<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 1.2 does not do HTTP profiling ??? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309767#M130610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Second Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Installed another (standalone) ISE with latest 1.1.4 version and patches&lt;/P&gt;&lt;P&gt;- connected ISE to vmware SPAN network with gig 1&lt;/P&gt;&lt;P&gt;- configured ISE to do http profiling on gig 1 only (nothing else)&lt;/P&gt;&lt;P&gt;- "sh int gig 1" show rapidly increasing packet counters&lt;/P&gt;&lt;P&gt;- Identites/Endpoints gui show lots of devices profiled into the correct classes (Win7, WinXP, ...), all devices were identified by the http user agent attribute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&amp;gt;&amp;gt; HTTP profiling works&amp;nbsp; !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Upgraded ISE 1.1.4 P3 to 1.2 via cli (used file: &lt;SPAN style="font-size: 10pt;"&gt;ise-upgradebundle-1.1.x-to-1.2.0.899.i386.tar.gz)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- "sh int gig 1" shows hardly any packet counts at all (monitoring session still running)&lt;/P&gt;&lt;P&gt;- Identites/Endpoints gui shows no additional devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;gt; HTTP profiling NOT working anymore !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- HTTP profiling does not work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - in newly installed ISE 1.2 (installed from .iso)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - in upgraded ISE 1.2 (via 1.2 upgrade-bundle)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- HTTP profiling does work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - on ISE 1.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the underlying operation system has been changed &lt;SPAN style="font-size: 10pt;"&gt;heavily &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;from 1.1 to 1.2, I would think that maybe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;the nic driver of the os could be most likely the issue here (promiscuous mode missing ???)&amp;nbsp; .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Aug 2013 12:11:34 GMT</pubDate>
    <dc:creator>Frank Lothar Weber</dc:creator>
    <dc:date>2013-08-21T12:11:34Z</dc:date>
    <item>
      <title>ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309763#M130606</link>
      <description>&lt;P&gt;Hi, guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone ISE 1.2 Patch 1 successfully enabled to do profiling using HTTP on a monitor session/span port ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- DMZ switch, which holds a vlan where (only) the central proxy server resides&lt;/P&gt;&lt;P&gt;- ESX 5.1 host, one nic connected to the DMZ switch&lt;/P&gt;&lt;P&gt;- configured a virtual switch/network on this host, which uses the nic connected to the DMZ switch (enabled promiscious mode on the vswitch and network)&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/3/1/151136-ise03.jpg" alt="ise03.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- ISE 1.2 Patch 1 installed on the ESX host, two interfaces (Gig 0 and 1), Gig 1 connected to the vswitch and virtual network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/2/1/151126-ise01.jpg" alt="ise01.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- configured virtual ISE to do http profiling on Gig 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/2/1/151125-ise02.jpg" alt="ise02.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh moni&lt;/P&gt;&lt;P&gt;Session 1&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Local Session&lt;/P&gt;&lt;P&gt;Source VLANs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Both&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : xx&lt;/P&gt;&lt;P&gt;Destination Ports&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Gi2/0/48&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encapsulation&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Native&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ingress&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh run int gig2/0/48&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet2/0/48&lt;/P&gt;&lt;P&gt; description *** ISE Proxy SPAN Port&lt;/P&gt;&lt;P&gt; switchport access vlan xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The span destination port shows lots of outgoing packets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#sh int gig2/0/48&lt;/P&gt;&lt;P&gt;GigabitEthernet2/0/48 is up, line protocol is down (monitoring)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is Gigabit Ethernet, address is 588d.0941.7130 (bia 588d.0941.7130)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Description: *** ISE-Riker Proxy SPAN Port&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; reliability 255/255, txload 10/255, rxload 1/255&lt;/P&gt;&lt;P&gt;&amp;nbsp; Encapsulation ARPA, loopback not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Keepalive set (10 sec)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Full-duplex, 1000Mb/s, media type is 10/100/1000BaseTX&lt;/P&gt;&lt;P&gt;&amp;nbsp; input flow-control is off, output flow-control is unsupported&lt;/P&gt;&lt;P&gt;&amp;nbsp; ARP type: ARPA, ARP Timeout 04:00:00&lt;/P&gt;&lt;P&gt;&amp;nbsp; Last input never, output 00:22:36, output hang never&lt;/P&gt;&lt;P&gt;&amp;nbsp; Last clearing of "show interface" counters 03:03:20&lt;/P&gt;&lt;P&gt;&amp;nbsp; Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 14352300&lt;/P&gt;&lt;P&gt;&amp;nbsp; Queueing strategy: fifo&lt;/P&gt;&lt;P&gt;&amp;nbsp; Output queue: 0/40 (size/max)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 minute input rate 0 bits/sec, 0 packets/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 minute output rate 42962000 bits/sec, 13051 packets/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 33 packets input, 2436 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 33 broadcasts (18 multicasts)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 runts, 0 giants, 0 throttles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 watchdog, 18 multicast, 0 pause input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input packets with dribble condition detected&lt;/P&gt;&lt;P&gt; &lt;SPAN style="color: #ff0000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 223104868 packets output&lt;/SPAN&gt;, 98731284385 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 babbles, 0 late collision, 0 deferred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 lost carrier, 0 no carrier, 0 PAUSE output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output buffer failures, 0 output buffers swapped out &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the interface on ISE hardly shows any incoming packets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sh int gig 1&lt;/P&gt;&lt;P&gt;GigabitEthernet 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Link encap:Ethernet&amp;nbsp; HWaddr 00:50:56:8D:4A:C1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet6 addr: fe80::250:56ff:fe8d:4ac1/64 Scope:Link&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UP BROADCAST RUNNING MULTICAST&amp;nbsp; MTU:1500&amp;nbsp; Metric:1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets:&lt;SPAN style="color: #ff0000;"&gt;3810&lt;/SPAN&gt; errors:0 dropped:0 overruns:0 frame:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets:12 errors:0 dropped:0 overruns:0 carrier:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; collisions:0 txqueuelen:1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:347928 (339.7 KiB)&amp;nbsp; TX bytes:936 (936.0 b)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interrupt:67 Base address:0x20a4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested if the vmware virtual network makes the packets disappear, therefore I have connected a windows virtual machine to the same network as ISE&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running Wireshark on this windows machine shows me LOOOOOTS of http packets on this virtual network, seem like the ISE nic just doesn't see them ......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs &lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309763#M130606</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2019-03-11T03:46:52Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309764#M130607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to run a packet capture on the gig 1 interface through the support tools? See if you can get a copy of the http headers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 18:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309764#M130607</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-08-15T18:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309765#M130608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Tarik.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice hint, I totally forgot the support tools ..... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Used the tcp dump support tool to capture Gig 1 on ise:&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/7/1/151172-ise05.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Viewing the dump file with wireshark shows lots of http packets:&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/7/1/151174-ise04.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;So, the monitoring session works ok, vmware virtual network does not swallow the packets,&lt;/P&gt;&lt;P&gt;they arrive on Gig 1 of ise, but looks like they are simply not processed .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 07:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309765#M130608</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-08-16T07:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309766#M130609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have connected another ISE 1.2 P1 (different one) with gig 1 to the virtual span network on the host and enabled http profiling on that ise, too. This time I used the cli "tech dumptcp" on that second ise to check, if span packets arrive on the ise nic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lots of http packets, too ......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# tech dumptcp 1&lt;/P&gt;&lt;P&gt;Invoking tcpdump. Press Control-C to interrupt.&lt;/P&gt;&lt;P&gt;tcpdump: WARNING: eth1: no IPv4 address assigned&lt;/P&gt;&lt;P&gt;tcpdump: listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes&lt;/P&gt;&lt;P&gt;14:16:10.545083 IP (tos 0x0, ttl 120, id 16220, offset 0, flags [DF], proto: TCP (6), length: 40) 10.x.y.142.52788 &amp;gt; 10.&lt;SPAN style="font-size: 10pt;"&gt;x.y&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.211.8080: ., cksum 0x3055 (correct), 1867362316:1867362316(0) ack 3989370400 win 64170&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;14:16:10.545271 IP (tos 0x0, ttl 128, id 16724, offset 0, flags [DF], proto: TCP (6), length: 1420) 10.&lt;SPAN style="font-size: 10pt;"&gt;x.y&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.211.8080 &amp;gt; 10.x.y.142.52788: . 78661:80041(1380) ack 0 win 258&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;14:16:10.545281 IP (tos 0x0, ttl 128, id 16725, offset 0, flags [DF], proto: TCP (6), length: 1420) 10.x.y.211.8080 &amp;gt; 10.x.y.142.52788: . 80041:81421(1380) ack 0 win 258&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;14:16:10.546312 IP (tos 0x0, ttl 128, id 16764, offset 0, flags [DF], proto: TCP (6), length: 1420) 10.x.y.211.8080 &amp;gt; 10.x.y.30.51413: . 51061:52441(1380) ack 0 win 255&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the problem is not bound to a specific ise, all 1.2 ise do not profile http ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The final message you get on the cli is quite interesting though:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;610 packets captured&lt;/P&gt;&lt;P&gt;29216 packets receiv&lt;SPAN style="color: #ff0000;"&gt;ed by filter&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;28469 packets &lt;SPAN style="color: #ff0000;"&gt;dropped &lt;/SPAN&gt;by kernel&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What filter ??? And why are that much packets dropped ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 14:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309766#M130609</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-08-16T14:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309767#M130610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Second Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Installed another (standalone) ISE with latest 1.1.4 version and patches&lt;/P&gt;&lt;P&gt;- connected ISE to vmware SPAN network with gig 1&lt;/P&gt;&lt;P&gt;- configured ISE to do http profiling on gig 1 only (nothing else)&lt;/P&gt;&lt;P&gt;- "sh int gig 1" show rapidly increasing packet counters&lt;/P&gt;&lt;P&gt;- Identites/Endpoints gui show lots of devices profiled into the correct classes (Win7, WinXP, ...), all devices were identified by the http user agent attribute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&amp;gt;&amp;gt; HTTP profiling works&amp;nbsp; !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Upgraded ISE 1.1.4 P3 to 1.2 via cli (used file: &lt;SPAN style="font-size: 10pt;"&gt;ise-upgradebundle-1.1.x-to-1.2.0.899.i386.tar.gz)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- "sh int gig 1" shows hardly any packet counts at all (monitoring session still running)&lt;/P&gt;&lt;P&gt;- Identites/Endpoints gui shows no additional devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;gt; HTTP profiling NOT working anymore !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- HTTP profiling does not work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - in newly installed ISE 1.2 (installed from .iso)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - in upgraded ISE 1.2 (via 1.2 upgrade-bundle)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- HTTP profiling does work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - on ISE 1.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the underlying operation system has been changed &lt;SPAN style="font-size: 10pt;"&gt;heavily &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;from 1.1 to 1.2, I would think that maybe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;the nic driver of the os could be most likely the issue here (promiscuous mode missing ???)&amp;nbsp; .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 12:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309767#M130610</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-08-21T12:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309768#M130611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. it is vm, right? can you get netstat -i?&lt;BR /&gt;&lt;BR /&gt;2. Did you configure an ip for the span receive interface? if not, you must configure one to make it work.&lt;BR /&gt;&lt;BR /&gt;looks like you don't have one,,, pls configure one...&lt;BR /&gt;&lt;BR /&gt;tcpdump: WARNING: eth1: no IPv4 address assigned&lt;BR /&gt;&lt;BR /&gt;3. on vswitch make sure the port is in promiscuous mode.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 16:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309768#M130611</guid>
      <dc:creator>Shaoqin Li</dc:creator>
      <dc:date>2013-08-21T16:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309769#M130612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;1. it is vm, right?&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yepp !! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;can you get netstat -i? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Executed where ?? On the esx host ?? On the ise vm ??&lt;/P&gt;&lt;P&gt;What do you expect to see ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;2. Did you configure an ip for the span receive interface?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;No, why should this be necessary ?? (switchport, wireshark, etc. don't need an ip to capture&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;packets on a promiscuous interface, even ISE 1.1.4 didn't need one on the http profiling interface .....)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Configuration guide doesn't say so anyway ......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;if not, you must configure one to make it work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #ff0000;"&gt;looks like you don't have one,,, pls configure one...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, ok ..., configured an ip address, checked the profiling attributes ...&lt;/P&gt;&lt;P&gt;Result: did not make any difference ..... (tadaaaahhhhh !!!)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #ff0000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #ff0000;"&gt;tcpdump: WARNING: eth1: no IPv4 address assigned&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Right, but tcpdump shows dozens of live packets as they arrive live on ise, they are just not reflected in the "sh int gig 1" counters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;and furthermore not picked up by the application, that is why I would suspect a nic driver malfunction on the underlying linux os ......&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;3. on vswitch make sure the port is in promiscuous mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;As I already mentioned before in this thread, it is. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; color: #000000;"&gt;If the vmware virtual network &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; color: #000000;"&gt;inbetween ise and the non-virtual network would swallow the packets, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;why would "tech dumptcp 1" show anything&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; color: #000000;"&gt; at all ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;(see screenshots above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 07:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309769#M130612</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-08-22T07:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309770#M130613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, no update here, nothing to that matter to be found in the bug toolkit, n&lt;SPAN style="font-size: 10pt;"&gt;o update/patch for ISE 1.2 either.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nobody out there, who has encountered the same problem ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 06:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309770#M130613</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-09-20T06:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309771#M130614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kindly find the link below may help you have some information and address your query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_ug.pdf"&gt;http://www.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_ug.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP SPAN Probe ( on page no. 405)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unable to Collect HTTP Attributes in Cisco ISE Running on VMware ( on page no. 405)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Oct 2013 23:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309771#M130614</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-18T23:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309772#M130616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This doesn't help at all, sorry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What might be in that doc on page 405 that would help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ensure that promiscous mode on the vmware switch is enabled ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, like I said five times before in this thread, IT IS !!! &lt;/P&gt;&lt;P&gt;Do you read threads before you post an answer ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;"tech dumptcp 1" shows that packets are arriving, but are:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1. not picked up by the application&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2. not reflected in "sh int gi 1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Turn on DHCP SPAN probe &lt;STRONG&gt;and &lt;/STRONG&gt;HTTP probe on the same interface, then HTTP will work ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not really, done that already when I first saw that HTTP probe doesn't work (turned on all probes&lt;/P&gt;&lt;P&gt;on that interface to see, if any traffic is recognized by the application on that nic, surpise: it isn't !!!) .... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As you might notice, I am quite pi****ed with this situation. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I personally think, this is a MAJOR &lt;SPAN style="font-size: 10pt;"&gt;showstopper for any ISE installation in our enterprise, if not resolved quickly ....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Oct 2013 21:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309772#M130616</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2013-10-19T21:26:22Z</dc:date>
    </item>
    <item>
      <title>ISE 1.2 does not do HTTP profiling ???</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309773#M130618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Frank,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe you might check from Operation &amp;gt; Troubleshoot &amp;gt; Download Logs &amp;gt; [YOURISE] &amp;gt; Deubg Logs &amp;gt; Profiler Log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure this is documented somewhere (didn't checked to be honest), but if you do not have an IP address on your interface, you would get such messages:&lt;/P&gt;&lt;P&gt;2013-10-21 18:25:44,118 ERROR&amp;nbsp; [ProfilerController-1-thread-1][] cisco.profiler.infrastructure.probemgr.ProbeLoader -:::- Loading all probes failed.:Loading probe httpfailed. HTTP probe cannot be started on any of the configured network interfaces - eth1 either because those interfaces do not exist or are down.&lt;/P&gt;&lt;P&gt;com.cisco.profiler.common.ProfilerException: Loading probe httpfailed. HTTP probe cannot be started on any of the configured network interfaces - eth1 either because those interfaces do not exist or are down.&lt;/P&gt;&lt;P&gt;Caused by: com.cisco.profiler.common.ProfilerException: HTTP probe cannot be started on any of the configured network interfaces - eth1 either because those interfaces do not exist or are down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you setup an IP address and restart the ISE Services, it should come up fine:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-10-21 18:33:41,144 INFO&amp;nbsp;&amp;nbsp; [ProfilerController-1-thread-1][] cisco.profiler.probes.http.HttpProbe -:::- Configuring HTTP probe.&lt;/P&gt;&lt;P&gt;2013-10-21 18:33:41,145 INFO&amp;nbsp;&amp;nbsp; [ProfilerController-1-thread-1][] cisco.profiler.probes.http.HttpProbe -:::- Starting HTTP probe.&lt;/P&gt;&lt;P&gt;2013-10-21 18:33:41,145 INFO&amp;nbsp;&amp;nbsp; [ProfilerController-1-thread-1][] cisco.profiler.probes.http.HttpProbe -:::- Starting HTTP SPAN probe on device:eth1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't help, you might open a TAC Case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 16:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-1-2-does-not-do-http-profiling/m-p/2309773#M130618</guid>
      <dc:creator>Bastien Migette</dc:creator>
      <dc:date>2013-10-21T16:38:31Z</dc:date>
    </item>
  </channel>
</rss>

