<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anomalous Behaviour not alerting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420378#M535831</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a follow up, we closed on this offline by describing options to set DHCP options in Linux.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 May 2017 20:23:29 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-05-16T20:23:29Z</dc:date>
    <item>
      <title>Anomalous Behaviour not alerting</title>
      <link>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420375#M535828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to work in my lab with the anomalies detection capability.&lt;/P&gt;&lt;P&gt;I have followed the guide from TAC on it (&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200973-Configure-Anomalous-Endpoint-Detection-a.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200973-Configure-Anomalous-Endpoint-Detection-a.html"&gt;Configure Anomalous Endpoint Detection and Enforcement on ISE 2.2 - Cisco&lt;/A&gt;) but it does not seem to be working as it should.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled only visibility and not enforcement.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have 2 clients, one Windows and one Linux. They both are profiled fine. Then I turn off the Windows machine, and make sure the session is ended. I spoof on the Linux machine the MAC of the Windows and I connected it to the network again.&lt;/LI&gt;&lt;LI&gt;I see the profile changing from Windows ti Linux, but no anomalous behavior is set.&lt;/LI&gt;&lt;LI&gt;I look at the debug, but I have no entry for anomalous behavior as per the guide.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The only entry I have on the ISE GUI (and on the log file), is the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4= DEVICE.Device Type, 5=Dot1x, 72=All_User_ID_Stores, 73=Internal Users, 76=All_AD_Join_Points, 77=All_AD_Join_Points, 78=TRUSTSEC\\employee1, 79=trustsec.local, 80=trustsec.local, 82=employee1@trustsec.local, 83=All_AD_Join_Points, 100=ad, 101=CLIENT-WIN7-HQ$@trustsec.local, 102=trustsec.local, 103=trustsec.local, 104=trustsec.local, 106=ad, 110= Session.EPSStatus, 111= EndPoints.AnomalousBehaviour, 112= EndPoints.EndPointPolicy, 113= CERTIFICATE.Subject - Common Name, 114=ad, 115=trustsec.local, 116=ad, 117=trustsec.local, 118=ad, 119=ad, 120= ad.ExternalGroups, 121= PassiveID.PassiveID_Groups, 122= Radius.Calling-Station-ID, 123= Normalised Radius.RadiusFlowType, 124=Employees&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should I do to have it working? Am I doing anything wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 May 2017 13:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420375#M535828</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2017-05-16T13:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Anomalous Behaviour not alerting</title>
      <link>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420376#M535829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For both the Windows and Linux endpoints, the DHCP class-identifier must reach ISE. What value do you see in both the cases (in Endpoint Context Visibility) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 May 2017 15:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420376#M535829</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2017-05-16T15:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Anomalous Behaviour not alerting</title>
      <link>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420377#M535830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hari,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turns out Ubuntu does not send the class-identifier, so that is stuck in Microsoft&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 May 2017 16:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420377#M535830</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2017-05-16T16:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Anomalous Behaviour not alerting</title>
      <link>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420378#M535831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a follow up, we closed on this offline by describing options to set DHCP options in Linux.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 May 2017 20:23:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anomalous-behaviour-not-alerting/m-p/3420378#M535831</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-16T20:23:29Z</dc:date>
    </item>
  </channel>
</rss>

