<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about ISE Profiling with Device Sensor in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/question-about-ise-profiling-with-device-sensor/m-p/3999477#M454992</link>
    <description>&lt;P&gt;That is correct.&amp;nbsp; In fact, if you are only using DHCP Snooping for DHCP profiling, then you can use the following command:&lt;/P&gt;&lt;P&gt;"ip dhcp snooping glean"&lt;/P&gt;&lt;P&gt;That command will basically use DHCP Snooping only for learning the bindings but will not try to enforce any DHCP Snooping violations.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Dec 2019 15:52:33 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2019-12-16T15:52:33Z</dc:date>
    <item>
      <title>Question about ISE Profiling with Device Sensor</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-profiling-with-device-sensor/m-p/3999436#M454991</link>
      <description>&lt;P&gt;Hello, I have been looking for confirmation for the following questions.&lt;/P&gt;&lt;P&gt;Background:&lt;/P&gt;&lt;P&gt;Medium ISE deployment&lt;/P&gt;&lt;P&gt;Large number of non 802.1X devices, need to have profiling to classify them.&lt;/P&gt;&lt;P&gt;Switching is a mix of Cat 3750,3850,45xx, (15.X/3.X) a few of the newer Cat 9x (16.X)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP Snooping with Database Agent for DHCP Device Sensor&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is it still common practice to have the Database Agent also configured?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Why I ask is in the all of the configuration examples I have found that have ip dhcp snooping, none have any reference to also having the Database agent configured in case of switch reboot.&lt;/P&gt;&lt;P&gt;Reading over the version documentation (3.x)&lt;/P&gt;&lt;P&gt;&lt;EM&gt;To keep the bindings when the switch reloads, you must use the DHCP snooping database agent. If the agent is disabled, dynamic ARP inspection or IP source guard is enabled, and the DHCP snooping binding database has dynamic bindings, the switch loses its connectivity. If the agent is disabled and only DHCP snooping is enabled, the switch does not lose its connectivity, but DHCP snooping might not prevent DHCP spoofing attacks.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only dhcp sno&lt;/SPAN&gt;oping will be enabled only for Device Sensor so my interpretation is that I don't need the database agent, so if the switch were to reboot the clients will not loss connectivity.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is that correct?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;CC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 14:57:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-profiling-with-device-sensor/m-p/3999436#M454991</guid>
      <dc:creator>ccole</dc:creator>
      <dc:date>2019-12-16T14:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question about ISE Profiling with Device Sensor</title>
      <link>https://community.cisco.com/t5/network-access-control/question-about-ise-profiling-with-device-sensor/m-p/3999477#M454992</link>
      <description>&lt;P&gt;That is correct.&amp;nbsp; In fact, if you are only using DHCP Snooping for DHCP profiling, then you can use the following command:&lt;/P&gt;&lt;P&gt;"ip dhcp snooping glean"&lt;/P&gt;&lt;P&gt;That command will basically use DHCP Snooping only for learning the bindings but will not try to enforce any DHCP Snooping violations.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 15:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-about-ise-profiling-with-device-sensor/m-p/3999477#M454992</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-12-16T15:52:33Z</dc:date>
    </item>
  </channel>
</rss>

