<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does anomalous behaviour triggered when EPoint LastActiv is ch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4491353#M570625</link>
    <description>&lt;P&gt;Hi Mikhail&lt;/P&gt;&lt;P&gt;i have similar problem with some&amp;nbsp; endpoints in one account. so far it looked like endpoint was cycling DHCP procedure from wrong VLAN. interesting is it was able to obtain IP-addressing (every time new IP or in cycle) whilst it shouldnt. i'm still in investigation process (DHCP-relays &amp;amp; DHCP-servers r out of my mgmt authority) but i'm pretty sure the change of addressing enforces accounting request turned into misconfigured NAD detected alert on ISE.&lt;/P&gt;</description>
    <pubDate>Sun, 24 Oct 2021 17:16:32 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2021-10-24T17:16:32Z</dc:date>
    <item>
      <title>Why does anomalous behaviour triggered when EPoint LastActiv is change</title>
      <link>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4466792#M569697</link>
      <description>&lt;P&gt;We have ISE 2.7 with patch4.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Some endpoints are defined by ISE as "AnomalousBehaviour true"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But I don't understand why ISE triggered for &lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;these&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; endpoints.&lt;/P&gt;&lt;P&gt;I found this via the show logging application profiler.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Endpoint LastActivity is null/empty. Updating it with updatetime&lt;BR /&gt;MAC: XX:XX:XX:XX:XX:XX Significant attribue: AnomalousBehaviour new value: true old value: null&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;How to resolve it?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4466792#M569697</guid>
      <dc:creator>MikhailDemekhov96072</dc:creator>
      <dc:date>2021-09-15T09:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does anomalous behaviour triggered when EPoint LastActiv is ch</title>
      <link>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4466836#M569698</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;This is triggered by one of the following conditions (these can be viewed&lt;BR /&gt;from profiler.log).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;   1. NAS-Port-Type - Determines if the access method of this endpoint has&lt;BR /&gt;   changed. For example, if the same MAC address that connected via Wired&lt;BR /&gt;   Dot1x is used for Wireless Dot1x and visa-versa.&lt;BR /&gt;&lt;BR /&gt;   2. DHCP Class ID - Determines whether the type of client/vendor of&lt;BR /&gt;   endpoint has changed. This only applies when DHCP class ID attribute is&lt;BR /&gt;   populated with a certain value and is then changed to another value. If an&lt;BR /&gt;   endpoint is configured with a static IP, the DHCP class ID attribute will&lt;BR /&gt;   not be populated on ISE. Later on, if another device spoofs the MAC address&lt;BR /&gt;   and uses DHCP, the Class ID will change from an empty value to a specific&lt;BR /&gt;   string. This will not trigger Anomouls Behaviour detection.&lt;BR /&gt;&lt;BR /&gt;   3. Endpoint Policy - A change in endpoint profile from Printer or IP&lt;BR /&gt;   phone to Workstation.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;See this doc for more information and how to disable it.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200973-configure-anomalous-endpoint-detection-a.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/200973-configure-anomalous-endpoint-detection-a.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Sep 2021 10:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4466836#M569698</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-09-15T10:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does anomalous behaviour triggered when EPoint LastActiv is ch</title>
      <link>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4467007#M569707</link>
      <description>&lt;P&gt;Thank for your reply!&lt;/P&gt;&lt;P&gt;But &lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;I could not find&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; change for these AttrName in the profiler.log&lt;/P&gt;&lt;P&gt;I found:&lt;BR /&gt;Significant attribute change detected, persisting EP: D0:BF:9C:33:05:0B&lt;/P&gt;&lt;P&gt;:D0:BF:9C:33:05:0B:c675b270-154d-11ec-a66d-02422d8e8bc0::- Endpoint LastActivity is null/empty. Updating it with updatetime&lt;BR /&gt;com.cisco.profiler.im.EndPoint -:D0:BF:9C:33:05:0B:c675b270-154d-11ec-a66d-02422d8e8bc0::- MAC: D0:BF:9C:33:05:0B Significant attribue: AnomalousBehaviour new value: true old value: null&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;What could be the reasons for this behavior?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 14:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4467007#M569707</guid>
      <dc:creator>MikhailDemekhov96072</dc:creator>
      <dc:date>2021-09-15T14:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why does anomalous behaviour triggered when EPoint LastActiv is ch</title>
      <link>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4491353#M570625</link>
      <description>&lt;P&gt;Hi Mikhail&lt;/P&gt;&lt;P&gt;i have similar problem with some&amp;nbsp; endpoints in one account. so far it looked like endpoint was cycling DHCP procedure from wrong VLAN. interesting is it was able to obtain IP-addressing (every time new IP or in cycle) whilst it shouldnt. i'm still in investigation process (DHCP-relays &amp;amp; DHCP-servers r out of my mgmt authority) but i'm pretty sure the change of addressing enforces accounting request turned into misconfigured NAD detected alert on ISE.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 17:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/why-does-anomalous-behaviour-triggered-when-epoint-lastactiv-is/m-p/4491353#M570625</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-10-24T17:16:32Z</dc:date>
    </item>
  </channel>
</rss>

