<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE profiling on wired using radius probe and accounting(no authentication) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516956#M529156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I have been struggling with problem since a couple of weeks now and seems that I need some help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I would be grateful if some could give me some hints or ideas regarding this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;The situation is the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;We are planning to roll out wired 8021x in our organization using ISE and the switches are mostly 3850, 3750 and 3560.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Now because there are more than 30k switch ports I’m trying to do the simplest configuration for a start.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;We would like to start with just profiling the devices for a couple of months maybe even a year.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I was thinking to use device sensor and radius probe to achieve this. Data will be sent using accounting to ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;The important thing is that authentication and authorization will not be configured for now! So the switch port configuration will not be touched, nothing new will be added here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I am following Craig Hyps trustsec guide regarding profiling(and other official documentation), and based on them this type of configuration is a valid one. It just needs a couple of global commands on the switches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Now the problem that I am facing is that it’s not working on any of the switch models for now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Device senor cache is populated on all switch types, but&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;on the 3850 and 3560 the accounting is not sent no matter what I do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;On the 3750 the accounting is sent and contains sensor data but no calling station ID, so ISE cannot create and endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;(of course if I configure authentication and accounting and use the standard switch port configuration for 8021x this works, but as I said this is not what we want for now)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I am working with TAC but no notable result for now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;At this point I beginning to lose my hope that this is even doable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Did someone ever manage to do this king of configuration that also worked? Can you let me know the exact IOS version and maybe an example of the configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Any ideas are welcome.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;laszlo&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Jun 2017 05:18:26 GMT</pubDate>
    <dc:creator>laposilaszlo</dc:creator>
    <dc:date>2017-06-09T05:18:26Z</dc:date>
    <item>
      <title>ISE profiling on wired using radius probe and accounting(no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516956#M529156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I have been struggling with problem since a couple of weeks now and seems that I need some help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I would be grateful if some could give me some hints or ideas regarding this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;The situation is the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;We are planning to roll out wired 8021x in our organization using ISE and the switches are mostly 3850, 3750 and 3560.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Now because there are more than 30k switch ports I’m trying to do the simplest configuration for a start.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;We would like to start with just profiling the devices for a couple of months maybe even a year.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I was thinking to use device sensor and radius probe to achieve this. Data will be sent using accounting to ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;The important thing is that authentication and authorization will not be configured for now! So the switch port configuration will not be touched, nothing new will be added here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I am following Craig Hyps trustsec guide regarding profiling(and other official documentation), and based on them this type of configuration is a valid one. It just needs a couple of global commands on the switches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Now the problem that I am facing is that it’s not working on any of the switch models for now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Device senor cache is populated on all switch types, but&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;on the 3850 and 3560 the accounting is not sent no matter what I do.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;On the 3750 the accounting is sent and contains sensor data but no calling station ID, so ISE cannot create and endpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;(of course if I configure authentication and accounting and use the standard switch port configuration for 8021x this works, but as I said this is not what we want for now)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I am working with TAC but no notable result for now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;At this point I beginning to lose my hope that this is even doable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Did someone ever manage to do this king of configuration that also worked? Can you let me know the exact IOS version and maybe an example of the configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Any ideas are welcome.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;laszlo&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 05:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516956#M529156</guid>
      <dc:creator>laposilaszlo</dc:creator>
      <dc:date>2017-06-09T05:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling on wired using radius probe and accounting(no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516957#M529158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IOS Device Sensor requires RADIUS to work.&amp;nbsp; If you're not doing any AAA, you won't get any information from Device Sensor.&amp;nbsp; You may want to look at other profiling methods such as DHCP probe (using IP helpers) or SNMP query while you are in monitor mode for the deployment.&amp;nbsp; You could also try NMAP as well as the AD probe but be sure ISE is getting the hostname of the endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 14:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516957#M529158</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-06-09T14:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling on wired using radius probe and accounting(no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516958#M529160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct, that is what I was thinking also.&lt;/P&gt;&lt;P&gt;Accounting usually happens after authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But then there is this part in the TrustSec document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;Note:&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;RADIUS accounting is required to forward sensor data to ISE. However, RADIUS authentication and authorization are not required to collect and send sensor data to ISE. Therefore, it is possible to use the Device Sensor for pre-ISE deployments during a network discovery phase when an organization is not yet ready to enable RADIUS authentication, even if only Monitor Mode. This support extends to deployments using ISE Profiling Services with Cisco NAC Appliance where RADIUS access control is not deployed.&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;Page 78&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf" title="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_30_ise_profiling.pdf&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;And I have talked to Craig Hyps and he confirmed that this should work.&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;So its confusing. I'm am still not sure if this is possible or not.&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;Thanks,&lt;/P&gt;&lt;P style="font-size: 13.4px; font-family: sans-serif;"&gt;laszlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jun 2017 05:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516958#M529160</guid>
      <dc:creator>laposilaszlo</dc:creator>
      <dc:date>2017-06-12T05:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling on wired using radius probe and accounting(no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516959#M529164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case, you would need to find a way to send RADIUS accounting because it holds the profiling data as you are aware.&amp;nbsp; At the same time, a monitor mode deployment where no enforcement is taking place could be another option.&amp;nbsp; Check out the below doc for more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-68150"&gt;How-To: Monitor Mode Deployment with ISE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jun 2017 13:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-on-wired-using-radius-probe-and-accounting-no/m-p/3516959#M529164</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-06-12T13:57:11Z</dc:date>
    </item>
  </channel>
</rss>

