<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to override the client attibutes from ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4011282#M454690</link>
    <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer. we have already actived the AD Probe. we will check the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robin&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2020 15:23:20 GMT</pubDate>
    <dc:creator>lupingyao</dc:creator>
    <dc:date>2020-01-14T15:23:20Z</dc:date>
    <item>
      <title>how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007562#M454681</link>
      <description>&lt;P&gt;we have the ISE 2.6 with Profiling license, after we update one client system from win7 to win10, in ISE we can just see the old information(win7), how can I override the old attibutes? I tried with nmap mauel scan, but after scan the ISE show me win7... But the system is already updated to win10...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone have a good idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robin&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 14:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007562#M454681</guid>
      <dc:creator>lupingyao</dc:creator>
      <dc:date>2020-01-07T14:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007575#M454683</link>
      <description>&lt;P&gt;Moved the discussion to ISE Forum for better visibility.&lt;/P&gt;
&lt;P&gt;Depending on your profiler probes that are active, you would normally get new information and overwrite any previous values when the probe receives it.&lt;/P&gt;
&lt;P&gt;You could also remove the endpoint from context visibility to "force" a new profile to be discerned the next time the device connects.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 13:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007575#M454683</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-01-07T13:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007581#M454684</link>
      <description>Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;thanks for quickly answer. yes i can do this, but we don't know which one client is updated to win 10, I would like to do a scan-override action for one network every week. is it possible?&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jan 2020 14:08:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007581#M454684</guid>
      <dc:creator>lupingyao</dc:creator>
      <dc:date>2020-01-07T14:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007820#M454686</link>
      <description>You can't manually update this attribute on an endpoint.  You could delete it from the context visibility database, and on the next authentication it would refresh itself. &lt;BR /&gt;&lt;BR /&gt;If AD has stale information, then ISE will have stale information.  If you do nothing, ISE should update this endpoint the next time the AD profiling probe runs against it.</description>
      <pubDate>Tue, 07 Jan 2020 21:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007820#M454686</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-01-07T21:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007852#M454688</link>
      <description>&lt;P&gt;Hi Robin,&lt;/P&gt;
&lt;P&gt;To answer your question, there is no way to schedule a weekly manual NMAP scan. Triggered NMAP scans only take place if the Exception Action is configured in the Profiling Policies.&lt;/P&gt;
&lt;P&gt;Keep in mind that discovering the Windows OS version via NMAP requires the use of the SMB Discovery scan. This is typically not very useful because SMB ports would normally be blocked somewhere in the path between the PSN and the end PC or limited by the host firewall.&lt;/P&gt;
&lt;P&gt;There is no difference between the DHCP Class Identifier for Windows 7 and 10 (both are 'MSFT 5.0'), so the AD Probe provides the best method for profiling the OS on AD-joined computers. If you're not using the AD Probe, you should consider enabling it. If you're using the AD Probe, but ISE is receiving incorrect OS info from AD, you might need to investigate AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 22:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4007852#M454688</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-01-07T22:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to override the client attibutes from ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4011282#M454690</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer. we have already actived the AD Probe. we will check the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Robin&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 15:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-override-the-client-attibutes-from-ise/m-p/4011282#M454690</guid>
      <dc:creator>lupingyao</dc:creator>
      <dc:date>2020-01-14T15:23:20Z</dc:date>
    </item>
  </channel>
</rss>

