<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Attribute Filter - Enabling for Additional Device Attributes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/endpoint-attribute-filter-enabling-for-additional-device/m-p/3730918#M489162</link>
    <description>&lt;P&gt;A customer of mine has a deployment with approx 10k active devices.&amp;nbsp; Some of the medical devices with static IP addresses are not profiling beyond the ethernet vendor code.&amp;nbsp; Some of these devices share the same ethernet NIC vendor and it is hard to determine what the device is from that perspective.&amp;nbsp; We are looking at different ways to find more attributes.&amp;nbsp; The first one is NMAP and then SNMP. The customer has the Endpoint Attribute Filter enabled (EAF).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) With EAF enabled, does context visibility just show the Whitelist and mandatory attributes?&lt;/P&gt;
&lt;P&gt;2) Would there be any benefit to disabling EAF to see if there are other attributes available for unique profile creating?&lt;/P&gt;
&lt;P&gt;3) How much of a performance impact would there be by disabling the EAF?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) Would there be a mass update or would the updates occur just when the endpoint's PSN ownership changes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've watched several of Craig's BRKSEC 3699 but still have these questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Sam.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 17:27:55 GMT</pubDate>
    <dc:creator>scamarda</dc:creator>
    <dc:date>2018-10-23T17:27:55Z</dc:date>
    <item>
      <title>Endpoint Attribute Filter - Enabling for Additional Device Attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-attribute-filter-enabling-for-additional-device/m-p/3730918#M489162</link>
      <description>&lt;P&gt;A customer of mine has a deployment with approx 10k active devices.&amp;nbsp; Some of the medical devices with static IP addresses are not profiling beyond the ethernet vendor code.&amp;nbsp; Some of these devices share the same ethernet NIC vendor and it is hard to determine what the device is from that perspective.&amp;nbsp; We are looking at different ways to find more attributes.&amp;nbsp; The first one is NMAP and then SNMP. The customer has the Endpoint Attribute Filter enabled (EAF).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Questions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) With EAF enabled, does context visibility just show the Whitelist and mandatory attributes?&lt;/P&gt;
&lt;P&gt;2) Would there be any benefit to disabling EAF to see if there are other attributes available for unique profile creating?&lt;/P&gt;
&lt;P&gt;3) How much of a performance impact would there be by disabling the EAF?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) Would there be a mass update or would the updates occur just when the endpoint's PSN ownership changes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've watched several of Craig's BRKSEC 3699 but still have these questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Sam.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 17:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-attribute-filter-enabling-for-additional-device/m-p/3730918#M489162</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2018-10-23T17:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Attribute Filter - Enabling for Additional Device Attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/endpoint-attribute-filter-enabling-for-additional-device/m-p/3731180#M489181</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;1) With EAF enabled, does context visibility just show the Whitelist and mandatory attributes?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No, there are some attributes for context visibility only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2) Would there be any benefit to disabling EAF to see if there are other attributes available for unique profile creating?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Unless we are certain they are being filtered out as a result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;3) How much of a performance impact would there be by disabling the EAF?&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Huge. The very reason why we have EAF&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;4) Would there be a mass update or would the updates occur just when the endpoint's PSN ownership changes?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Potentially a mass update. I do not think it related to ownership changes.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 02:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/endpoint-attribute-filter-enabling-for-additional-device/m-p/3731180#M489181</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-24T02:50:11Z</dc:date>
    </item>
  </channel>
</rss>

