<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE AD probe in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570051#M536071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI. I have the probes configured but AD fetch is not triggered after receiving the fqdn from the dns. I see that the fqdn is successfuly learned via dns. I have a case w tac. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 26 Feb 2017 22:02:02 GMT</pubDate>
    <dc:creator>edondurguti</dc:creator>
    <dc:date>2017-02-26T22:02:02Z</dc:date>
    <item>
      <title>Cisco ISE AD probe</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570049#M536069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm trying to profile corporate assets without doing any kind of posturing.&lt;/P&gt;&lt;P&gt;Was excited about the Active Directory probe but I've hit some limitations. According to some documts the to trigger the active directory probe, ISE must get the host-name attribute, so far the only way to get the host-name attribute is via DHCP.&lt;/P&gt;&lt;P&gt;Looks simple if using WLC or dot1x for wireless/wired users.&lt;/P&gt;&lt;P&gt;Here's an example for wireless:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200553-Configure-ISE-2-1-Profiling-Services-bas.html" title="http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200553-Configure-ISE-2-1-Profiling-Services-bas.html"&gt;Configure ISE 2.1 Profiling Services Based on AD Probe - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My case is for VPN only, I've tried to configure DHCP on the ASA for anyconnect users but that didn't help, ASA proxies the DHCP request packets.&lt;/P&gt;&lt;P&gt;I was hoping DNS would provide the 'host-name' attribute but looks like DNS provides FQDN instead and that doesn't seem to trigger the AD connector runtime, I do have PTR records for my VPN users.&lt;/P&gt;&lt;P&gt;Any ideas anyone?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570049#M536069</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2017-02-20T18:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD probe</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570050#M536070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Edon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you stated, the AD probe is reliant on getting the host name attribute.&amp;nbsp; There are a few ways to do this: DHCP, NMAP and DNS.&amp;nbsp; A FQDN will also trigger the AD probe.&amp;nbsp; Be sure that you have those probes enabled so that AD probe can be triggered.&amp;nbsp; If you do have those probes enabled, please open a TAC case for further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2017 18:31:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570050#M536070</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-02-23T18:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD probe</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570051#M536071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI. I have the probes configured but AD fetch is not triggered after receiving the fqdn from the dns. I see that the fqdn is successfuly learned via dns. I have a case w tac. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Feb 2017 22:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570051#M536071</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2017-02-26T22:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD probe</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570052#M536072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;opened: CSCve59881 - dns will not trigger AD probe.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jul 2017 02:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/3570052#M536072</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2017-07-21T02:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE AD probe</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/4903885#M583402</link>
      <description>&lt;P&gt;How do you see the fqdn successfully learned from dns?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 20:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-ad-probe/m-p/4903885#M583402</guid>
      <dc:creator>DannyDulin</dc:creator>
      <dc:date>2023-08-11T20:55:12Z</dc:date>
    </item>
  </channel>
</rss>

