<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 - AP Profiling issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222582#M551190</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please Attach screenshots from the endpoint DETAILS (context visibility &amp;gt;&amp;gt; endpoints then hit the Mac address of the APs’ Mac address). From that view you will be able to see everything ISE knows about or have letande about the endpoint. That’s the data you need to compare to the profiling policy in order to troubleshoot why there’s no 2700-AP policy match&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2017 10:57:34 GMT</pubDate>
    <dc:creator>davidgranathkarlsson</dc:creator>
    <dc:date>2017-11-26T10:57:34Z</dc:date>
    <item>
      <title>ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3220768#M551178</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having a POC with Cisco ISE 2.3 and i have some issue with AP Profiling, it's always falling the CWA policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is my policy about AP.&lt;/P&gt;
&lt;P&gt;I have created a Logical policy - AP-GROUP, then i pointed it out in the condition with full access as result.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The result is always pointing to the CWA with the Endpoin Porife as "Cisco-Device" and after few seconds, mab will fail and will never reauthenticate again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S.: I have done similar configuration with IP Phone with just pointing it to the logical profile of Phone and it works perfectly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any Suggestion please....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3220768#M551178</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2020-02-21T18:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3221824#M551179</link>
      <description>&lt;P&gt;If ISE&amp;nbsp;can only identify your access points as a "Cisco-device" this normally means ISE&amp;nbsp;i basing its profiling "decision" on OUI only, or the default profling policies isn't sufficient enough. As I don't know which methods you are using when profiling devices (nmap, dhcp, device sensor .....) this will be hard to tell.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming the issue is caused by lack of profiling information (only OUI) my suggestion would be either to enable device sensor (&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200292-Configure-Device-Sensor-for-ISE-Profilin.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200292-Configure-Device-Sensor-for-ISE-Profilin.html&lt;/A&gt;) or profile devices based on dhcp discover/requests as well (one of two ways to do this is&amp;nbsp;to add ISE as a IP helper)&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 20:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3221824#M551179</guid>
      <dc:creator>davidgranathkarlsson</dc:creator>
      <dc:date>2017-11-23T20:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222160#M551180</link>
      <description>&lt;P&gt;I had the same issue once on ISE 2.0&lt;/P&gt;
&lt;P&gt;Try first to enable device-sensor using cdp, lldp and dhcp probes if possible. This should increase the amont of information collected from the endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then make sure that based on your profiling rules are acccurate enough to match the corresponding profile (See Policy - Profile - AP XXX)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;B/R&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 15:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222160#M551180</guid>
      <dc:creator>Florian P</dc:creator>
      <dc:date>2017-11-24T15:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222564#M551182</link>
      <description>&lt;P&gt;Hi, Thank you folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have enabled mostly the required probes, and even added the device sensor command in the switch, but i am still getting the same result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have attached some of the screenshot to understand the situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly if anyone can suggest the profiling condition, i would appreciate it. I have even attached the profile condition for Access Point&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 08:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222564#M551182</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-11-26T08:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222573#M551184</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have added the snapshot&amp;nbsp;of the profiling policy of &amp;nbsp;AP model 2700 for further reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Manny&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 09:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222573#M551184</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-11-26T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222574#M551186</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have added the snapshot&amp;nbsp;of the profiling policy of &amp;nbsp;AP model 2700 for further reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Manny&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 09:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222574#M551186</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-11-26T09:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222577#M551188</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/342468"&gt;@Florian P&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it's fine, can you share with the related screen shots of your profiling condition related to Access-Point and AP model 2700, I&amp;nbsp;just to compare my configuration, maybe i missed something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate your concern!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Manny&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 09:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222577#M551188</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-11-26T09:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222582#M551190</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please Attach screenshots from the endpoint DETAILS (context visibility &amp;gt;&amp;gt; endpoints then hit the Mac address of the APs’ Mac address). From that view you will be able to see everything ISE knows about or have letande about the endpoint. That’s the data you need to compare to the profiling policy in order to troubleshoot why there’s no 2700-AP policy match&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 10:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222582#M551190</guid>
      <dc:creator>davidgranathkarlsson</dc:creator>
      <dc:date>2017-11-26T10:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222593#M551192</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/391610"&gt;@davidgranathkarlsson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thansk man, appreciate your response...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As requested, kindly find attached complete screen shots from context visibility tab...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if you found something new...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Manny&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 12:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222593#M551192</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-11-26T12:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222863#M551194</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AP2800-Rule1.PNG" style="width: 672px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3994i07A5C1DD3512ADB3/image-size/large?v=v2&amp;amp;px=999" role="button" title="AP2800-Rule1.PNG" alt="AP2800-Rule1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AP2800-Rule2.PNG" style="width: 670px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3995iE55E395F84F67D94/image-size/large?v=v2&amp;amp;px=999" role="button" title="AP2800-Rule2.PNG" alt="AP2800-Rule2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to add this in you switch config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;device-sensor filter-list lldp list TLV-LLDP&lt;BR /&gt;&amp;nbsp;tlv name system-name&lt;BR /&gt;&amp;nbsp;tlv name system-description&lt;BR /&gt;!&lt;BR /&gt;device-sensor filter-list cdp list TLV-CDP&lt;BR /&gt;&amp;nbsp;tlv name device-name&lt;BR /&gt;&amp;nbsp;tlv name address-type&lt;BR /&gt;&amp;nbsp;tlv name capabilities-type&lt;BR /&gt;&amp;nbsp;tlv name platform-type&lt;BR /&gt;!&lt;BR /&gt;device-sensor filter-list dhcp list TLV-DHCP&lt;BR /&gt;&amp;nbsp;option name host-name&lt;BR /&gt;&amp;nbsp;option name requested-address&lt;BR /&gt;&amp;nbsp;option name parameter-request-list&lt;BR /&gt;&amp;nbsp;option name class-identifier&lt;BR /&gt;&amp;nbsp;option name client-identifier&lt;BR /&gt;device-sensor filter-spec dhcp include list TLV-DHCP&lt;BR /&gt;device-sensor filter-spec lldp include list TLV-LLDP&lt;BR /&gt;device-sensor filter-spec cdp include list TLV-CDP&lt;BR /&gt;device-sensor accounting&lt;BR /&gt;device-sensor notify all-changes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now take a look at all the attributes gathered by the device sensor and make rules accurate enough to profile your APs correctly. For instance this is what I had to add to the standard ruleset :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 07:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3222863#M551194</guid>
      <dc:creator>Florian P</dc:creator>
      <dc:date>2017-11-27T07:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3223432#M551196</link>
      <description>Yeah it appears that for some reason ISE isn't getting cdp/lldp or dhcp data. Can you confirm that dhcp broadcast packets from the accesspoints are being forwarded to ISE?&lt;BR /&gt;&lt;BR /&gt;Also remember, when a client hit a authZ rule which results in a redirect, ISE won't issue a CoA. This will prevent the AP from being authorized correctly even when the AP has been profiled properly. However, once you restart the AP and it has been profiled properly this shouldn't be an issue as it will hit the correct authZ rule straight away.</description>
      <pubDate>Mon, 27 Nov 2017 21:45:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/3223432#M551196</guid>
      <dc:creator>davidgranathkarlsson</dc:creator>
      <dc:date>2017-11-27T21:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - AP Profiling issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/5295238#M596585</link>
      <description>&lt;P&gt;Hi guys, I hope your are well.&lt;/P&gt;&lt;P&gt;Could you fix the issue? I have the same issue&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 11:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-ap-profiling-issue/m-p/5295238#M596585</guid>
      <dc:creator>marcerojasc3</dc:creator>
      <dc:date>2025-05-30T11:55:31Z</dc:date>
    </item>
  </channel>
</rss>

