<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with automatic profiling on Ise 3.1 for cisco phones with in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562893#M573106</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for replay.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saw, i attached the screen with default rule Cisco-device and cisco-ip-phone, and the profiling Configuration NODE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe I did't say it clear enough. When I connect a new Cisco phone, it is profiled as a Cisco Device and not as a Cisco-Ip-Phone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i'm using the default profiles of the nac. And as you can see from the screen, the cisco device profile contains only those rules.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2022 10:48:57 GMT</pubDate>
    <dc:creator>adrian.ciubotariu.lacatusu</dc:creator>
    <dc:date>2022-03-03T10:48:57Z</dc:date>
    <item>
      <title>Problem with automatic profiling on Ise 3.1 for cisco phones with MAB</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562181#M573065</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with automatic profiling on Ise 3.1 for cisco phones (7861,8851) with MAB.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, if my device is already profiled on ISE in manual mode, when the phone is connected, it is recognized correctly, in fact in the radius logs I see the cdp tlv parameters sent correctly to the NAC,but when I connect a new phone, it is profiled as a cisco device and not as a cisco ip-phone and is blocked by my policy. Launching a debug on the switch, I noticed, as reported above, that a device inserted manually on the nac, the switch sends the cdp tlv parameters correctly and in the other case it does not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I use a switch 2960X with two different IOS :15.2(4)E8 and&amp;nbsp;15.2(7)E5 , and another model of switch with:&amp;nbsp;WS-C3560CX-8PC-S&amp;nbsp; IOS&amp;nbsp;&amp;nbsp;15.2(7)E2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 15:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562181#M573065</guid>
      <dc:creator>adrian.ciubotariu.lacatusu</dc:creator>
      <dc:date>2022-03-02T15:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562292#M573077</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/591273"&gt;@adrian.ciubotariu.lacatusu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;to be profiled as &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt; (at &lt;STRONG&gt;Work Centers &amp;gt; Profiler &amp;gt; Profiling Policies &amp;gt; Cisco-Device &amp;gt; Cisco-IP-Phone&lt;/STRONG&gt;) some &lt;STRONG&gt;Conditions&lt;/STRONG&gt; must be match for &lt;STRONG&gt;DHCP&lt;/STRONG&gt;, &lt;STRONG&gt;CDP&lt;/STRONG&gt; or &lt;STRONG&gt;LLDP&lt;/STRONG&gt;, for ex.: CiscoIPPhoneDHCPClassIdentifierCheck, CiscoIPPhoneCDPDeviceIDCheck, ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Please double check if you are using the correct &lt;STRONG&gt;Probe&lt;/STRONG&gt; (at &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment &amp;gt; select a PSN Node &amp;gt; Profiling Configuration&lt;/STRONG&gt;) for that.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 17:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562292#M573077</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-03-02T17:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562893#M573106</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for replay.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saw, i attached the screen with default rule Cisco-device and cisco-ip-phone, and the profiling Configuration NODE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe I did't say it clear enough. When I connect a new Cisco phone, it is profiled as a Cisco Device and not as a Cisco-Ip-Phone.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i'm using the default profiles of the nac. And as you can see from the screen, the cisco device profile contains only those rules.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 10:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562893#M573106</guid>
      <dc:creator>adrian.ciubotariu.lacatusu</dc:creator>
      <dc:date>2022-03-03T10:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562983#M573115</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/591273"&gt;@adrian.ciubotariu.lacatusu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;to be profiled as &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt; some &lt;STRONG&gt;Conditions&lt;/STRONG&gt; must be matched (please take a look at the image that you provided: &lt;U&gt;&lt;EM&gt;cisco-ip-phone.png&lt;/EM&gt;&lt;/U&gt;), for ex. the &lt;STRONG&gt;CiscoIPPhoneDHCPClassIdentifierCheck2&lt;/STRONG&gt;&amp;nbsp;condition needs a &lt;STRONG&gt;DHCP Probe&lt;/STRONG&gt; enabled (that is intended for use with methods where the &lt;STRONG&gt;DHCP Request&lt;/STRONG&gt; is sent directly to the &lt;STRONG&gt;ISE PSN&lt;/STRONG&gt;, as the result of &lt;STRONG&gt;DHCP Relay&lt;/STRONG&gt; functions in the network, via the &lt;STRONG&gt;ip helper-address&lt;/STRONG&gt; command).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: at &lt;STRONG&gt;Context Visibility&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; &amp;gt; select the &lt;U&gt;IP Phone MAC Addr&lt;/U&gt; &amp;gt; &lt;STRONG&gt;Attributes&lt;/STRONG&gt;, you are able to check the attributes received for that particular &lt;STRONG&gt;IP Phone&lt;/STRONG&gt;, in other words, you are able to check what is missing for that &lt;STRONG&gt;IP Phone&lt;/STRONG&gt; to be profiled as &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 13:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4562983#M573115</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-03-03T13:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4563055#M573122</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;for dhcp i use another system, that's why i disabled dhcp on node. I checked the attributes, but it's different because one was manually profiled and another was automatically profiled. at the first connection, the phone is profiled with cisco-device and is blocked by the policy rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cisco Device is a default profile and the same for Cisco-ip-Phone.&amp;nbsp;&lt;SPAN&gt;In fact, I can't understand why he immediately chooses the cisco device profile, and not the cisco-ip-phone profile ..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in Attached the attributes, the policy and some log. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry if I look stubborn, I don't have much experience with ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 14:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4563055#M573122</guid>
      <dc:creator>adrian.ciubotariu.lacatusu</dc:creator>
      <dc:date>2022-03-03T14:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4564202#M573170</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/591273"&gt;@adrian.ciubotariu.lacatusu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;the &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; logs for &lt;STRONG&gt;IP Phones&lt;/STRONG&gt; that &lt;U&gt;Not-Work&lt;/U&gt;&amp;nbsp;vs &lt;U&gt;Work&lt;/U&gt; are the same during the initial authentication process. The point here is, since you "&lt;STRONG&gt;Static Assigment&lt;/STRONG&gt;" some IP &lt;STRONG&gt;Phones&lt;/STRONG&gt; to &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt;, this &lt;STRONG&gt;Endpoints&lt;/STRONG&gt; don't need to be profiled by &lt;STRONG&gt;ISE&lt;/STRONG&gt; because they are already &lt;U&gt;manually profiled&lt;/U&gt; as &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt; (and this is a &lt;STRONG&gt;Condition&lt;/STRONG&gt; of your &lt;STRONG&gt;IP-PHONE-Authorization&lt;/STRONG&gt; rule).&lt;BR /&gt;&amp;nbsp;Please take a look at your &lt;STRONG&gt;Cisco-Device-Attributes.PNG&lt;/STRONG&gt;&amp;nbsp;file ... you must check the &lt;STRONG&gt;Other Attributes&lt;/STRONG&gt; and search for (for ex.):&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="DHCP.png" style="width: 507px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145326iE2BD549D259FE40C/image-dimensions/507x176?v=v2" width="507" height="176" role="button" title="DHCP.png" alt="DHCP.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;the &lt;STRONG&gt;DHCP-Class-Identifier&lt;/STRONG&gt; is a &lt;STRONG&gt;Condition&lt;/STRONG&gt; to the &lt;STRONG&gt;Cisco-IP-Phone&lt;/STRONG&gt; profile.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 15:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4564202#M573170</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-03-04T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with automatic profiling on Ise 3.1 for cisco phones with</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4582995#M573770</link>
      <description>&lt;P&gt;Hello Marcelo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank's for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I activated the dhcp voice on the two nodes, and then I set the helper addresses under the vlan voice with the radius ip and it worked.&lt;/P&gt;&lt;P&gt;I'm having the following problem:&lt;/P&gt;&lt;P&gt;If I connect a pc to the switch, it authenticates itself correctly with the dot1x. If I connect a Cisco phone, it is profiled correctly with the mab. If I insert a phone,&lt;BR /&gt;with the pc connected behind it, the phone is not profiled, but remains in the cisco device group, instead the pc authenticates itself correctly, even if behind the phone.&lt;BR /&gt;I also entered the command on the interface : access-session host-mode multi-domain.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BR&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 12:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-automatic-profiling-on-ise-3-1-for-cisco-phones/m-p/4582995#M573770</guid>
      <dc:creator>adrian.ciubotariu.lacatusu</dc:creator>
      <dc:date>2022-03-31T12:24:56Z</dc:date>
    </item>
  </channel>
</rss>

