<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DHCP Probe does not work in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3864978#M472786</link>
    <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i have three Cat6500 that act as DHCP servers (each one of them in a different VTP Domain) i wouldn't&amp;nbsp; prefer to use SPAN sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But what do you mean to use ip helper on the L3 SVI on the downstream?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already use ip helper addresses in the SVIs on the Cat6500s side (where the DHCP server reside).&lt;/P&gt;&lt;P&gt;Do you suggest something different?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, as i have already done some testing with external linux vm acting as a DHCP server and ISE PSNs started to get the DHCP messages, i am considering of permanently enabling external DHCP services on linux vms and canceling the DHCP services on the 6500s.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support,&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
    <pubDate>Thu, 30 May 2019 06:39:03 GMT</pubDate>
    <dc:creator>Ditter</dc:creator>
    <dc:date>2019-05-30T06:39:03Z</dc:date>
    <item>
      <title>DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862357#M472690</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i wonder if you can help me in the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two cisco PSNs.&amp;nbsp; Both of them are configured as profiling nodes&amp;nbsp; and both of them have activated the following three probes:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. SNMP Query Probe&lt;/P&gt;&lt;P&gt;2. DNS Probe&lt;/P&gt;&lt;P&gt;3. DHCP Probe&lt;/P&gt;&lt;P&gt;4. Radius Probe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition on the Cisco routers that act as DHCP servers i have configured ip helper addressess that point to the two PSNs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that not even one endpoint has been profiled via the DHCP probe , most of them have&amp;nbsp; been profiled through SNMP and some of them through Radius Probe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please not that the DHCP clients are not 802.1x clients, simple endpoints that come in the network as simple DHCP clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any possibility that the Cisco DHCP servers that runs on the various 6500s suppress the ip helper messages because of the fact that the DHCP server is itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also suspected ip forward-protocol but at least for bootp the ip forward protocol is on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2019 13:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862357#M472690</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-05-24T13:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862517#M472691</link>
      <description>Are your devices configured to act as a sensor? Should be something along these lines:&lt;BR /&gt;#device-sensor notify all-changes&lt;BR /&gt;#device-sensor filter-spec dhcp include list dhcpLIST&lt;BR /&gt;#device-sensor filter-list dhcp list dhcpLIST&lt;BR /&gt;##option name host-name&lt;BR /&gt;##option (? will show you the attribute list)&lt;BR /&gt;&lt;BR /&gt;Good luck &amp;amp; HTH!</description>
      <pubDate>Fri, 24 May 2019 16:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862517#M472691</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-05-24T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862635#M472692</link>
      <description>&lt;P&gt;thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not all my switches support device sensor , i have many cat 4500 that do not support the sensor command.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2019 20:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3862635#M472692</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-05-24T20:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3863239#M472737</link>
      <description>&lt;P&gt;It seems that no bootps packets reach ISE PSNs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am suspecting the DHCP server which is the cisco router itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any possibility that as Csico router is the DHCP server itself does not forward the same DHCP requests to the ISE PSNs although ip helper-address is configured and no firewall exists between the dhcp clients vlan and the ISE vlan ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 09:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3863239#M472737</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-05-27T09:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3863287#M472738</link>
      <description>&lt;P&gt;I did some more settings with external DHCP Server and ISE successfully gets the dhcp packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i am convinced that when the Cat6500 acts as a DHCP server does not forward DHCP packets to ISE.&lt;/P&gt;&lt;P&gt;although forward protocol is ON for bootps and ip helper-address is correctly configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it bug or a feature of Cat6500?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 11:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3863287#M472738</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-05-27T11:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3864699#M472739</link>
      <description>&lt;P&gt;Something to ask the switching group. You can rely on dhcp span if needed. What about ip helper on the L3 SVI on the downstream? Setup a DHCP server instead of using the network infrastructure and send it to that instead? A microsoft DHCP server perhaps?&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 19:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3864699#M472739</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-29T19:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3864978#M472786</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i have three Cat6500 that act as DHCP servers (each one of them in a different VTP Domain) i wouldn't&amp;nbsp; prefer to use SPAN sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But what do you mean to use ip helper on the L3 SVI on the downstream?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already use ip helper addresses in the SVIs on the Cat6500s side (where the DHCP server reside).&lt;/P&gt;&lt;P&gt;Do you suggest something different?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, as i have already done some testing with external linux vm acting as a DHCP server and ISE PSNs started to get the DHCP messages, i am considering of permanently enabling external DHCP services on linux vms and canceling the DHCP services on the 6500s.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your support,&lt;/P&gt;&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 06:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3864978#M472786</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-05-30T06:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3865080#M472787</link>
      <description>The external server as you found is the way to go. You have tried the other viable options and they are not working&lt;BR /&gt;</description>
      <pubDate>Thu, 30 May 2019 10:24:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3865080#M472787</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-05-30T10:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Probe does not work</title>
      <link>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3865452#M472788</link>
      <description>&lt;P&gt;Hi Ditter,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 6500 won't send DHCP broadcast (start of DORA) to ip helper addresses because itself is the DHCP server.&amp;nbsp; To profile devices using DHCP you will need to either:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;Remove local DHCP services and migrate to another one e.g. Microsoft DHCP or other.&lt;/LI&gt;&lt;LI&gt;Leverage SPAN ports for DHCP however it may be inconvenient to run up PSN (virtual) all over your campus/network to ingest SPAN information.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hope this answers your question.&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 21:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dhcp-probe-does-not-work/m-p/3865452#M472788</guid>
      <dc:creator>adriansoh</dc:creator>
      <dc:date>2019-05-30T21:49:54Z</dc:date>
    </item>
  </channel>
</rss>

