<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Aruba AP Profiling in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887220#M471622</link>
    <description>&lt;P&gt;I ran in to very minor issue around profiling Aruba AP's and am looking to see if we can get this fixed at the source. ISE was not able to successfully&amp;nbsp;profile an Aruba APIN0325 WAP because the MAC OUI was resolving to a different name than the Aruba parent policy is configured for.&amp;nbsp; So in short, the ArubaAP profile is nested under the Aruba-Device parent profile which doesn't get hit. It would be nice to see the profiler feed updated to address this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Parent profile: Aruba-Device&lt;BR /&gt;matches:&amp;nbsp; OUI CONTAINS ARUBA NETWORKS&lt;/P&gt;
&lt;P&gt;Child profile: ArubaAP&lt;BR /&gt;matches:&amp;nbsp;DHCP:dhcp-class-identifier EQUALS ArubaInstantAP OR DHCP:dhcpv6-vendor-class EQUALS ArubaInstantAP OR&amp;nbsp;DHCP:dhcp-class-identifier EQUALS ArubaAP&lt;BR /&gt;&lt;BR /&gt;The Aruba AP has a MAC address that begins with &lt;SPAN&gt;AC:A3:1E, and ISE is resolving this OUI as "Aruba,&amp;nbsp;&lt;/SPAN&gt;a Hewlett Packard Enterprise Company", not "Aruba Networks". The&amp;nbsp;dhcp-class-identifier attribute is coming through correctly with ArubaAP, so when we make a slight adjustment to the parent profile, it then matches the child correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a side discussion to this, I've seen this before with other products as well where the MAC OUI text changes and ISE no longer profiles it, is it normal for these to change?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2022 06:55:08 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2022-03-10T06:55:08Z</dc:date>
    <item>
      <title>Aruba AP Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887220#M471622</link>
      <description>&lt;P&gt;I ran in to very minor issue around profiling Aruba AP's and am looking to see if we can get this fixed at the source. ISE was not able to successfully&amp;nbsp;profile an Aruba APIN0325 WAP because the MAC OUI was resolving to a different name than the Aruba parent policy is configured for.&amp;nbsp; So in short, the ArubaAP profile is nested under the Aruba-Device parent profile which doesn't get hit. It would be nice to see the profiler feed updated to address this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Parent profile: Aruba-Device&lt;BR /&gt;matches:&amp;nbsp; OUI CONTAINS ARUBA NETWORKS&lt;/P&gt;
&lt;P&gt;Child profile: ArubaAP&lt;BR /&gt;matches:&amp;nbsp;DHCP:dhcp-class-identifier EQUALS ArubaInstantAP OR DHCP:dhcpv6-vendor-class EQUALS ArubaInstantAP OR&amp;nbsp;DHCP:dhcp-class-identifier EQUALS ArubaAP&lt;BR /&gt;&lt;BR /&gt;The Aruba AP has a MAC address that begins with &lt;SPAN&gt;AC:A3:1E, and ISE is resolving this OUI as "Aruba,&amp;nbsp;&lt;/SPAN&gt;a Hewlett Packard Enterprise Company", not "Aruba Networks". The&amp;nbsp;dhcp-class-identifier attribute is coming through correctly with ArubaAP, so when we make a slight adjustment to the parent profile, it then matches the child correctly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a side discussion to this, I've seen this before with other products as well where the MAC OUI text changes and ISE no longer profiles it, is it normal for these to change?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 06:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887220#M471622</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2022-03-10T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887279#M471624</link>
      <description>Please open a tac case and defect for fix&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Jul 2019 20:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887279#M471624</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-07-09T20:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887358#M471626</link>
      <description>How often should the text of these change?  Are we allowed to know where Cisco gets their OUI names?</description>
      <pubDate>Tue, 09 Jul 2019 23:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3887358#M471626</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-09T23:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3888875#M471627</link>
      <description>&lt;P&gt;The IEEE maintains master OUI lists. These changes do happen from time to time such as here due to company mergers and acquisitions. &amp;nbsp;It happened about two years ago when many of the OUIs assigned to Apple were consolidated. &amp;nbsp;Consequently, many of the default ISE profiles based on original OUIs failed to match. &amp;nbsp;As you probably know, you can address using interim workaround by adding a custom condition to top-level Aruba-Device profile that matches on new OUI value (for example, STARTSWITH Aruba, or CONTAINS Aruba), but agree that ultimate fix would be via profile update. This is a case where you want to test Feed updates offline prior to production import/pull and why automated online feed can have unexpected/undesirable results. Ideally there would be a check for all OUI changes and determine if any impacted default Cisco provided profiles, thus necessitating profile update.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 02:50:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aruba-ap-profiling/m-p/3888875#M471627</guid>
      <dc:creator>chyps</dc:creator>
      <dc:date>2019-07-12T02:50:37Z</dc:date>
    </item>
  </channel>
</rss>

