<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.3, C3PL, and DHCP profiling in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527502#M520421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am starting a deployment using the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Cisco ISE 2.3 with Patch 1 (updated patch)&lt;/LI&gt;&lt;LI&gt;Cisco 3850 with 03.07.05E&lt;UL&gt;&lt;LI&gt;C3PL is enabled&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Device sensors are being used on the switch for profiling. Only HTTP, RADIUS, and Active Directory profiling is enabled on the PSNs. The device sensor configuration is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;ip dhcp snooping&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;ip dhcp snooping vlan [comma-separated list of VLANs]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list dhcp list dhcp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name host-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name requested-address&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name parameter-request-list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name class-identifier&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name client-identifier&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec dhcp include list dhcp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cdp run&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list cdp list cdp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name device-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name address-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name capabilities-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name platform-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec cdp include list cdp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;lldp run&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list lldp list lldp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-description&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-capabilities&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec lldp include list lldp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor notify all-changes&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-session attributes filter-list list sensor_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cdp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;lldp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;dhcp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-session accounting attributes filter-spec include list sensor_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When I do a &lt;STRONG&gt;show device-sensor cache interface gi1/0/3&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;(Macbook Pro w/ OSX Sierra connected), I get the following details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;SPAN class="s1"&gt;&lt;EM&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;12:host-name &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;11 0C 09 42 72 61 64 73 2D 4D 42 50&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;50:requested-address&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;6 32 04 0A 4A 6C 3A&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;61:client-identifier&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;9 3D 07 01 98 5A EB CD B8 B5&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;55:parameter-request-list&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;12 37 0A 01 79 03 06 0F 77 FC 5F 2C 2E&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;In the ISE Context Visibility &amp;gt; Endpoints list, the laptop only shows up as Apple-Device based on the MAC OU. Nothing is hitting on the Workstation profile list. I suspect it is because IP:User-Agent isn't being processed. The same issue happens with a Windows 7 laptop. It is only seen as a Microsoft-Device and never a Windows workstation (or the specific Windows version). When I click on the details of the endpoint in Context Visibility, I do see &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;STRONG&gt;dhcp-parameter-request-list&lt;/STRONG&gt; and &lt;STRONG&gt;dhcp-requested-address&lt;/STRONG&gt; in the list of attributes received along with the endpoint source being RADIUS Probe.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;This is not an issue with CDP profiling. The test IP phone, a Cisco 7961, is profiled correctly almost immediately.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;Am I missing something in the device sensor configuration? I have used a similar (not exactly the same) device sensor config in other deployments but they were not using the new style authentication without C3PL enabled. One of the old styles was using the command &lt;STRONG&gt;no macro auto monitor&lt;/STRONG&gt; to disable the local device analyzer but I didn't find a similar command for the new style configuration. Not sure if that can cause an issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Oct 2017 14:03:22 GMT</pubDate>
    <dc:creator>Joseph Johnson</dc:creator>
    <dc:date>2017-10-26T14:03:22Z</dc:date>
    <item>
      <title>ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527502#M520421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am starting a deployment using the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Cisco ISE 2.3 with Patch 1 (updated patch)&lt;/LI&gt;&lt;LI&gt;Cisco 3850 with 03.07.05E&lt;UL&gt;&lt;LI&gt;C3PL is enabled&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Device sensors are being used on the switch for profiling. Only HTTP, RADIUS, and Active Directory profiling is enabled on the PSNs. The device sensor configuration is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;ip dhcp snooping&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;ip dhcp snooping vlan [comma-separated list of VLANs]&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list dhcp list dhcp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name host-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name requested-address&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name parameter-request-list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name class-identifier&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;option name client-identifier&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec dhcp include list dhcp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cdp run&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list cdp list cdp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name device-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name address-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name capabilities-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name platform-type&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec cdp include list cdp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;lldp run&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-list lldp list lldp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-name&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-description&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;tlv name system-capabilities&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor filter-spec lldp include list lldp_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;device-sensor notify all-changes&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-session attributes filter-list list sensor_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;cdp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;lldp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;dhcp&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;access-session accounting attributes filter-spec include list sensor_list&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When I do a &lt;STRONG&gt;show device-sensor cache interface gi1/0/3&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;(Macbook Pro w/ OSX Sierra connected), I get the following details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;SPAN class="s1"&gt;&lt;EM&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;12:host-name &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;11 0C 09 42 72 61 64 73 2D 4D 42 50&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;50:requested-address&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;6 32 04 0A 4A 6C 3A&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;61:client-identifier&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;9 3D 07 01 98 5A EB CD B8 B5&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1" style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;DHCP&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;55:parameter-request-list&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;12 37 0A 01 79 03 06 0F 77 FC 5F 2C 2E&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;In the ISE Context Visibility &amp;gt; Endpoints list, the laptop only shows up as Apple-Device based on the MAC OU. Nothing is hitting on the Workstation profile list. I suspect it is because IP:User-Agent isn't being processed. The same issue happens with a Windows 7 laptop. It is only seen as a Microsoft-Device and never a Windows workstation (or the specific Windows version). When I click on the details of the endpoint in Context Visibility, I do see &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;STRONG&gt;dhcp-parameter-request-list&lt;/STRONG&gt; and &lt;STRONG&gt;dhcp-requested-address&lt;/STRONG&gt; in the list of attributes received along with the endpoint source being RADIUS Probe.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;This is not an issue with CDP profiling. The test IP phone, a Cisco 7961, is profiled correctly almost immediately.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;Am I missing something in the device sensor configuration? I have used a similar (not exactly the same) device sensor config in other deployments but they were not using the new style authentication without C3PL enabled. One of the old styles was using the command &lt;STRONG&gt;no macro auto monitor&lt;/STRONG&gt; to disable the local device analyzer but I didn't find a similar command for the new style configuration. Not sure if that can cause an issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN class="s1"&gt;&lt;SPAN class="Apple-converted-space"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 14:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527502#M520421</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-26T14:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527503#M520424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just double checked the device sensor cache. For the port the IP phone is connected to, the cache is showing DHCP class identifier information (DHCP option 60). The port where the Macbook is connected is not showing DHCP class identifier information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 17:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527503#M520424</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-26T17:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527504#M520426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not all Macbooks will populate Class ID and there is no default condition for Mac OS profile to match on DHCP options or Class ID.&amp;nbsp; For Windows, you should see Class ID = MSFT and that would match the Windows-Workstation profile.&amp;nbsp; If not seeing that, then requires further investigation.&amp;nbsp; A screenshot of endpoint attributes for Windows WS would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 18:27:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527504#M520426</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-26T18:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527505#M520430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Mac OS profile includes IP:User-Agent. That info is found in the class identifier. Not sure why it's not showing up in this one, though. I've used the same laptop in other deployments and it profiled properly. I could test doing DHCP profiling but I doubt it will work since option 60 doesn't appear to be populating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll test another Windows laptop ASAP and post the result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 00:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527505#M520430</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-27T00:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527506#M520432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is not correct.&amp;nbsp; The user agent is extracted from HTTP data and we currently do not retrieve HTTP data for Wired connections via Device Sensor today--only wireless.&amp;nbsp; User Agent is very different than DHCP Class ID.&amp;nbsp; If think there is a difference in attributes, you can quickly tell difference by enabling DHCP probe on the PSN and adding an ip helper-address to the local gateway of the client which points to that same PSN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 01:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527506#M520432</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-27T01:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527507#M520435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I am confused on the way Mac OSX is profiled. I know I've profiled OSX machines in the past with just DHCP because they didn't go through any portal (guest, URL redirect, etc.) so HTTP wasn't utilized. I'll check into it further. I may just have to create a custom profile using the OUI and DHCP parameter request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527507#M520435</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-27T15:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527508#M520438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you’re using network device sensor then you were likely to get http probes as well with that and better increase your profile accuracy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-71879&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527508#M520438</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-10-27T15:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527509#M520441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joseph,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information we typically get to help profile Macs are OUI, User-agent and operating system.&amp;nbsp; If we just get the OUI, it will fall into the "Apple-Device" policy which will then kick off an OS NMAP scan of the endpoint where we learn the operating system.&amp;nbsp; That is for wired networks of course.&amp;nbsp; If wireless, WLCs with HTTP profiling enabled on the SSID will send the User-agent string and can profile it with only that information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527509#M520441</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-10-27T15:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527510#M520443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wonder if there is any HTTP info coming from the way OSX checks for a captive portal on networks. I could enable the HTTP sensor and grab that if it exist. I'll test that out. I appreciate all the responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: They don't want to enable NMAP on the limited number of PSNs they have so that probe is out at the moment. Would be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527510#M520443</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-27T15:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527511#M520445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you doing posturing at all? If you're doing CPP, I would assume ISE could get the user-agent from that as well (Tim and co will correct me if I'm wrong) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527511#M520445</guid>
      <dc:creator>katmcnam</dc:creator>
      <dc:date>2017-10-27T15:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527512#M520448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Points of clarification:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;We do not use posture data for profiling today &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Counter to popular belief, HTTP probe does NOT need to be enabled to capture user agent data.&amp;nbsp; We auto capture user agent when client connects to ISE portal&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;DHCP PRL May contribute but may not see Class ID populated&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;HTTP in Device Sensor is only supported on wireless today unlesss there was some more recent IOS-XE or Polaris code release that changed that for wired clients on current switch platforms.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Again, actual endpoint details will reveal what is being captured and if opportunity to expand on profile based on available data, or detection of missing probe opportunities.&amp;nbsp; For example, AD probe is one of the best and simplest options for gathering detail Windows classification. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Craig&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 16:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527512#M520448</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-27T16:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527513#M520452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh I meant profiling when the endpoint hits the CPP since that's technically an ISE portal when they initially connect&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 16:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527513#M520452</guid>
      <dc:creator>katmcnam</dc:creator>
      <dc:date>2017-10-27T16:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527514#M520454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, any web interaction with ISE including Hotspot, CWA, BYOD, MDM, Posture, Client Provisioning, Sponsor/MyDevices Portal should capture user agent automatically.&amp;nbsp; The enablement of HTTP probe is typically used only for SPAN or local promiscuous capture of HTTP traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 16:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527514#M520454</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-27T16:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527515#M520456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to clarify my previous response regarding ability to leverage posture in ISE profiling. (Thanks Hsing for calling out potential confusion).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AC and NAC Agent do have a web-enabled application and their user agents are also captured by ISE when they hit an ISE portal. There was a specific defect where this was not working in some releases and addressed by &lt;SPAN style="font-size: large;"&gt;&lt;STRONG&gt;&lt;A href="https://cdetsng.cisco.com/webui/#view=CSCuz59037"&gt;CSCuz59037&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;A href="http://wwwin.cisco.com/ops/infra/pds/cbms/cdets/legend.shtml" target="_blank" title="Help"&gt;&lt;SPAN style="font-size: 8pt;"&gt;.&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, it is possible to indirectly capture user agent from endpoint via posture agent.&amp;nbsp; The point I was calling out is that we do not currently extract detailed posture info learned from Posture (or MDM) process for the purpose of profiling.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that clarifies.&amp;nbsp;&amp;nbsp; /Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2017 18:00:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527515#M520456</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-27T18:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3, C3PL, and DHCP profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527516#M520459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, there is no posture planned at this phase of the customer's deployment. That would make it a lot easier to profile for sure. Profiling for workstations is only for visibility and no authorization rules. Profiling for IP phones, printers, APs, etc. is going to be used for authorization but that is working so far with the device sensors.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Oct 2017 15:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-c3pl-and-dhcp-profiling/m-p/3527516#M520459</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2017-10-28T15:53:48Z</dc:date>
    </item>
  </channel>
</rss>

