<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anyone using NMAP custom ports in profiling condition? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522458#M529760</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ISE 2.1 Patch 3 I've created an NMAP scan to include customer ports (tcp 8000, 4767 and 8194) and the NMAP Extensions dictionary is updated, but the attribute names do not appear in the profiling conditions pull-down, so i cannot create the condition.&lt;/P&gt;&lt;P&gt;Also, what would the value be?&lt;/P&gt;&lt;P&gt;For a scan on tcp 8194, the endpoint has an attribute "8194-tcp" with value "sophos", but i cannot enter "8194-tcp" as a profiling condition attribute.&lt;/P&gt;&lt;P&gt;I'm aware of CSCvb31331 but we do not see the same symptoms.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 May 2017 16:00:21 GMT</pubDate>
    <dc:creator>grant.maynard</dc:creator>
    <dc:date>2017-05-10T16:00:21Z</dc:date>
    <item>
      <title>Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522458#M529760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ISE 2.1 Patch 3 I've created an NMAP scan to include customer ports (tcp 8000, 4767 and 8194) and the NMAP Extensions dictionary is updated, but the attribute names do not appear in the profiling conditions pull-down, so i cannot create the condition.&lt;/P&gt;&lt;P&gt;Also, what would the value be?&lt;/P&gt;&lt;P&gt;For a scan on tcp 8194, the endpoint has an attribute "8194-tcp" with value "sophos", but i cannot enter "8194-tcp" as a profiling condition attribute.&lt;/P&gt;&lt;P&gt;I'm aware of CSCvb31331 but we do not see the same symptoms.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 16:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522458#M529760</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2017-05-10T16:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522459#M529761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure you are selecting NMAPExtension...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="107118" alt="" class="image-1 jive-image" height="237" src="https://community.cisco.com/legacyfs/online/fusion/107118_pastedImage_0.png" style="max-width: 1200px; max-height: 900px; width: 461px; height: 237.438px;" width="461" /&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 18:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522459#M529761</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-10T18:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522460#M529762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig. Yes, we are using NMAPExtension. I can see it's ok in your screenshot - what version is that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying 2.1 Patch 3.&lt;/P&gt;&lt;P&gt;I tried 2.1 Patch 2 on a lab setup and it worked.&lt;/P&gt;&lt;P&gt;I applied Patch 3 to this and it didn't work.&lt;/P&gt;&lt;P&gt;So I rolled back to Patch 2 and it worked again.&lt;/P&gt;&lt;P&gt;It must be a problem with Patch 3.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 May 2017 21:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522460#M529762</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2017-05-10T21:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522461#M529763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried it on my ISE 2.1 Patch 3 and it worked fine, with the steps described in the bug you cited. Mine is fresh install 2.1 and has Patch 3 only.&lt;/P&gt;&lt;P&gt;What is the history of your ISE in term of install, upgrade, and patching?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 01:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522461#M529763</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-11T01:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522462#M529764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE 2.1 Patch 1 is what I used and it worked fine.&amp;nbsp; Try removing the conditions referencing custom ports and then remove the nmap scan template.&amp;nbsp; You should see changes to the Profile Dictionary as you make changes.&amp;nbsp; When re-add the custom ports, you should see dictionary attributes appear.&amp;nbsp; This should then make them visible to profiler conditions as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 01:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522462#M529764</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-11T01:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522463#M529766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;There are five nodes - 2 Admin/Mon and 3 PSN-only.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;Originally, for all nodes, we installed 2.1, then patch 1, and patch 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;Then, due to a disk space problem on M nodes, we rebuilt both &lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;Admin/Mon as 2.1 then&lt;/SPAN&gt; went straight to patch 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;Then all nodes had patch 3 applied.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 22:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522463#M529766</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2017-05-11T22:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522464#M529772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We tried this today but there are a few oddities: we could not delete one profile condition based on a custom port, because it said it was referenced somewhere, but we could not find where.&lt;/P&gt;&lt;P&gt;We tried to delete the profile policy which had referenced this condition but got an error that a resource or child policy was using the associated identity group. Again, we could not find where.&lt;/P&gt;&lt;P&gt;We're going to reboot all nodes in a few days to see if this clears it.&lt;/P&gt;&lt;P&gt;if we removed Profiling Services from all PSN, would that cleanly remove the profiling config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 22:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522464#M529772</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2017-05-11T22:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522465#M529778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Removing profiling services would not help as PPAN has the master copy of the profiling policies and elements. If you really need them removed, then please engage Cisco TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 May 2017 22:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522465#M529778</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-11T22:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using NMAP custom ports in profiling condition?</title>
      <link>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522466#M529786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my testing it worked in Patch 2 but then didn't work when Patch 3 was applied, but I rolled back to 2 then re-applied 3 and it did work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We raised a TAC case which lead to bug ID CSCve51076. Hopefully it will be fixed in ISE 2.1 patch 4.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 08:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyone-using-nmap-custom-ports-in-profiling-condition/m-p/3522466#M529786</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2017-05-29T08:55:29Z</dc:date>
    </item>
  </channel>
</rss>

