
CSCvv29737 DNA ACA Security Groups sync fails with JDBCException error
CSCvv30161 Live session details report show incorrect authorization profile and policy for VPN
Posture scenario
CSCvv30226 Livelog sessions show incomplete authorization policy for VPN Posture scenario
CSCvv30274 Context Visibility shows incorrect authorization profile and policy for VPN Posture
scenario
CSCvv31500 ISE Guest portal registration and expiration email need to maintain format entered in
the portal
CSCvv35921 Cannot start CSV exporting for Selected User in internal ID Store
CSCvv36189 RADIUS passed-auth live logs not sent due to invalid IPv6 Address
CSCvv38249 Manual NMAP not working when only custom ports are enabled
CSCvv41935 PSK cisco-av-pair throws an error if the key contains < or > symbols
CSCvv44401 Generate self-signed certificates and CSR default parameters doesn't match with
pre-installed self-signed certificate
CSCvv45063 Internal CA Certificate not getting deleted when node is removed from deployment
CSCvv46034 Device admin service is getting disabled when updating TACACS configuration
CSCvv46958 TrustSec enabled NADs not showing in TrustSec Matrices when NDG column exceeds
255 characters
CSCvv47849 Mapped SGT entry cleared from Authorization Rules if Security Group name is
modified in Cisco DNA Center
CSCvv50168 ISE must allow Posture Grace Period more than 30 days
CSCvv50721 Can't get the download link of NetworkSetupAssistant.exe using Aruba dynamic URL
redirect
CSCvv54761 Export of current active session reports only shows sessions that has been updated
since midnight
CSCvv54798 Context Visibility CSV exported from CLI not showing IP addresses
CSCvv55663 ISE 2.6/2.7 Repositories get deleted post ISE node reload
CSCvv57628 Suspended Guest User is not automatically removed from Endpoint Group
CSCvv57639 Saving command with parenthesis in TACACS command set gives an error
CSCvv57830 Group lookup failed as empty value was appended to the context
CSCvv58629 Certificate Authority Service initializing EST Service not running after upgrade to ISE
2.7 patch 2
CSCvv59233 ISE RADIUS Live Log details missing AD-Group-Names under Other Attributes
section
CSCvv60014 Operational backup throws error if available free space in /opt folder is 1 TB or greater
CSCvv60353 Authentication summary report gets stuck if the total records are more than 5M
CSCvv60686 ISE SXP should have a mechanism to clear stale mappings learned from session
CSCvv60923 Need to add the ability to use a forward slash in the IP data type of internal user custom
attribute
CSCvv61732 Unable to create unique community string for different SNMP servers
CSCvv62549 Custom Attribute from Culinda not showing in endpoint GUI page
CSCvv62729 Network Device API call throws error 500 if you query an non-existent network device
CSCvv63548 PSN rmi GC collection not working properly causing memory leak in PassiveID flow
CSCvv64190 Case sensitivity on User Identity Groups causes "Select Sponsor Group Members"
window to not load
CSCvv67743 Posture Assessment by Condition report displays No Data with Condition Status filter
CSCvv67935 Security Group values in Authorization Profile disappear shortly after fetching
CSCvv68293 ISE not consuming plus license when using local or global exceptions
CSCvv72418 ISE 3.0 REST ID log file not included in support bundle
CSCvv77007 ISE constantly sending internal Super Admin user requests to external RADIUS token
server
CSCvv77530 Unable to retrieve LDAP Groups/Subject Attributes when % character is used twice
or more in bind password
CSCvv77914 Client Provisioning window does not show current settings properly
CSCvv77928 Bulk certificate generation failed with "An unexpected error occurred" message after
primary PAN failure
CSCvv82806 Network Device IP filter does not match IPs that are inside subnets
CSCvv85588 High memory usage on the PSN nodes with PassiveID flow
CSCvv91007 Smart Licensing Entitlement tab gets stuck at "Refreshing" if there is connection failure
CSCvv91234 ISE 2.6 scheduled reports are not working when primary MnT is down
CSCvv92203 "NetworkAuthZProfile with entered name already exists" message seen while trying
to create an SGT with name "Employees"
CSCvv92613 Users that do not belong to the sponsor group are able to login in the sponsor portal
CSCvv92638 Cannot configure scheduled config and operational backup with start date same as
current day
CSCvv93442 Double Slash "//" added in File Path for SFTP servers
CSCvv96532 Maximum time difference not specified for "thisUpdate of OCSP response"
CSCvw00375 Unable to load Context Visibility window for custom view in ISE 2.7 patch 2
CSCvw01225 ISE configuration restore fails at 40% with "DB Restore using IMPDP failed" error
CSCvw01829 ISE GUI login page shows error while using Chrome version 85/86
CSCvw03693 NTP does not work because internal user 'chrony' not created
CSCvw08292 ACI mappings are not being deleted after a delete message
CSCvw08330 Posture does not work with dynamic redirection on third party NADs
CSCvw16237 Scheduled operational data backups not being triggered after Primary MnT reload
CSCvw17908 Pushing IP to SGT mapping from ISE to switch doesn't work if default route is tagged
CSCvw19785 Editing external data source posture condition is showing always the wrong AD
CSCvw20060 Agent marks DC as down if agent service comes up before windows network interface
CSCvw20636 Authorization Profiles showing "No data available" after NAD profile is deleted
CSCvw26415 ISE 3.0 not importing certificates missing CN and SAN into Trusted Certificate Store
CSCvw26570 International Phone Number dropdown box not working in ISE 2.7
CSCvw28441 NADs shared secrets are visible in the logs while using APIs
CSCvw31269 SAML groups do not work if they are applied in the Sponsor Portal Groups
CSCvw33115 ISE MnT Live Session status is not changing to Postured in VPN use case
CSCvw34491 Enabling Essentials licenses only block access to Network Devices tab
CSCvw36743 ISE Service Account Locked and WMI not established due to special characters in
password
CSCvw37844 ANC CoA not working as ISE uses hostname for internal calls
CSCvw38530 Exception shown in ise-psc.log for repository while loading Backup and Restore
window
CSCvw38853 Sophos 10.x definition missing from Anti-malware condition for MAC OSX
CSCvw48697 API IP SGT mapping not returning result for [No Devices]
CSCvw49938 No TACACS Command Accounting report for third party device with a space before
TACACS command
CSCvw50381 CoA-disconnect is not issued by ISE for Aruba WLC when grace access is expired
CSCvw50829 AD security groups cannot have their OU end with dot character on RBAC policies
CSCvw51787 ISE is not allowing to import CA signed certificate on top of self-signed certificate
CSCvw51801 Session which was previously having Postured Live Session state is moving to Started
upon receiving Accounting Interim Update from NAD
CSCvw54878 ISE does not display Full Authorization rules if it has 50 rules or more in Japanese
GUI
CSCvw55793 ISE fails to send CoA from PSNs with "Identifier Allocation Failed" error
CSCvw66483 RADIUS server sequence gets corrupted when selected external server list is modified
CSCvw68480 Total mappings not displayed properly when using multiple SXP nodes in ISE
deployment
CSCvw68944 Sponsor portal shows wrong week information on setting date while using Chinese
language
CSCvw73928 NTP sync failure alarms that are not relevant need to be changed
CSCvw75563 HotSpot Guest portal displays Error Loading Page when passcode field contains special
characters
CSCvw78289 Authentication Passed live logs are not seen when using a profile name with more than
50 characters
CSCvw80520 "Radius Authentication Details" report takes time when ISE Messaging Service is
disabled
CSCvw82815 Authorization profile CWA option does not work correctly with some network device
profiles
CSCvw84127 Configuration Audit detail does not show which Policy Set was modified
CSCvw85599 TACACS+ Device Network Conditions and Device Port Network Conditions tabs
scrollbar not working
CSCvw85860 ISE pxGrid exceptions should have ERROR log level instead of DEBUG
CSCvw87173 MAB authorization is failing if AD object representing the MAC address is in disabled
state
CSCvw87175 MAB authentication via Active Directory passes with AD object disabled
CSCvw88881 DB Clean up hourly cron acquiring DB lock causing deployment registration failure
CSCvw89326 For PKI based SFTP, exporting GUI key for MnT node is only possible when it is
promoted as PAN
CSCvw94603 Change in Polling interval not taking effect for external MDM server (Microsoft_intune)
CSCvw96371 Static policy and group assignment are lost from EP when updating custom attributes
from API
CSCvw97905 Internal user export feature shows no error for invalid characters in password
CSCvx00245 Itune integration throws error while Test Connection works fine in MDM window
CSCvx04512 Admin access with certificate based authentication can be bypassed by going directly
to login.jsp
CSCvx09383 Error seen when trying to sort endpoint's Applications by "Running process" in Context
Visibility
CSCvx10186 ISE remains in eval expire state even after registering with Smart Licensing
CSCvx11857 Latency in loading certain pages due to stale certificate entries in ISE TrustCert Store
CSCvx15427 DNS Resolvability in Health Checks: False failures with ISE FQDN as CNAME
CSCvx18730 Sudo Privilege Escalation Vulnerability Affecting Cisco Products: January 2021
CSCvx22229 "ipv6 address autoconfig" gets removed when changing IP address of bond interface
CSCvx28402 Support bundle does not capture ise-jedis.log files on ISE 2.7 and later
CSCvx32666 Authentication Method conditions not matching in Policy Set entry evaluation
CSCvx37149 SGA value under-provisioned for SNS 3515 running all personas on same node
CSCvx37297 Error 400 while authenticating to Sponsor portal with Single Sign-on/Kerberos user
account
CSCvx37467 Sponsor portal gives "Invalid Input" if the "mobile number" field is unchecked in portal
settings
CSCvx41826 Unable to get all tenable adapter repositories with Tenable SC 5.17
CSCvx43566 No login fail log when using external username and wrong password
CSCvx43825 Receiving acct stop without NAS-IP address keeps session in started state
CSCvx45481 CoA failure upon endpoint change to a new switch-port and Endpoint Identity Group
change
CSCvx46638 In EAP chaining scenario, posture policy failed to retrieve machine AD group
membership
CSCvx47691 Session Directory topic does not update user SGT attribute after a dynamic authorization
CSCvx47891 AMP events for new endpoints are not correctly mapped
CSCvx54213 Default Network Devices window requires Plus license to allow configuration
CSCvx60818 ERS self-registration portal update is not deleting fields as expected in PSN
CSCvx61664 ISE not updating the Json file information in the AnyConnect output config file
CSCvx64247 "Invalid phone number format" error seen on mobile devices using the Country-code
drop-down option
CSCvx70633 ISE does not accept % in EXEC or Enable Mode password in network device trustsec
configuration
CSCvx78643 Emails sent for all system alarms using legacy data even when there is no email address
configured in current deployment
CSCvx82808 MacOS Big Sur 11.x BYOD failing EAP-TLS when using a CA signed certificate
CSCvx85355 Increase the maximum allowable value of the posture grace period from 30 to 90 days
CSCvx85391 Internal user inactivity timer is not updated due to login letter case
CSCvx85675 ISE can't handle deletion/addition of SXP-IP mappings propagation due to race
condition
CSCvx85807 Smart license of de-registration flow is not working in ISE and ISE-PIC
CSCvx86571 The instruction box should be removed when the login-page message is empty
CSCvx86921 RADIUS Token Identity Source Prompt vs Internal User prompt for TACACS
authentication
CSCvx94452 EST service not running on ISE 2.7 patch 2 and above
CSCvx96190 Top Authorization report does not show filter in scheduled reports
CSCvx97501 ROPC authentication is failing with non Base64 characters in the password
CSCvx99151 Internal ERS user attempting to authenticate via external ID store causing REST delays
CSCvy04443 MNT REST API for ReAuth fails when used in distributed deployment (with separate
MnT)
CSCvy04665 TACACS Reports Advance filters not working when matching full numeric ID entries
CSCvy05954 All SXP Mappings window not displaying IPv6 mappings learned via Session
CSCvy07088 Agentless Posture doesn't install CA certificate chain in endpoint Trusted Store
CSCvy10026 Agentless Posture fails if ISE admin certificate CN is not equal to FQDN
CSCvy14342 High CPU seen on PSN nodes from ISE 2.6 patch 3 onwards due to PIP query
evaluation
CSCvy17893 ISE REST API returns duplicate values for IP-SGT mappings
CSCvy18560 RADIUS Accounting Details report does not display Accounting details
CSCvy20277 Special characters allowed previously in Descriptions field for few objects no longer
can be used
CSCvy23354 Maximum height of Description field in ISE authorization profile UI too small in FF
88
CSCvy24370 ISE not accepting more than 6 attributes to be modified in RADIUS server sequence
configuration
CSCvy25550 ISE does not accept name of custom attribute for Framed-IPv6-Address in the
authorization profile
CSCvy30119 LDAP groups disappear from Sponsor group when making other changes to options
CSCvy32461 Sponsor user cannot edit data when phone/email fields are filled
CSCvy34977 Application Server stuck on initializing state due to certificate template curve type
P-192
CSCvy36868 ISE 2.3 and later version do not support "cariage return" <cr> character in command-set
CSCvy38459 ISE 2.7 patch 3 GUI doesn't show all device admin authorization policies
CSCvy38896 AAA requests without Framed-IP value will cause exception in SXP process
CSCvy40845 Updating a custom attribute through ERS request updates another attribute as well
CSCvy45015 ISE Guest Self-Registration error for duplicate user when "Use Phone number as
username" option is enabled
CSCvy46504 Intermittent error on Cisco DNA Center while trying to deploy policy
CSCvy48766 ISE installation fails with Database Priming Failed error when All Numbers subdomain
is used
CSCvy51073 ISE authorization profile ERS update ignores accessType attribute changes
CSCvy60752 Setup wizard password does not supports hyphen after reset of config via CLI
CSCvy61564 ISE 2.7 Patch 3 ERS call is not accepting RADIUS shared secret with 3 characters
CSCvy61894 Generate key pair accepts space but cannot export key
CSCvy62875 [ 400 ] Bad Request error with SAML SSO OKTA on Apple devices
CSCvy74456 Authentication via ISE fails with "Invalid login credentials" error
CSCvy74919 ISE internal users are not getting disabled after hitting inactivity timer
CSCvy76262 ISE DACL Syntax validator does not comply with ASA's code requirements
CSCvy76601 Delete 'All' function showing incorrect number of endpoints on confirmation popup
CSCvy76617 Need the Select ALL device option with or without filter in NAD page
CSCvy82114 First/Last name wrongly displayed as Unicode of Chinese in Network Access Users
window after upgrade
CSCvz00034 The log level for OcspClient must be changed to ERROR instead of WARN
• Option to skip ICMP, DNS, and NTP checks in the ZTP tool. For more information, see "Zero Touch
Provisioning" in the Chapter "Additional Installation Information" in Cisco ISE Installation Guide,
Release 3.1.
Note • The filenames of the new files will have "b" appended to the build number (for example,
ise-3.1.0.518b.SPA.x86_64.iso).
• If you want to import the SNS 3695 OVA template to the VMware vCenter content library, you can use
the ISE-3.x.x.xxx-virtual-SNS3695-1800.ova template. This OVA template is similar to the
ISE-3.x.x.xxx-virtual-SNS3695-2400.ova template, except for the reserved disk size, which has been
reduced from 2400 GB to 1800 GB to workaround a limitation in the Vmware vCenter content library
that prevents import of OVAs with disk size larger than 2 TB.
• You will see the following ISE version in the output of show tech-support command:
ZTPBUNDLE
• Existing Cisco ISE 3.1 patches will work fine with this build.
Open Caveats
Open Caveats
Caveat ID Number Description
CSCwn93753 External RADIUS Server authentication fails with could not find selected
access service message.
CSCwn94797 RADIUS token configuration does not work after installing Cisco ISE Release
3.1 Patch 10 in deployment.
CSCwf69715 After a patch install on Cisco ISE, TC-NAC adapters will be not reachable
and new adapters cannot be configured.
CSCwf80292 Cisco ISE cannot retrieve a peer certificate during EAP-TLS authentication.
CSCwf79310 ISE 3.1 patch 7: no VN's under security group in authorization profile.
CSCwe72097 31P6:Unable to launch sponor portal with eth1 FQDN(diff dns)- when existing portal
is edited.
CSCwe25050 Wild card Certificate imported on PPAN not replicated to other nodes in deployment.
CSCwh92366 In 3.1 Patch 8: Observing Insufficient Virtual Machine Resource Alarm in 3.1Patch 8
Longevity setup.
Bug ID Description
CSCwd70346 After a full upgrade to Cisco ISE Release 3.1 patch 5, the precheck page loads with old selected
data, and the start button is disabled.
CSCwd97582 Cisco ISE Release 3.1 Patch 5 verifies CA certificate EKU causing Unsupported Certificate
error.
CSCwh92366 In 3.1 Patch 8: Observing Insufficient Virtual Machine Resource Alarm in 3.1Patch 8 Longevity
setup.
Bug ID Description
CSCwc62413 Cisco Identity Services Engine Cross-Site Scripting Vulnerability.
CSCwh92366 In 3.1 Patch 8: Observing Insufficient Virtual Machine Resource Alarm in 3.1Patch 8 Longevity
setup.
CSCwa09113 Single Byod Flow with Internal CA failing "12557 User Auth failed because
OCSP status is unknown".
CSCvy88861 Policy change doesn’t get pushed to the network device after ISE HA.
CSCvz20020 Okta redirection happens only after the initially added SAML configuration is deleted
and reconfigured.
CSCvz20770 Unable to see the pxGrid pages in GUI, after pxGrid is enabled and disabled in
Deployment tab on secondary node.
CSCwe99666 Live logs and live sessions pages are displayed in incorrect sorting order when timezone
is changed on PSN and MnT nodes.
CSCwe99706 Session data is shown at the bottom when PSNs are in different timezones.
CSCwh92366 In 3.1 Patch 8: Observing Insufficient Virtual Machine Resource Alarm in 3.1Patch 8
Longevity setup.
CSCwn62873 Known issue with Cisco ISE integration with Active Directory on Windows server
2025.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH
THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY,
CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of
the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS.
CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT
LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS
HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network
topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional
and coincidental.
All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.
Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL:
https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. (1721R)
© 2021 Cisco Systems, Inc. All rights reserved.