<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device Sensor Filter Lists and MUD Profling in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885726#M471918</link>
    <description>Just to confirm then, tlv 127 will always be sent to ISE even if we don't have it explicitly configured?  I find it a bit confusing because the filter lists are reversed since we are telling it what to include, and it comes up with the message of "hard filtered".  &lt;BR /&gt;&lt;BR /&gt;Thanks for clarifying and looking in to it.</description>
    <pubDate>Sun, 07 Jul 2019 05:50:18 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-07-07T05:50:18Z</dc:date>
    <item>
      <title>Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3881016#M471899</link>
      <description>&lt;P&gt;I was looking to play with MUD using some existing switches already configured for ISE. So being as new as it is, that meant going to the RFC.&amp;nbsp;&amp;nbsp;&lt;A href="https://tools.ietf.org/id/draft-ietf-opsawg-mud-09.html" target="_blank"&gt;https://tools.ietf.org/id/draft-ietf-opsawg-mud-09.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It looks like we cannot use device sensor filter lists if we also want to use MUD. I've seen some pretty ugly issues when device sensor filter lists are missing, and I always thought it was best practice to use them. The RFC indicates that that TLV 127 (vendor specific) is what the MUD URL is sent with, seems like that might have been a bad number?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IOS-XE 16.6.6&lt;/P&gt;
&lt;P&gt;3850(config)#device-sensor filter-list lldp list lldp-list&lt;BR /&gt;3850(config-sensor-lldplist)#tlv name system-description&lt;BR /&gt;3850(config-sensor-lldplist)#tlv number 127&lt;BR /&gt;LLDP tlv 127 is hard filtered, hence cannot be configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the best way to address this so we can leverage it once moving to 2.6?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 18:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3881016#M471899</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-06-27T18:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882015#M471901</link>
      <description>&lt;P&gt;The beta test plan shows IOS-XE 16.9.1 FCS2 used. Please try that while I am checking with the SMEs.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2019 20:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882015#M471901</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-06-29T20:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882041#M471906</link>
      <description>&lt;P&gt;At least with 16.9.3a the results are the same. I could test again on 16.9.1, but I suspect this configuration will be identical.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to clarify too, I'm only testing configuration at this point. I am making the assumption that if I cannot add "tlv number 127" to my LLDP filter list, then the switch will not forward it. I suspect it works fine if we don't enable device sensor filtering, but that goes against what we would want since device sensor can be very spammy without it.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2019 22:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882041#M471906</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-06-29T22:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882043#M471914</link>
      <description>&lt;P&gt;Even though the test plan not adding this tlv number 127 to the LLDP filter-list, the expected result shows it. So...&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;3850(config)#device-sensor filter-list lldp list lldp-list&lt;BR /&gt;3850(config-sensor-lldplist)#tlv name system-description&lt;BR /&gt;3850(config-sensor-lldplist)#tlv number 127&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;LLDP tlv 127 is hard filtered&lt;/STRONG&gt;, hence cannot be configured.&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;most likely means it's always available in the filter.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 02:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3882043#M471914</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-06-30T02:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885480#M471916</link>
      <description>&lt;P&gt;I got a confirmation that 127 is always there in the LLDP filter list and not configurable.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 22:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885480#M471916</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-05T22:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885726#M471918</link>
      <description>Just to confirm then, tlv 127 will always be sent to ISE even if we don't have it explicitly configured?  I find it a bit confusing because the filter lists are reversed since we are telling it what to include, and it comes up with the message of "hard filtered".  &lt;BR /&gt;&lt;BR /&gt;Thanks for clarifying and looking in to it.</description>
      <pubDate>Sun, 07 Jul 2019 05:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885726#M471918</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-07T05:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885917#M471922</link>
      <description>&lt;P&gt;Yes, that is the case. Below is the LLDP filter list used in the test plan:&lt;/P&gt;
&lt;PRE&gt;device-sensor filter-list lldp list lldp-list
 tlv name end-of-lldpdu
 tlv name chassis-id
 tlv name port-id
 tlv name time-to-live
 tlv name port-description
 tlv name system-name
 tlv name system-description
 tlv name system-capabilities
 tlv name management-address
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jul 2019 23:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885917#M471922</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-07T23:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Device Sensor Filter Lists and MUD Profling</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885928#M471925</link>
      <description>Thanks for looking in to this.</description>
      <pubDate>Mon, 08 Jul 2019 00:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-filter-lists-and-mud-profling/m-p/3885928#M471925</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-07-08T00:50:19Z</dc:date>
    </item>
  </channel>
</rss>

