<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Profiler Configuration: SNMPv3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485532#M496257</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I did not elaborate enough...... this is for Static assigned IP printers, that ISE uses NMAP, to gather SNMP info from...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;go to Administration&amp;gt;System&amp;gt;Settings&amp;gt;Profiling&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; font-family: Tahoma; font-size: 14px; font-weight: bold;"&gt;Profiler Configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE class="cpmLocalTableSpacing" style="font-size: 12px; color: #000000; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-family: Arial;"&gt;&lt;P class="dijit dijitReadOnly xwtValidationTextBox xwtValidationTextBoxReadOnly dijitInlineTable dijitTextBox dijitLeft dijitTextBoxReadOnly dijitReset" style="margin: 0 5px 0 0; padding: 2px 5px; font-style: inherit; font-weight: bold; font-family: Tahoma, sans-serif; color: #222222; background-position: inherit;"&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD align="right" nowrap="nowrap" style="font-family: Arial;"&gt;&lt;LABEL style="margin-bottom: 5px; color: #222222;"&gt;Current custom SNMP community strings:&lt;/LABEL&gt;&lt;/TD&gt;&lt;TD style="font-family: Arial;"&gt;&lt;P class="dijit dijitReadOnly xwtValidationTextBox xwtValidationTextBoxReadOnly dijitInlineTable dijitTextBox dijitLeft dijitTextBoxReadOnly dijitReset" style="margin: 0 5px 0 0; padding: 2px 5px; font-style: inherit; font-weight: bold; font-family: Tahoma, sans-serif; color: #222222; background-position: inherit;"&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="dijitReset dijitValidationIcon" style="background-position: initial;"&gt;&amp;lt;v2c sting&amp;gt;&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;thanks for any info......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jul 2018 21:28:03 GMT</pubDate>
    <dc:creator>Kevin S Hatch</dc:creator>
    <dc:date>2018-07-11T21:28:03Z</dc:date>
    <item>
      <title>ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485530#M496255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When will the Profiler configuration in ISE be able to use SNMPv3.&amp;nbsp; I work in the financial/banking industry and our security department is telling that we can't use SNMPv1 or v2c.&amp;nbsp; Is there a work around that will work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:khatch@open-techs.com"&gt;khatch@open-techs.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485530#M496255</guid>
      <dc:creator>Kevin S Hatch</dc:creator>
      <dc:date>2018-07-11T16:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485531#M496256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We support SNMPv3. Please see: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0100011.html#reference_4D603ADC9DCF45F88982448A99D8EA89" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0100011.html#reference_4D603ADC9DCF45F88982448A99D8EA89"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_010…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 19:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485531#M496256</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-07-11T19:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485532#M496257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I did not elaborate enough...... this is for Static assigned IP printers, that ISE uses NMAP, to gather SNMP info from...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;go to Administration&amp;gt;System&amp;gt;Settings&amp;gt;Profiling&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #545454; font-family: Tahoma; font-size: 14px; font-weight: bold;"&gt;Profiler Configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE class="cpmLocalTableSpacing" style="font-size: 12px; color: #000000; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-family: Arial;"&gt;&lt;P class="dijit dijitReadOnly xwtValidationTextBox xwtValidationTextBoxReadOnly dijitInlineTable dijitTextBox dijitLeft dijitTextBoxReadOnly dijitReset" style="margin: 0 5px 0 0; padding: 2px 5px; font-style: inherit; font-weight: bold; font-family: Tahoma, sans-serif; color: #222222; background-position: inherit;"&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD align="right" nowrap="nowrap" style="font-family: Arial;"&gt;&lt;LABEL style="margin-bottom: 5px; color: #222222;"&gt;Current custom SNMP community strings:&lt;/LABEL&gt;&lt;/TD&gt;&lt;TD style="font-family: Arial;"&gt;&lt;P class="dijit dijitReadOnly xwtValidationTextBox xwtValidationTextBoxReadOnly dijitInlineTable dijitTextBox dijitLeft dijitTextBoxReadOnly dijitReset" style="margin: 0 5px 0 0; padding: 2px 5px; font-style: inherit; font-weight: bold; font-family: Tahoma, sans-serif; color: #222222; background-position: inherit;"&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="dijitReset dijitValidationIcon" style="background-position: initial;"&gt;&amp;lt;v2c sting&amp;gt;&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;thanks for any info......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485532#M496257</guid>
      <dc:creator>Kevin S Hatch</dc:creator>
      <dc:date>2018-07-11T21:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485533#M496258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not currently. Just curious about the SNMPv3 though. Are the printers enabled with v3 out of the box or is v3 enabled by the admins? Typically NMAP SNMP scan is to provide profiling attributes for endpoints configured with default SNMP string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In terms of the static IP on printers, are they manually configured through printer interface or are they setup as DHCP/BOOTP but the MAC is reserved on the DHCP server. If latter then you can still get it profiled via DHCP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 23:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485533#M496258</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-07-11T23:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485534#M496259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;V3 would have to be enabled on the printer (specifically HP printers, I don’t seem to have an issue with any other Printer/MFP manufacturer).  The “public”/ default  community string; sets of alerts at every security audit and we have been told that we cannot use it ever.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have been set as Static. I have asked them to extend the DHCP range and create DHCP reservation, but they are resistant to change.  (ie.. “we have done it this way for the last 20  years, so we don’t want to have to change the way we do everything.”)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use that custom string with a non “default”  v2c string, I have tested this and it does work.  But our security team keeps telling us to use only v3 with Auth and Priv options, only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could ISE be modified to use the v3 strings that are set for network devices to do the NMAP scan, as well?  Just an idea….&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 14:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485534#M496259</guid>
      <dc:creator>Kevin S Hatch</dc:creator>
      <dc:date>2018-07-12T14:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Profiler Configuration: SNMPv3</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485535#M496260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case I would configure 802.1X on the printers to authenticate instead of doing profiling + MAB (MAC Authentication Bypass). In general profiling is done for devices that cannot do 802.1X and admin prefer not to touch them. If you are already touching them to configure SNMPv3, I would suggest configuring 802.1X on the printers instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you still want us to consider SNMPv3 for the endpoints, please contact the product management team through your local Cisco contact or you can provide feedback through ISE GUI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 16:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-configuration-snmpv3/m-p/3485535#M496260</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-07-12T16:59:06Z</dc:date>
    </item>
  </channel>
</rss>

