<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device-Sensor Profiling Doesn't Appear To Be Working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432625#M504483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps there is a command missing in the AP config.&amp;nbsp; Sorry I don't have experience with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would run a tcpdump on the ISE PSN node and look for your accounting requests from your Cisco AP.&amp;nbsp; If the AP is sending the Cisco AVPair then it should be visible in the tcpdump.&amp;nbsp; If not, then it's not an ISE issue.&amp;nbsp; I have included an example from a Cisco 5520 WLC below which has device sensor enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117312_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 May 2018 01:17:12 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2018-05-31T01:17:12Z</dc:date>
    <item>
      <title>Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432620#M504478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Devices are configured with device-sensor CDP, LLDP and RADIUS:&lt;/P&gt;&lt;P&gt;device-sensor filter-list cdp list manual-cdp-list&lt;/P&gt;&lt;P&gt; tlv name device-name&lt;/P&gt;&lt;P&gt; tlv name address-type&lt;/P&gt;&lt;P&gt; tlv name capabilities-type&lt;/P&gt;&lt;P&gt; tlv name platform-type&lt;/P&gt;&lt;P&gt;device-sensor filter-list lldp list manual-lldp-list&lt;/P&gt;&lt;P&gt; tlv name system-name&lt;/P&gt;&lt;P&gt; tlv name system-description&lt;/P&gt;&lt;P&gt;device-sensor filter-list dhcp list manual-dhcp-list&lt;/P&gt;&lt;P&gt; option name host-name&lt;/P&gt;&lt;P&gt; option name default-ip-ttl&lt;/P&gt;&lt;P&gt; option name requested-address&lt;/P&gt;&lt;P&gt; option name parameter-request-list&lt;/P&gt;&lt;P&gt; option name class-identifier&lt;/P&gt;&lt;P&gt; option name client-identifier&lt;/P&gt;&lt;P&gt;device-sensor filter-spec dhcp include list manual-dhcp-list&lt;/P&gt;&lt;P&gt;device-sensor filter-spec lldp include list manual-lldp-list&lt;/P&gt;&lt;P&gt;device-sensor filter-spec cdp include list manual-cdp-list&lt;/P&gt;&lt;P&gt;device-sensor accounting&lt;/P&gt;&lt;P&gt;device-sensor notify all-changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SNMP:&lt;/P&gt;&lt;P&gt;snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change added&lt;/P&gt;&lt;P&gt; snmp trap mac-notification change removed&lt;/P&gt;&lt;P&gt;snmp-server host 192.168.101.169 public &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see ISE receives the CDP LLDP info, but is not profiling the endpoint correctly (under context visibility endpoint details):&lt;/P&gt;&lt;P&gt;cdpCacheDeviceId&amp;nbsp;&amp;nbsp;&amp;nbsp; APCC16.7E98.7A2C&lt;/P&gt;&lt;P&gt;cdpCachePlatform&amp;nbsp;&amp;nbsp;&amp;nbsp; cisco AIR-AP3802I-B-K9&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cdpCacheVersion&amp;nbsp;&amp;nbsp;&amp;nbsp; Cisco AP Software, ap3g3-k9w8 Version: 8.5.110.0 Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" rel="nofollow" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;SPAN&gt; Copyright (c) 2014-2015 by Cisco Systems, Inc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but in the logs and main context visibility page it is classified as a Cisco-Switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 23:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432620#M504478</guid>
      <dc:creator>loverbey</dc:creator>
      <dc:date>2018-05-30T23:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432621#M504479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you send Radius Accounting to ISE PSN?&amp;nbsp; The Device Sensor data is contained inside the Radius Accounting Cisco AVPairs.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 23:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432621#M504479</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-05-30T23:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432622#M504480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Arne.&amp;nbsp; I do have this configured, but oddly it isn't showing up in the running-config.&amp;nbsp; I enabled debug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*May 30 23:57:34.464: RADIUS/DECODE(0000117F): There is no General DB. Reply server details may not be recorded&lt;/P&gt;&lt;P&gt;*May 30 23:57:34.464: RADIUS(0000117F): Unique id not in use&lt;/P&gt;&lt;P&gt;*May 30 23:57:34.464: RADIUS/DECODE(0000117F): There is no RADIUS DB Some Radius attributes may not be stored&lt;/P&gt;&lt;P&gt;*May 30 23:57:34.464: RADIUS(0000117F): Unique id not in use&lt;/P&gt;&lt;P&gt;*May 30 23:57:34.464: RADIUS/DECODE(0000117F): There is no RADIUS DB Some Radius attributes may not be stored&lt;/P&gt;&lt;P&gt;*May 30 23:57:35.871: RADIUS/ENCODE(00001180):Orig. component type = CTS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 00:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432622#M504480</guid>
      <dc:creator>loverbey</dc:creator>
      <dc:date>2018-05-31T00:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432623#M504481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your radius servers are not showing up in the running config then alarm bells should be ringing!&amp;nbsp; IOS can hide config defaults and that is normal, but your aaa config should always be visible.&amp;nbsp; Perhaps there is an additional command to include VSA' in the Radius accounting (I have a vague memory of this ... you have to tell IOS what all to include in the Accounting requests).&lt;/P&gt;&lt;P&gt;Can you share your relevant aaa IOS config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 00:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432623#M504481</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-05-31T00:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432624#M504482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are showing up and authen/authorization is working:&lt;/P&gt;&lt;P&gt;aaa group server radius dnac-client-radius-group&lt;/P&gt;&lt;P&gt; server name dnac-radius_192.168.101.179&lt;/P&gt;&lt;P&gt; ip radius source-interface Loopback0&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group dnac-client-radius-group&lt;/P&gt;&lt;P&gt;aaa authorization network default group dnac-client-radius-group &lt;/P&gt;&lt;P&gt;aaa authorization network dnac-cts-list group dnac-client-radius-group &lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group dnac-client-radius-group&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt; client 172.25.0.179 server-key notforyou2&lt;/P&gt;&lt;P&gt; client 192.168.101.179 server-key notforyou2&lt;/P&gt;&lt;P&gt; client 172.25.0.178 server-key notforyou2&lt;/P&gt;&lt;P&gt;ip radius source-interface Loopback0 &lt;/P&gt;&lt;P&gt;snmp-server enable traps trustsec-server radius-server provision-secret&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 6 support-multiple&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;&lt;P&gt;radius-server deadtime 30&lt;/P&gt;&lt;P&gt;radius server dnac-radius_192.168.101.179&lt;/P&gt;&lt;P&gt; address ipv4 192.168.101.179 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt; timeout 2&lt;/P&gt;&lt;P&gt; retransmit 1&lt;/P&gt;&lt;P&gt; pac key notforyou2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;METRO-A5#sh radius server-group all&lt;/P&gt;&lt;P&gt;Server group radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sharecount = 1&amp;nbsp; sg_unconfigured = FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type = standard&amp;nbsp; Memlocks = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server(192.168.101.179:1812,1813) Transactions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authen: 0&amp;nbsp;&amp;nbsp;&amp;nbsp; Author: 0&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server_auto_test_enabled: FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Keywrap enabled: FALSE&lt;/P&gt;&lt;P&gt;Server group dnac-client-radius-group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sharecount = 1&amp;nbsp; sg_unconfigured = FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type = standard&amp;nbsp; Memlocks = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server(192.168.101.179:1812,1813) Transactions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authen: 6228&amp;nbsp;&amp;nbsp;&amp;nbsp; Author: 61&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct: 44771&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server_auto_test_enabled: FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Keywrap enabled: FALSE&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 00:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432624#M504482</guid>
      <dc:creator>loverbey</dc:creator>
      <dc:date>2018-05-31T00:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432625#M504483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps there is a command missing in the AP config.&amp;nbsp; Sorry I don't have experience with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would run a tcpdump on the ISE PSN node and look for your accounting requests from your Cisco AP.&amp;nbsp; If the AP is sending the Cisco AVPair then it should be visible in the tcpdump.&amp;nbsp; If not, then it's not an ISE issue.&amp;nbsp; I have included an example from a Cisco 5520 WLC below which has device sensor enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117312_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 01:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432625#M504483</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-05-31T01:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432626#M504484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is a lab, please post the complete list of attributes for this endpoint. Or, you may unicast me the info and, if available, along with the profiler.log file (profiler in DEBUG).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am guessing other attributes, such as LLDP and NMAP, making it as Cisco-Switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 02:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432626#M504484</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-31T02:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Device-Sensor Profiling Doesn't Appear To Be Working</title>
      <link>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432627#M504485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After reviewing the complete list of attributes of the endpoints, it appears that the endpoint is not performing authentication so IOS device sensor is unlikely at work and, instead, the attributes are gathered by SNMP probe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've open CSCvj77125 to track the issue of CDP platform strings for the newer Cisco APs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Jun 2018 03:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-sensor-profiling-doesn-t-appear-to-be-working/m-p/3432627#M504485</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-02T03:20:48Z</dc:date>
    </item>
  </channel>
</rss>

