<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 and Active Directory Probe in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731887#M507051</link>
    <description>&lt;P&gt;Our ISE 2.3 installed patch 2,3 I was planning on installing patch 4 and patch 5. Will that address the bug problem?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2018 17:05:30 GMT</pubDate>
    <dc:creator>creserva1</dc:creator>
    <dc:date>2018-10-24T17:05:30Z</dc:date>
    <item>
      <title>ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3722198#M507033</link>
      <description>&lt;P&gt;I think this bug is hitting our ISE and we are not able to use AD-Join-Host-Point as one of authentication for host.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf55996" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf55996&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 21:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3722198#M507033</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-09T21:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3729173#M507036</link>
      <description>&lt;P&gt;This is a mis-interpretation.&lt;/P&gt;
&lt;P&gt;AD-Join-Point (without "-Host-") is the one collected by ISE profiler's AD probe. And, AD-Host-Join-Point (with "-Host-") is collected by ISE profiler's RADIUS probe. As a result, it's not currently available in the dictionary ACTIVEDIRECTORY_PROBE.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Oct 2018 19:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3729173#M507036</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-20T19:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731650#M507040</link>
      <description>&lt;P&gt;With that being said I can't use it as a profiler condition?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 324px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/21115i04883211B62537AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 13:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731650#M507040</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-24T13:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731787#M507043</link>
      <description>&lt;BLOCKQUOTE&gt;With that being said I can't use it as a profiler condition?
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Your picture shows AD-Join-Point used as a condition for a profiler check. It would be a bug if that is not working to make a match. As said previously, the other attribute, despite with the same value most of the time, is not available for such.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 15:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731787#M507043</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-24T15:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731862#M507046</link>
      <description>&lt;P&gt;Checking&amp;nbsp;EndPointSource Active Directory Probe, other attributes is&amp;nbsp;&lt;SPAN&gt;AD-Host-Join-Point but on profiler condition is AD-Join-Point. The AD-Join-Point is not showing on Endpoint other attributes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If AD-Host-Join-Point used by ISE Radius probe, how can I make ISE to perform EndPointSource Radius Probe instead of Active Directory Probe? Turning off AD probe will that make it Radius probe to take place?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 16:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731862#M507046</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-24T16:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731877#M507049</link>
      <description>&lt;P&gt;No, it won't work like that. It's likely you are hitting some other bug, such as CSCve03360&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 16:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731877#M507049</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-24T16:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731887#M507051</link>
      <description>&lt;P&gt;Our ISE 2.3 installed patch 2,3 I was planning on installing patch 4 and patch 5. Will that address the bug problem?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 17:05:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731887#M507051</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-24T17:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731924#M507052</link>
      <description>&lt;P&gt;When you patch ISE, you don't need to install every patch released. The most recent patch incorporates all the previous patch fixes. &lt;BR /&gt;ex. You can apply just patch 5 on your ISE deployment and it will include all patch 1-4 items too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just commentary on patching. I don't know if your issue is fixed in patch X.&amp;nbsp; When I am unsure if an issue is fixed in patch X, I work with TAC, I would suggest you do the same here.&amp;nbsp; It can be very difficult to troubleshoot/identify fridge issues via forum posts.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 18:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3731924#M507052</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-10-24T18:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732178#M507055</link>
      <description>&lt;P&gt;I concurred with Damien's comment.&lt;/P&gt;
&lt;P&gt;CSCve03360 is due to ISE 2.2+ using AD probe to fetch both computer info and user info and two types of fetches using the same AD-Last-Fetch-Time such that computer info fetch not occurring if user info fetched within the last 24 hour or the configured interval. The bug is addressed in ISE 2.4 FCS. CSCvm72309 observed in ISE 2.4 Patch 1+.&lt;/P&gt;
&lt;P&gt;Your deployment might need both bug fixes and TAC may help analyzing that.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 23:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732178#M507055</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-24T23:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732874#M507056</link>
      <description>&lt;P&gt;I turned on debug on ISE for profiler and I found out that the initial authentication method is MAB, then Radius Probe and then last Active Directory Probe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I shutdown the interface first, deleted the endpoint on the ISE, rebooted the pc and do no shutdown on interface. For the first time when ISE sees the MAC address it will be unknown but the first sequence is MAB, then Radius Probe and then Active Directory probe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE of course after I deleted the endpoint it has no longer the mac address in its database. How can I configure the ISE to perform Radius Probe or AD Probe only?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 15:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732874#M507056</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-25T15:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732888#M507057</link>
      <description>&lt;P&gt;Radius Probe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attribute:AAA-Server value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AD-Error-Details value:Domain trust is one-way&lt;BR /&gt; Attribute:AD-Groups-Names value:&amp;lt;omitted&amp;gt;/Builtin/Domain Computers&lt;BR /&gt; Attribute:AD-Host-Candidate-Identities value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AD-Host-DNS-Domain value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AD-Host-Join-Point value:EXAMPLE.ORG&lt;BR /&gt; Attribute:AD-Host-NetBios-Name value:EXAMPLE&lt;BR /&gt; Attribute:AD-Host-Resolved-DNs value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AD-Host-Resolved-Identities&amp;nbsp;&lt;SPAN&gt;&amp;lt;omitted&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt; Attribute:AD-Last-Fetch-Time value:1540480415942&lt;BR /&gt; Attribute:AKI value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AuthenticationIdentityStore value:EXAMPLE&lt;BR /&gt; Attribute:AuthenticationMethod value:x509_PKI&lt;BR /&gt; Attribute:AuthenticationStatus value:AuthenticationPassed&lt;BR /&gt; Attribute:AuthorizationPolicyMatchedRule value:AD OU Computers Root CA&lt;BR /&gt; Attribute:BYODRegistration value:Unknown&lt;BR /&gt; Attribute:CacheUpdateTime value:1540480415962&lt;BR /&gt; Attribute:Called-Station-ID value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:Calling-Station-ID value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:CreateTime value:1540480406501&lt;BR /&gt; Attribute:DTLSSupport value:Unknown&lt;BR /&gt; Attribute:Days to Expiry value:3393&lt;BR /&gt; Attribute:DestinationIPAddress value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:DestinationPort value:1812&lt;BR /&gt; Attribute:Device IP Address value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:Device Identifier value:&lt;BR /&gt; Attribute:Device Port value:1645&lt;BR /&gt; Attribute:Device Type value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt; Attribute:EndPointMACAddress value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:EndPointPolicy value:Dell-Inc-Device&lt;BR /&gt; Attribute:EndPointPolicyID value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:EndPointProfilerServer value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:EndPointSource value:RADIUS Probe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Profiling Condition , selecting Radius as Type, searching for&amp;nbsp;AD-Host-Join-Point name is not available. I can't build these attributes and use it for matching endpoint that are part of Active Directory.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the AD Probe&lt;/P&gt;
&lt;P&gt;MAC: &amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:AD-Last-Fetch-Time value:1540480480951&lt;BR /&gt; Attribute:BYODRegistration value:Unknown&lt;BR /&gt; Attribute:DeviceRegistrationStatus value:NotRegistered&lt;BR /&gt; Attribute:EndPointProfilerServer value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:EndPointSource value:Active Directory Probe&lt;BR /&gt; Attribute:MACAddress value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:NmapSubnetScanID value:0&lt;BR /&gt; Attribute:OUI value:Dell Inc.&lt;BR /&gt; Attribute:PolicyVersion value:0&lt;BR /&gt; Attribute:PortalUser value:&lt;BR /&gt; Attribute:PostureApplicable value:Yes&lt;BR /&gt; Attribute:User-Fetch-CountryName value:&lt;BR /&gt; Attribute:User-Fetch-Department value:&lt;BR /&gt; Attribute:User-Fetch-Email value:&lt;BR /&gt; Attribute:User-Fetch-First-Name value:&lt;BR /&gt; Attribute:User-Fetch-Job-Title value:&lt;BR /&gt; Attribute:User-Fetch-Last-Name value:&lt;BR /&gt; Attribute:User-Fetch-LocalityName value:&lt;BR /&gt; Attribute:User-Fetch-Organizational-Unit value:&lt;BR /&gt; Attribute:User-Fetch-StateOrProvinceName value:&lt;BR /&gt; Attribute:User-Fetch-StreetAddress value:&lt;BR /&gt; Attribute:User-Fetch-Telephone value:&lt;BR /&gt; Attribute:User-Fetch-User-Name value:&amp;lt;omitted&amp;gt;&lt;BR /&gt; Attribute:SkipProfiling value:false&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The attribute for AD-Join-Point is not even showing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 16:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732888#M507057</guid>
      <dc:creator>creserva1</dc:creator>
      <dc:date>2018-10-25T16:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732923#M507058</link>
      <description>&lt;P&gt;Please check if this post could help you&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/ise-2-3-and-active-directory-probe/td-p/3351475" target="_blank"&gt;https://community.cisco.com/t5/policy-and-access/ise-2-3-and-active-directory-probe/td-p/3351475&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 16:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732923#M507058</guid>
      <dc:creator>ramkchel</dc:creator>
      <dc:date>2018-10-25T16:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 and Active Directory Probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732990#M507059</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Attribute:AD-Last-Fetch-Time value:1540480480951&lt;BR /&gt;
&lt;P&gt;...&lt;BR /&gt; Attribute:User-Fetch-CountryName value:&lt;BR /&gt; Attribute:User-Fetch-Department value:&lt;BR /&gt; Attribute:User-Fetch-Email value:&lt;BR /&gt; Attribute:User-Fetch-First-Name value:&lt;BR /&gt; Attribute:User-Fetch-Job-Title value:&lt;BR /&gt; Attribute:User-Fetch-Last-Name value:&lt;BR /&gt; Attribute:User-Fetch-LocalityName value:&lt;BR /&gt; Attribute:User-Fetch-Organizational-Unit value:&lt;BR /&gt; Attribute:User-Fetch-StateOrProvinceName value:&lt;BR /&gt; Attribute:User-Fetch-StreetAddress value:&lt;BR /&gt; Attribute:User-Fetch-Telephone value:&lt;BR /&gt; Attribute:User-Fetch-User-Name value:&amp;lt;omitted&amp;gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is pretty much &lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCve03360" target="_blank"&gt;CSCve03360&lt;/A&gt;. The User-Fetch-* attributes are fetched by the AD probe for the user visibility data and updated AD-Last-Fetch-Time so the AD probe won't fetch for the computer data for another 24 hours. I do not know any reliable workaround until getting the fix for the bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2018 18:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-and-active-directory-probe/m-p/3732990#M507059</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-25T18:12:54Z</dc:date>
    </item>
  </channel>
</rss>

