<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I actually enabled all probes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895995#M39530</link>
    <description>&lt;P&gt;I actually enabled all probes to see if it would help. One thing my cisco rep said is to check the prob log, do you know where to access that?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jun 2016 14:35:38 GMT</pubDate>
    <dc:creator>Dustin Anderson</dc:creator>
    <dc:date>2016-06-10T14:35:38Z</dc:date>
    <item>
      <title>MacBook profiles as Cisco-Switch in 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895987#M39507</link>
      <description>&lt;P&gt;I'm&amp;nbsp;experimenting with trying to get Mac's to profile on ISE. 2.1. I've tried installing AnyConnect and for some reason it sees it as a Nexus 7000 switch.&lt;/P&gt;
&lt;P&gt;Here's info from the debug&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attribute:AAA-Server value:ise-2&lt;BR /&gt;Attribute:Airespace-Wlan-Id value:5&lt;BR /&gt; Attribute:AllowedProtocolMatchedRule value:EAP_Chaining_Wireless&lt;BR /&gt;Attribute:AuthenticationMethod value:MSCHAPV2&lt;BR /&gt; Attribute:AuthorizationPolicyMatchedRule value:Default&lt;BR /&gt; Attribute:BYODRegistration value:Unknown&lt;BR /&gt; Attribute:CacheUpdateTime value:1465417705907&lt;BR /&gt; Attribute:Called-Station-ID value:20-3a-07-66-96-20&lt;BR /&gt; Attribute:Calling-Station-ID value:a4-5e-60-cf-81-83&lt;BR /&gt; Attribute:CreateTime value:1464896196500&lt;BR /&gt; Attribute:DestinationIPAddress value:10.10.207.156&lt;BR /&gt; Attribute:DestinationPort value:1812&lt;BR /&gt; Attribute:DetailedInfo value:Authentication succeed&lt;BR /&gt; Attribute:Device IP Address value:10.10.204.114&lt;BR /&gt; Attribute:Device Identifier value:&lt;BR /&gt; Attribute:Device Port value:32772&lt;BR /&gt; Attribute:Device Type value:Device Type#All Device Types&lt;BR /&gt; Attribute:DeviceCompliance value:Unknown&lt;BR /&gt; Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt; Attribute:EndPointMACAddress value:A4-5E-60-CF-81-83&lt;BR /&gt; Attribute:EndPointPolicy value:Cisco-Switch&lt;BR /&gt; Attribute:EndPointPolicyID value:4afc4ae0-6d8e-11e5-978e-005056bf2f0a&lt;BR /&gt; Attribute:EndPointProfilerServer value:ise-2&lt;BR /&gt; Attribute:EndPointSource value:RADIUS Probe&lt;BR /&gt; Attribute:FailureReason value:5440 Endpoint abandoned EAP session and started new&lt;BR /&gt; Attribute:FirstCollection value:1464896196418&lt;BR /&gt; Attribute:Framed-IP-Address value:&lt;BR /&gt; Attribute:Framed-IPv6-Address value:&lt;BR /&gt; Attribute:IdentityAccessRestricted value:false&lt;BR /&gt; Attribute:IdentityGroup value:Profiled&lt;BR /&gt; Attribute:IdentityGroupID value:b132c920-6d8d-11e5-978e-005056bf2f0a&lt;BR /&gt; Attribute:IsThirdPartyDeviceFlow value:false&lt;BR /&gt; Attribute:LastActivity value:1465417705904&lt;BR /&gt; Attribute:LastNmapScanTime value:1465245395228&lt;BR /&gt; Attribute:Location value:Location#All Locations&lt;BR /&gt; Attribute:LogicalProfile value:Infrastructure Network Devices&lt;BR /&gt; Attribute:MACAddress value:A4:5E:60:CF:81:83&lt;BR /&gt; Attribute:MDMServerID value:&lt;BR /&gt; Attribute:MatchedPolicy value:Cisco-Switch&lt;BR /&gt; Attribute:MatchedPolicyID value:4afc4ae0-6d8e-11e5-978e-005056bf2f0a&lt;BR /&gt; Attribute:MessageCode value:5440&lt;BR /&gt; Attribute:NAS-IP-Address value:10.10.204.114&lt;BR /&gt; Attribute:NAS-Identifier value:WLC-3&lt;BR /&gt; Attribute:NAS-Port value:1&lt;BR /&gt; Attribute:NAS-Port-Type value:Wireless - IEEE 802.11&lt;BR /&gt; Attribute:Network Device Profile value:Cisco&lt;BR /&gt; Attribute:NetworkDeviceGroups value:Location#All Locations, Device Type#All Device Types&lt;BR /&gt; Attribute:NetworkDeviceName value:WLC-3&lt;BR /&gt; Attribute:NetworkDeviceProfileId value:8ade1f15-aef1-4a9a-8158-d02e835179db&lt;BR /&gt; Attribute:NetworkDeviceProfileName value:Cisco&lt;BR /&gt; Attribute:NmapScanCount value:1&lt;BR /&gt; Attribute:NmapSubnetScanID value:0&lt;BR /&gt; Attribute:OUI value:Apple, Inc.&lt;BR /&gt; Attribute:PhoneID value:&lt;BR /&gt; Attribute:PolicyVersion value:32&lt;BR /&gt; Attribute:PortalUser value:&lt;BR /&gt; Attribute:PostureApplicable value:Yes&lt;BR /&gt; Attribute:PostureAssessmentStatus value:NotApplicable&lt;BR /&gt; Attribute:PostureExpiry value:&lt;BR /&gt; Attribute:PostureStatus value:Unknown&lt;BR /&gt; Attribute:RadiusFlowType value:Wireless802_1x&lt;BR /&gt; Attribute:RadiusPacketType value:AccessRequest&lt;BR /&gt; Attribute:RegistrationTimeStamp value:0&lt;BR /&gt; Attribute:Response value:{RadiusPacketType=Drop; }&lt;BR /&gt; Attribute:SSID value:20-3a-07-66-96-20&lt;BR /&gt; Attribute:SelectedAccessService value:Default Network Access&lt;BR /&gt; Attribute:SelectedAuthenticationIdentityStores value:Internal Users, ise-2, All_AD_Join_Points&lt;BR /&gt; Attribute:SelectedAuthorizationProfiles value:DenyAccess&lt;BR /&gt; Attribute:Service-Type value:Framed&lt;BR /&gt; Attribute:StaticAssignment value:false&lt;BR /&gt; Attribute:StaticGroupAssignment value:false&lt;BR /&gt; Attribute:StepData value:4= Normalised Radius.RadiusFlowType, 5=EAP_Chaining_Wireless&lt;BR /&gt; Attribute:TLSCipher value:ECDHE-RSA-AES256-SHA&lt;BR /&gt; Attribute:TLSVersion value:TLSv1&lt;BR /&gt; Attribute:TimeToProfile value:44&lt;BR /&gt; Attribute:Total Certainty Factor value:30&lt;BR /&gt; Attribute:UniqueSubjectID value:&lt;BR /&gt; Attribute:UpdateTime value:1465245396597&lt;BR /&gt;Attribute:allowEasyWiredSession value:false&lt;BR /&gt; Attribute:host-name value:&lt;BR /&gt; Attribute:ip value:&lt;BR /&gt; Attribute:operating-system value:Cisco Nexus 7000 switch (NX-OS 4.2.6) (accuracy 99%)&lt;BR /&gt; Attribute:operating-system-result value:Cisco Nexus 7000 switch (NX-OS 4.2.6) (accuracy 99%)&lt;BR /&gt; Attribute:SkipProfiling value:false&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:51:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895987#M39507</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2019-03-11T06:51:00Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895988#M39510</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;as per number of years I'm installing ISE, I experienced that issue only 1 time. To solve this issue for me it was to update&amp;nbsp;&lt;SPAN&gt;Administration&amp;gt;Feed Service&amp;gt;Profiler.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don't know why the 1st time it was saying&amp;nbsp;&lt;/SPAN&gt;successful but not working. I had stopped and restarted all services, do again update and then it was profiled correctly.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You may try this. If not working, I hope someone else could give you some helps otherwise you need to open a TAC case.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2016 22:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895988#M39510</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-08T22:45:58Z</dc:date>
    </item>
    <item>
      <title>I increased the weights on</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895989#M39515</link>
      <description>&lt;P&gt;I increased the weights on the apple profile, but still hate that mac's don't profile at all. Most I get is the MAC oui. Anyconnect doesn't seem to pass any more info along. Wish it would be like windows and at least give me the OS version.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 14:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895989#M39515</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-09T14:31:45Z</dc:date>
    </item>
    <item>
      <title>Did you tried feed update?</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895990#M39523</link>
      <description>&lt;P&gt;Did you tried feed update?&lt;/P&gt;
&lt;P&gt;When I got this issue i had played with all profiles but nothing was working except feed updates as I mentioned before.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Maybe you need to raise a Tac case?&lt;/P&gt;
&lt;P&gt;I'm sorry to not helping more but I had this issue only 1 time on several deployment and no time to troubleshoot more as I solved it after updates in a specific order.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 20:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895990#M39523</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-09T20:25:50Z</dc:date>
    </item>
    <item>
      <title>Yeah, I tried feed update. I</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895991#M39524</link>
      <description>&lt;P&gt;Yeah, I tried feed update. I can't do a TAC since it's only a demo atm. It looks like we will be going to it, so may just have to wait for purchase and then open a TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 22:54:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895991#M39524</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-09T22:54:10Z</dc:date>
    </item>
    <item>
      <title>Have you patched ISE with</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895992#M39525</link>
      <description>&lt;P&gt;Have you patched ISE with latest patches?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've not tested yet version 2.1 in production. As it is a test, have you done the same work with version 2.0?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 23:00:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895992#M39525</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-09T23:00:40Z</dc:date>
    </item>
    <item>
      <title>Yeah, had the same issue with</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895993#M39526</link>
      <description>&lt;P&gt;Yeah, had the same issue with 2.0.1. all Apple came in as Apple-Device. Could be an issue because of doing EAP-Chaining for windows PC's&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 00:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895993#M39526</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-10T00:29:42Z</dc:date>
    </item>
    <item>
      <title>Apple-Device is quite good</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895994#M39528</link>
      <description>Apple-Device is quite good compare to cisco-switch has you said. 

What kind of probes are you using?
I don't see any related issue with EAP-CHAINING</description>
      <pubDate>Fri, 10 Jun 2016 00:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895994#M39528</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-10T00:34:08Z</dc:date>
    </item>
    <item>
      <title>I actually enabled all probes</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895995#M39530</link>
      <description>&lt;P&gt;I actually enabled all probes to see if it would help. One thing my cisco rep said is to check the prob log, do you know where to access that?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 14:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895995#M39530</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-10T14:35:38Z</dc:date>
    </item>
    <item>
      <title>You will find all things on</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895996#M39532</link>
      <description>&lt;P&gt;You will find all things on Monitor tab, Troubleshooting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to set the level of logs, you need to go on Administration/System/Logging&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 14:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895996#M39532</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-10T14:58:17Z</dc:date>
    </item>
    <item>
      <title>HA! Got it, We set up the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895997#M39533</link>
      <description>&lt;P&gt;HA! Got it, We set up the ISE server on the firewall as a DHCP server so all the traffic is also forwarded to it. This and the DHCP probe finally gave me the hostname and we start all them with the prefix MB, so I was able to make a new profile rule looking for hostname starting with MB and added it to Apple-MacBook.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 16:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895997#M39533</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-10T16:04:05Z</dc:date>
    </item>
    <item>
      <title>Can you explain this a little</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895998#M39534</link>
      <description>&lt;P&gt;Can you explain this a little bit?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have read adding the ISE node to the DHCP helper command will help with profiling.&lt;/P&gt;
&lt;P&gt;On the WLC I point the interface to our DHCP servers, how can I also forward that traffic to ISE to use for profiling?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 18:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895998#M39534</guid>
      <dc:creator>michaellperrin</dc:creator>
      <dc:date>2016-06-10T18:42:06Z</dc:date>
    </item>
    <item>
      <title>Ok you've done it manually,</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895999#M39535</link>
      <description>&lt;P&gt;Ok you've done it manually, but normally you don't need question. I asked which probe you were using. Could you confirm me that you set ip dhcp helper on all SVI pointing to your ISE server?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 18:45:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2895999#M39535</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-10T18:45:38Z</dc:date>
    </item>
    <item>
      <title>Ok, wish I was still at work</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896000#M39536</link>
      <description>&lt;P&gt;Ok, wish I was still at work to verify and get some screenshots. Our main networker set it up, but I think I caught what he did. Basically, for 2 of our wireless networks, we have DHCP relay set up to forward requests to our 2 servers. We just added the ISE server as a third DHCP server for our onboarding network. This way, when a wireless device connects, the firewall sends the DHCP request to the servers and the ISE.&lt;/P&gt;
&lt;P&gt;This at least gets me the hostname to use in profiling.&lt;/P&gt;
&lt;P&gt;As for a WLC, I would guess if you are doing DHCP relay on that, you could just add your ISE in as a DHCP server so it also gets the traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 20:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896000#M39536</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-10T20:43:35Z</dc:date>
    </item>
    <item>
      <title>Yes you need to add ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896001#M39537</link>
      <description>&lt;P&gt;Yes you need to add ISE server in your dhcp helper (dhcp relay) in order to get some information on DHCP request to profile correctly devices.&lt;/P&gt;
&lt;P&gt;Even after setting correctly ISE in your DHCP relay, you aren't able to profile?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 21:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896001#M39537</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-10T21:54:07Z</dc:date>
    </item>
    <item>
      <title>Better than it was. It just</title>
      <link>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896002#M39538</link>
      <description>&lt;P&gt;Better than it was. It just gives me hostname, so if the name contains iPhone iPad etc it works.&lt;/P&gt;
&lt;P&gt;I was more concerned on MacBooks, but we use a specific naming scheme, so can profile those by the name prefix.&lt;/P&gt;
&lt;P&gt;This is just for company managed devices, so not a BYOD setup. I know you can get more if you do a web redirect to a login page, but we don't want to do that for company systems.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2016 02:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macbook-profiles-as-cisco-switch-in-2-1/m-p/2896002#M39538</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-06-11T02:58:38Z</dc:date>
    </item>
  </channel>
</rss>

