<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE profiler feeds updates in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379168#M548940</link>
    <description>&lt;OL&gt;
&lt;LI&gt;My ISE is not able to connect to the internet for the profiler feed update so I am looking to download the updates offline and then upload to ISE is it possible&amp;nbsp; ??? but I am not able to find the path to download.
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Go to &lt;A href="http://ise.cisco.com/partner" target="_blank"&gt;http://ise.cisco.com/partner&lt;/A&gt; and register for an account.&amp;nbsp; Once registered, you will be able to download the updates for use offline.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;HP&amp;nbsp;printer model (HP-LASER JET2055dn) are not available in the ISE 2.2 patch 7 &amp;nbsp;and they are detected as a HP device so in such situation it is a security risk to allow them&amp;nbsp;by profiling HP-Device&amp;nbsp;how I can restrict these printers, if I m not wrong I can do by creating a separate profiler group and add these printers in that group and restrict them to a specific permission. Please correct me if I m wrong ??
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;You are correct.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;I am following the below link in which it says use the NMAP scanning by using that it falls in the HP-Printers&amp;nbsp;group&amp;nbsp;so what NMAP really helped is that it detects insight probe on the device to profiled accordingly ?? please clarify, so for&amp;nbsp;any device if it failing I have to run a NMAP scan on that endpoint.
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;I don't really understand the question.&amp;nbsp; NMAP Scanning is just another way of learning more information about the device to help you profile it.&amp;nbsp; Depending on how your particular printer works and how it is seen by the network, NMAP may or may not provide you with enough additional information to profile it successfully.&amp;nbsp; Unfortunately I don't have access to one to test.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.Please find the attached screenshot and explain what actual expression it is looking to profile this HP-Color-LaserJet-2500&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;STRONG&gt;1. Nothing attached.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 May 2018 09:02:09 GMT</pubDate>
    <dc:creator>RichardAtkin</dc:creator>
    <dc:date>2018-05-07T09:02:09Z</dc:date>
    <item>
      <title>ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3378396#M548937</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;My ISE is not able to connect to the internet for the profiler feed update so I am looking to download the updates offline and then upload to ISE is it possible&amp;nbsp; ??? but I am not able to find the path to download.&lt;/LI&gt;
&lt;LI&gt;HP&amp;nbsp;printer model (HP-LASER JET2055dn) are not available in the ISE 2.2 patch 7 &amp;nbsp;and they are detected as a HP device so in such situation it is a security risk to allow them&amp;nbsp;by profiling HP-Device&amp;nbsp;how I can restrict these printers, if I m not wrong I can do by creating a separate profiler group and add these printers in that group and restrict them to a specific permission. Please correct me if I m wrong ??&lt;/LI&gt;
&lt;LI&gt;I am following the below link in which it says use the NMAP scanning by using that it falls in the HP-Printers&amp;nbsp;group&amp;nbsp;so what NMAP really helped is that it detects insight probe on the device to profiled accordingly ?? please clarify, so for&amp;nbsp;any device if it failing I have to run a NMAP scan on that endpoint.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/intrusion-prevention-systems-ids/securing-network-with-ise-profiling-hp-devices/m-p/2687522#M22095" target="_blank"&gt;https://supportforums.cisco.com/t5/intrusion-prevention-systems-ids/securing-network-with-ise-profiling-hp-devices/m-p/2687522#M22095&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;4.Please find the attached screenshot and explain what actual expression it is looking to profile this HP-Color-LaserJet-2500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3378396#M548937</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T18:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379168#M548940</link>
      <description>&lt;OL&gt;
&lt;LI&gt;My ISE is not able to connect to the internet for the profiler feed update so I am looking to download the updates offline and then upload to ISE is it possible&amp;nbsp; ??? but I am not able to find the path to download.
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Go to &lt;A href="http://ise.cisco.com/partner" target="_blank"&gt;http://ise.cisco.com/partner&lt;/A&gt; and register for an account.&amp;nbsp; Once registered, you will be able to download the updates for use offline.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;HP&amp;nbsp;printer model (HP-LASER JET2055dn) are not available in the ISE 2.2 patch 7 &amp;nbsp;and they are detected as a HP device so in such situation it is a security risk to allow them&amp;nbsp;by profiling HP-Device&amp;nbsp;how I can restrict these printers, if I m not wrong I can do by creating a separate profiler group and add these printers in that group and restrict them to a specific permission. Please correct me if I m wrong ??
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;You are correct.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;I am following the below link in which it says use the NMAP scanning by using that it falls in the HP-Printers&amp;nbsp;group&amp;nbsp;so what NMAP really helped is that it detects insight probe on the device to profiled accordingly ?? please clarify, so for&amp;nbsp;any device if it failing I have to run a NMAP scan on that endpoint.
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;I don't really understand the question.&amp;nbsp; NMAP Scanning is just another way of learning more information about the device to help you profile it.&amp;nbsp; Depending on how your particular printer works and how it is seen by the network, NMAP may or may not provide you with enough additional information to profile it successfully.&amp;nbsp; Unfortunately I don't have access to one to test.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4.Please find the attached screenshot and explain what actual expression it is looking to profile this HP-Color-LaserJet-2500&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;STRONG&gt;1. Nothing attached.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 09:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379168#M548940</guid>
      <dc:creator>RichardAtkin</dc:creator>
      <dc:date>2018-05-07T09:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379505#M548943</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;
&lt;P&gt;My printers were detecting as HP device, when I run a NMAP on those specific HP printers IP address it start detected them as a HP printers, so what special NMAP probe is doing here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the attached screenshot and explain what actual expression it is looking to profile this HP-Color-LaserJet-2500&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Please find the attached&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 18:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379505#M548943</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-05-07T18:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379575#M548945</link>
      <description>When you run an NMAP probe it will run OS Scan, SNMP Port Scan and common ports etc. By the looks of the profiling policy for the HP Color Laserjet 2500 it needs the snmp probe to return the attribute "hrDeviceDescr" and it must contain "HP Color LaserJet 2500".&lt;BR /&gt;&lt;BR /&gt;As there is no profiling policy defined for the 2550dn that you have, I suggest running an NMAP SNMP scan probe and see what the "hrDeviceDescr" is, from there create a new profiling rule for that model of printer.&lt;BR /&gt;&lt;BR /&gt;The ISE profiling guide states the NMAP probe can only use the default community string "public" to directly query endpoints. In other words if you've disabled or change SNMP on those printers, you won't get the information you require from NMAP.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Mon, 07 May 2018 20:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3379575#M548945</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-05-07T20:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380285#M548948</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;
&lt;PRE&gt;By the looks of the profiling policy for the HP Color Laserjet 2500 it needs the snmp probe to return the attribute "hrDeviceDescr" and it must contain "HP Color LaserJet 2500".&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;the attribute hrDeviceDescr means the device description should contain HP Color LaserJet 2500 then only it will be&amp;nbsp;profiled&amp;nbsp;as a HP color laserJet 2500 printer ???&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please correct me if I m wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 19:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380285#M548948</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-05-08T19:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380307#M548955</link>
      <description>Correct, if the nmap probe gets that information back from snmp, it will determine the device to be a HP Color Laserjet printer and therefore classify the endpoint as such.</description>
      <pubDate>Tue, 08 May 2018 20:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380307#M548955</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-05-08T20:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiler feeds updates</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380329#M548958</link>
      <description>&lt;P&gt;thanks for confirming +5 for you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestion or best practices&amp;nbsp;for profiling,,, &amp;nbsp;the cisco document for profiling should be referred for every aspect of profiling configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 20:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiler-feeds-updates/m-p/3380329#M548958</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-05-08T20:27:35Z</dc:date>
    </item>
  </channel>
</rss>

