Cisco Cisco Identity Services Engine 1.3 전단

다운로드
페이지 168
 
3-11
Cisco Identity Services Engine API 
참조 가이드, 릴리스 1.4
OL-26134-01
장      트러블슈팅을 위한 쿼리 API
  
쿼리 API 호출을 사용하여 Cisco ISE 트러블슈팅
=00:0C:29:46:F3:B8; User-Name=00-0C-29-46-F3-B8; 
State=ReauthSession:0A4D98D1000001F26F0C04D9; 
Class=CACS:0A4D98D1000001F26F0C04D9:guest-240/138796808/76; 
Termination-Action=RADIUS-Request; Tunnel-Type=(tag=1) VLAN; 
Tunnel-Medium-Type=(tag=1) 802; Tunnel-Private-Group-ID=(tag=1) 2; 
cisco-av-pair=url-redirect-acl=ACL-WEBAUTH-REDIRECT; 
cisco-av-pair=url-redirect=https://guest-240.cisco.com:8443/guestportal/gateway?
sessionId=0A4D98D1000001F26F0C04D9&action=cwa; 
cisco-av-pair=ACS:CiscoSecure-Defined-ACL=#ACSACL#-IP-pre-posture-506e980a; 
cisco-av-pair=profile-name=WindowsXP-Workstation;}</response
><audit_session_id>0A4D98D1000001F26F0C04D9</audit_session_id><nas_po
rt_id>GigabitEthernet1/0/17</nas_port_id><posture_status>Pending</posture_status>
<selected_azn_profiles>CWA_Redirect</selected_azn_profiles>
<service_type>Call Check</service_type>
<message_code>5200</message_code>
<nac_policy_compliance>Pending</nac_policy_compliance>
<id>1349422277270556</id>
<acsview_timestamp>2012-10-05T10:49:47.915Z</acsview_timestamp>
<identity_store>Internal Endpoints</identity_store>
<response_time>13</response_time>
<other_attributes>ConfigVersionId=81,DestinationPort=1812,Protocol=Radius,AuthorizationPol
icyMatchedRule=CWA_Redirect,
NAS-Port=50117,Framed-MTU=1500,NAS-Port-Type=Ethernet,EAP-Key-N
ame=,cisco-nas-port=GigabitEthernet1/0/17,AcsSessionID=guest-240/138796808/76,Us
eCase=Host Lookup,SelectedAuthenticationIdentityStores=Internal 
Endpoints,ServiceSelectionMatchedRule=MAB,IdentityPolicyMatchedRule=Default,CPMS
essionID=0A4D98D1000001F26F0C04D9,EndPointMACAddress=00-0C-29-46-F3-B8,EndPointM
atchedProfile=WindowsXP-Workstation,ISEPolicySetName=Default,HostIdentityGroup=E
ndpoint Identity Groups:Guest_IDG,Device Type=Device Type#All Device 
Types,Location=Location#All Locations,Device IP 
Address=10.77.152.209,Called-Station-ID=00:24:F7:73:9A:91,CiscoAVPair=audit-sess
ion-id=0A4D98D1000001F26F0C04D9</other_attributes>
-
</authStatusElements>
-
</authStatusList>
-
</authStatusOutputList>
계정 상태 API 호출
AcctStatus API 
호출을 사용하여 대상 노드의 최신 디바이스 및 세션 계정 정보를 검색할 수 있습
니다. 이 섹션에서는 스키마 파일 출력 예시, 이 API 호출을 통해 최신 디바이스 및 세션 정보에 대
한 요청을 전송하기 위한 절차, 이 API 호출이 실행된 이후에 반환되는 데이터 샘플을 제공합니다. 
AcctStatus API 
호출을 통해 시간 관련 매개변수를 구성할 수 있습니다.
기간 — 지정된 MAC 주소와 관련된 최신 계정 디바이스 레코드를 검색할 시간(초)을 정의합
니다. 사용자 구성 가능한 유효한 값의 범위는 1~432000초(5일)입니다. 예:
값에 2400초(40분)를 입력하는 경우, 지난 40분 동안 사용할 수 있도록 지정된 MAC 주소
에 대한 최신 계정 디바이스 레코드가 필요하다는 것을 의미합니다.
값에 0초를 입력하는 경우, 15분(900초)의 기본 기간이 지정됩니다. 이는 해당 기간 동안 
사용할 수 있도록 지정된 MAC 주소에 대한 최신 계정 디바이스 레코드가 필요하다는 것
을 의미합니다.