<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NMAP Printer Profiling in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602796#M538156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ISE 2.1 you can create your own NMAP Scans, SNMP Port being one of them.&amp;nbsp; Go to &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results&lt;/STRONG&gt; and choose &lt;STRONG&gt;Profiling &amp;gt; Network Scan (NMAP) Actions&lt;/STRONG&gt;.&amp;nbsp; From there, Choose &lt;STRONG&gt;+Add&lt;/STRONG&gt; to create your own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NMAP.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/98248_NMAP.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, you might be able to use the &lt;STRONG&gt;SNMPPortsAndOS-scan&lt;/STRONG&gt; default NMAP Scan Action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From there, navigate to &lt;STRONG&gt;Policy &amp;gt; Profiling&lt;/STRONG&gt; and choose the device profile for which you would like to add the NMAP Scan Action.&amp;nbsp; Choose the&lt;STRONG&gt; Network Scan (NMAP) Action&lt;/STRONG&gt; from the drop down and click &lt;STRONG&gt;Save&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NMAP2.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/98249_NMAP2.PNG" style="height: 333px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Jul 2016 19:31:07 GMT</pubDate>
    <dc:creator>Charlie Moreton</dc:creator>
    <dc:date>2016-07-27T19:31:07Z</dc:date>
    <item>
      <title>NMAP Printer Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602795#M538153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure in what version NMAP defaults changed, but now unknown devices and most of the Cisco predefined profiles use "SNMPPortsandOS-scan" for the NMAP scanning.&amp;nbsp; Previously NMAP uses to scan all common ports.&amp;nbsp; Normally I don't care about more than SNMP, but port 9100 was a huge part of my printer strategy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After rolling out monitor mode, I would usually create a profiler to pull in all NMAP 9100 listeners into a group and start creating a printer profile.&amp;nbsp; Now with common ports not on by default or even available in 2.1 (at least I don't see it) I am stuck with hopefully getting SNMP data or OUI.&amp;nbsp; DHCP is not enabled for printers in most customers even though we encourage them to go with DHCP and static reservations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other way to get port 9100 open information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2016 18:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602795#M538153</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2016-07-27T18:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Printer Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602796#M538156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ISE 2.1 you can create your own NMAP Scans, SNMP Port being one of them.&amp;nbsp; Go to &lt;STRONG&gt;Policy &amp;gt; Policy Elements &amp;gt; Results&lt;/STRONG&gt; and choose &lt;STRONG&gt;Profiling &amp;gt; Network Scan (NMAP) Actions&lt;/STRONG&gt;.&amp;nbsp; From there, Choose &lt;STRONG&gt;+Add&lt;/STRONG&gt; to create your own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NMAP.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/98248_NMAP.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, you might be able to use the &lt;STRONG&gt;SNMPPortsAndOS-scan&lt;/STRONG&gt; default NMAP Scan Action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From there, navigate to &lt;STRONG&gt;Policy &amp;gt; Profiling&lt;/STRONG&gt; and choose the device profile for which you would like to add the NMAP Scan Action.&amp;nbsp; Choose the&lt;STRONG&gt; Network Scan (NMAP) Action&lt;/STRONG&gt; from the drop down and click &lt;STRONG&gt;Save&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NMAP2.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/98249_NMAP2.PNG" style="height: 333px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2016 19:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602796#M538156</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2016-07-27T19:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: NMAP Printer Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602797#M538158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks I missed where you could define custom NMAP scans.  I guess now we have to make a customer scan to get common ports then go and modify all the possible printer top level profiles to make sure 9100 is checked.  Much easier before when common ports scan was the default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the quick feedback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2016 19:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nmap-printer-profiling/m-p/3602797#M538158</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2016-07-27T19:39:34Z</dc:date>
    </item>
  </channel>
</rss>

