<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No LLDP profiling data without DHCP? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929396#M37355</link>
    <description>&lt;P&gt;I am trying to move&amp;nbsp;to closed mode with ISE 2.1. The switches are running XE 3.6.4. Only the RADIUS probe is enabled in ISE because I am using device sensors on the switch. The issue I'm running into is that Avaya IP phones that use LLDP are not being profiled correctly once closed mode (no authentication open, no pre-auth ACL) is enabled. The phones are profiled correctly in low impact mode. In closed mode, the phones are profiled as Avaya-Device (top level profile) based on the MAC OUI but that's where it stops. It does not get reprofiled as Avaya-IP-Phone (child profile) based on the LLDP information.&lt;/P&gt;
&lt;P&gt;Port config:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;switchport mode access authentication event fail action next-method&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server dead action authorize&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server dead action authorize voice&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server alive action reinitialize &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication host-mode multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication control-direction in mab authentication violation restrict&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication periodic authentication timer reauthenticate server&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer inactivity server dynamic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Device sensor config:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;lldp run&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor filter-list lldp list lldp_list&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-name&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-description&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-capabilities&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor filter-spec lldp include list lldp_list&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor accounting&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor notify all-changes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;no macro auto monitor&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;access-session template monitor&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;I can look at the LLDP information on the switch and see the LLDP cache populating for the port.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;The weird thing is that I can create an auth rule based on Avaya-Device to assign a dACL that allows DHCP only and it works properly. If I disable that rule,&amp;nbsp;remove the phone from the endpoints list, and bounce the port, the phone will fail to be profiled as Avaya-IP-Phone. This leads me to believe that none of the LLDP info is being passed to ISE and DHCP info is not available without the DHCP rule or fail open config.&lt;/P&gt;
&lt;P&gt;Is this expected behavior or could I be missing a configuration line?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:16:42 GMT</pubDate>
    <dc:creator>Joseph Johnson</dc:creator>
    <dc:date>2019-03-11T07:16:42Z</dc:date>
    <item>
      <title>No LLDP profiling data without DHCP?</title>
      <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929396#M37355</link>
      <description>&lt;P&gt;I am trying to move&amp;nbsp;to closed mode with ISE 2.1. The switches are running XE 3.6.4. Only the RADIUS probe is enabled in ISE because I am using device sensors on the switch. The issue I'm running into is that Avaya IP phones that use LLDP are not being profiled correctly once closed mode (no authentication open, no pre-auth ACL) is enabled. The phones are profiled correctly in low impact mode. In closed mode, the phones are profiled as Avaya-Device (top level profile) based on the MAC OUI but that's where it stops. It does not get reprofiled as Avaya-IP-Phone (child profile) based on the LLDP information.&lt;/P&gt;
&lt;P&gt;Port config:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;switchport mode access authentication event fail action next-method&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server dead action authorize&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server dead action authorize voice&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication event server alive action reinitialize &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication host-mode multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication control-direction in mab authentication violation restrict&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication periodic authentication timer reauthenticate server&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication timer inactivity server dynamic&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dot1x timeout tx-period 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;spanning-tree portfast&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;authentication port-control auto&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Device sensor config:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;lldp run&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor filter-list lldp list lldp_list&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-name&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-description&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;tlv name system-capabilities&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor filter-spec lldp include list lldp_list&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor accounting&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device-sensor notify all-changes&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;no macro auto monitor&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;access-session template monitor&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;I can look at the LLDP information on the switch and see the LLDP cache populating for the port.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;The weird thing is that I can create an auth rule based on Avaya-Device to assign a dACL that allows DHCP only and it works properly. If I disable that rule,&amp;nbsp;remove the phone from the endpoints list, and bounce the port, the phone will fail to be profiled as Avaya-IP-Phone. This leads me to believe that none of the LLDP info is being passed to ISE and DHCP info is not available without the DHCP rule or fail open config.&lt;/P&gt;
&lt;P&gt;Is this expected behavior or could I be missing a configuration line?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929396#M37355</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2019-03-11T07:16:42Z</dc:date>
    </item>
    <item>
      <title>Please provide show version</title>
      <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929397#M37356</link>
      <description>&lt;P&gt;Please provide show version of switch. Is the code a suggested release from CCO.&lt;/P&gt;
&lt;P&gt;I have seen sometimes ISE doesn't get profiled. If I put switch on suggested release, it starts working.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200292-Configure-Device-Sensor-for-ISE-Profilin.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please cross verify the confoguration from above document.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate if it helps!!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 10:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929397#M37356</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-12-08T10:16:38Z</dc:date>
    </item>
    <item>
      <title>The switch is running IOX XE</title>
      <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929398#M37357</link>
      <description>&lt;P&gt;The switch is running IOX XE 3.8.0 now and it still does not work properly. It's a weird issue that goes away if I allow DHCP (nothing else).&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 23:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929398#M37357</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-12-08T23:28:22Z</dc:date>
    </item>
    <item>
      <title>Latest finding:</title>
      <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929399#M37358</link>
      <description>&lt;P&gt;Latest finding:&lt;/P&gt;
&lt;P&gt;So it turns out I don't need to allow DHCP. If I change the default authorization rule from&amp;nbsp;DenyAccess&amp;nbsp;(ACCESS-REJECT) to a custom authorization profile that is ACCEPT-ACCEPT but pushes a dACL with "deny ip any any", device sensor data is received by ISE and the endpoint is profiled correctly.&lt;/P&gt;
&lt;P&gt;This is really odd because none of the documentation I've found mentions having to set the default rule to anything other than DenyAccess for closed mode. We tested it several times. The results were always the same.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Default rule DenyAccess: No device sensor data received even though the switch shows cached sensor information on the port.&lt;/LI&gt;
&lt;LI&gt;Default rule custom with ACCESS-ACCEPT and "deny ip any any" dACL: Device sensor data received.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Does the ACCESS-REJECT completely shut off sending the device sensor data to ISE?&lt;/P&gt;
&lt;P&gt;Anyone see a problem with using ACCESS-ACCEPT profile with a deny all dACL as the default rule, as well as no open authentication on the port, and considering the installation "closed mode"?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 13:45:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929399#M37358</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-12-15T13:45:25Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929400#M37359</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, I have seen this behavior in case of deny access rule. In order to trigger that it needs radius accounting packet to receive on ISE which will only be triggered when you have limited access from ISE for initial authentication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let's take the below from one of the internal cases&lt;/P&gt;
&lt;P&gt;In absence of Cisco-Device limited policy in the authorization policies, the cisco devices / Cisco-IP-Phone will not get profiled due to the reason that: Radius Accounting packets need to be triggered, which in turn trigger SNMP query to occur from the ISE node. ISE will only trigger SNMP query on the device that pass some level of authorization (with Radius Access-Accept) in the authorization policy. In this case the limited authorization can be defined with Cisco-Device.&lt;/P&gt;
&lt;P&gt;During the first authentication and authorization attempt, the endpoint gets (IP phone) profiled to Cisco-Device authorization policy using the limited access policy and causes radius accounting start packet to trigger from the switch. A subsequent CoA is sent after ISE receives sufficient attributes to re-profile the phone. This is a security feature to only allow legitimate cisco-devices to trigger snmp as we do not want just about any devices to trigger SNMP query.&lt;/P&gt;
&lt;P&gt;If the concern is about giving limited access with DACL in the Cisco-Device authorization policy, you can create a dummy dynamic VLAN as part of limited access instead of DACL. The Dummy vlan can be any private restricted vlan and the limited authorization profile need to have an Access-Accept to trigger the Radius-Accounting start. So, that the subsequent CoA will re-profile the phone.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps : rate if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 17:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-lldp-profiling-data-without-dhcp/m-p/2929400#M37359</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-12-15T17:54:58Z</dc:date>
    </item>
  </channel>
</rss>

