<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 3.0 patch-3 is making outbound https to unknown sites in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446130#M568920</link>
    <description>&lt;P&gt;My Cisco ISE 3.0 patch 3 on SNS-3655 is making outbound https to the following sites:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;173.37.145.8&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt; --&amp;gt; tools2.cisco.com&lt;/P&gt;&lt;P&gt;34.216.127.109 --&amp;gt; ec2-34-216-127-109.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;35.83.205.101 --&amp;gt; ec2-35-83-205-101.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;54.148.222.24 --&amp;gt; ec2-54-148-222-24.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;72.163.4.38 --&amp;gt; tools1.cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to Cisco, with Smart Licensing, it should only make https outbound connection to tools.cisco.com:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dig @8.8.8.8 tools.cisco.com +short&lt;BR /&gt;173.37.145.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, you can see it is making to so AWS hosts on a regular basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Sun, 08 Aug 2021 21:06:20 GMT</pubDate>
    <dc:creator>david.tran</dc:creator>
    <dc:date>2021-08-08T21:06:20Z</dc:date>
    <item>
      <title>Cisco ISE 3.0 patch-3 is making outbound https to unknown sites</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446130#M568920</link>
      <description>&lt;P&gt;My Cisco ISE 3.0 patch 3 on SNS-3655 is making outbound https to the following sites:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;173.37.145.8&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt; --&amp;gt; tools2.cisco.com&lt;/P&gt;&lt;P&gt;34.216.127.109 --&amp;gt; ec2-34-216-127-109.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;35.83.205.101 --&amp;gt; ec2-35-83-205-101.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;54.148.222.24 --&amp;gt; ec2-54-148-222-24.us-west-2.compute.amazonaws.com.&lt;/P&gt;&lt;P&gt;72.163.4.38 --&amp;gt; tools1.cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to Cisco, with Smart Licensing, it should only make https outbound connection to tools.cisco.com:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dig @8.8.8.8 tools.cisco.com +short&lt;BR /&gt;173.37.145.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, you can see it is making to so AWS hosts on a regular basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2021 21:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446130#M568920</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2021-08-08T21:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 patch-3 is making outbound https to unknown sites</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446133#M568921</link>
      <description>&lt;P&gt;tools.cisco.com for only smart License, cisco also need some posture updates and Cisco host some service with Amazon Cloud too, Maybe i am guessing here to get updates? what port 443?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2021 21:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446133#M568921</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-08T21:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 patch-3 is making outbound https to unknown sites</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446134#M568922</link>
      <description>&lt;P&gt;I am not running posture.&amp;nbsp; I am using Smart Licensing.&amp;nbsp; I currently have a TAC case with Cisco but the TAC engineer doesn't know either.&amp;nbsp; He is investigating but he doesn't know why the box is reaching out to the AWS Internet.&amp;nbsp; To me, that's a security red flag. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;:&amp;nbsp; Yes, https (443) as posted in my original thread&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2021 21:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446134#M568922</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2021-08-08T21:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 patch-3 is making outbound https to unknown sites</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446139#M568923</link>
      <description>&lt;P&gt;Are you using any of these features? Even if you're not using them there is a chance that a call out is still enabled like with automatic posture updates/downloads, and the profiler feed updates. I also see quite a few ISE deployments making calls for CRL, it's a pretty common investigation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_6023002BA3B549D6BBED2ACE4B6FDDAE" class="li"&gt;
&lt;P class="p"&gt;Partner Mobile Management&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_C8DB94363CE5484BB95A62DFA3E8B3D6" class="li"&gt;
&lt;P class="p"&gt;Endpoint Profiler Feed Service Update&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_28BFECFC09B5455A94D7194A863C9564" class="li"&gt;
&lt;P class="p"&gt;Endpoint Posture Update&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_212AF48AF78349BEB5CBF88B0F4D16B9" class="li"&gt;
&lt;P class="p"&gt;Endpoint Posture Agent Resources Download&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_234EB65A90024A03906F17C9CF63CD3F" class="li"&gt;
&lt;P class="p"&gt;Certificate Revocation List (CRL) Download&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="task_5EED7670B71847DE949430AB5E267DBD__li_3D42011FC1574833AAD425F50FBC91C3" class="li"&gt;
&lt;P class="p"&gt;Guest Notifications&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;SMS Message Transmission&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Social Login&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 08 Aug 2021 22:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446139#M568923</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-08-08T22:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 patch-3 is making outbound https to unknown sites</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446140#M568924</link>
      <description>&lt;P&gt;I may be missed your HTTPS information, I was only thought tools.cisco.com for HTTPS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by investigating more: here is the IP related to Cisco.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ipduh.com/dns/?www.ciscoconnectdna.com" target="_blank"&gt;https://ipduh.com/dns/?www.ciscoconnectdna.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Aug 2021 22:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-patch-3-is-making-outbound-https-to-unknown-sites/m-p/4446140#M568924</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-08T22:16:10Z</dc:date>
    </item>
  </channel>
</rss>

