<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596800#M574291</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Cisco had the same issue with ISE 1.1 back in 2013.&amp;nbsp;&amp;nbsp; Since you are working for Cisco, you can easily find that ticket.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 12:55:06 GMT</pubDate>
    <dc:creator>adamscottmaster2013</dc:creator>
    <dc:date>2022-04-21T12:55:06Z</dc:date>
    <item>
      <title>Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4595523#M574242</link>
      <description>&lt;P&gt;For one day last week, my Cisco ISE Primary Admin/MNT attempted to communicate with &lt;A href="http://moleman.w3.org" target="_blank" rel="noopener"&gt;http://moleman.w3.org and it was blocked by our Internet firewalls, as it should be.&amp;nbsp;&amp;nbsp;&lt;/A&gt;However, this triggered security alarms in our environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Cisco ISE 3.0 infrastructure has been up and running for over year now and this is the first time it attempted to communicate with this unknown website.&amp;nbsp; Because I am using Smart Licensing features, the ISE node is only allowed to communicate with &lt;U&gt;&lt;A href="https://tools.cisco.com," target="_blank" rel="noopener"&gt;https://tools.cisco.com,&lt;/A&gt; &lt;A href="https://tools1.cisco.com" target="_blank" rel="noopener"&gt;https://tools1.cisco.com, https://&lt;/A&gt;tools2.cisco.com and &lt;A href="https://tools3.cisco.com" target="_blank" rel="noopener"&gt;https://tools3.cisco.com&lt;/A&gt;&lt;/U&gt; and nothing else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a bug or just bad coding?&amp;nbsp; Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4595523#M574242</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-04-19T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596160#M574268</link>
      <description>&lt;P&gt;There should be no ISE software doing that.&lt;/P&gt;
&lt;P&gt;Look in your ISE logs fot that day to see which process tried to connect to that site.&lt;/P&gt;
&lt;P&gt;The fact that it happened only for one day reinforces that it probably wasn't ISE doing it systemically but perhaps someone configuring or testing something on ISE.&amp;nbsp; The only places I can think of where ISE fetches a URL is profiling or posture updates if someone was testing those.&lt;/P&gt;
&lt;P&gt;Are you the only ISE admin? If not, talk to your team mates and be sure they weren't playing with those features.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 14:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596160#M574268</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-04-20T14:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596186#M574270</link>
      <description>&lt;P&gt;1- I don't use profiling or posture features in ISE.&amp;nbsp; I disable those features last year when ISE was put into production,&lt;/P&gt;&lt;P&gt;2- I am the only ISE admin to this device.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 14:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596186#M574270</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-04-20T14:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596229#M574271</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Some advanced tricks as mentioned in this link (an example only) :&amp;nbsp;&lt;A href="https://serverfault.com/questions/666482/how-to-find-out-pid-of-the-process-sending-packets-generating-network-traffic" target="_blank"&gt;https://serverfault.com/questions/666482/how-to-find-out-pid-of-the-process-sending-packets-generating-network-traffic&lt;/A&gt;&amp;nbsp;, could reveal the process which is using the particular dns resolution or query , the only problem being that ISE shields basic linux administrative access. If security requirements are high , one could restore a previous application&amp;nbsp; backup (e.g.) or re-image, the latter being a measure of last resort.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 16:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596229#M574271</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-04-20T16:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596509#M574281</link>
      <description>&lt;P&gt;I believe&amp;nbsp;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533" target="_self" aria-label="View Profile of adamscottmaster2013"&gt;&lt;SPAN class=""&gt;adamscottmaster&lt;WBR /&gt;2013&lt;/SPAN&gt;&lt;/A&gt; already working with TAC.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.w3.org" target="_blank"&gt;www.w3.org&lt;/A&gt;&amp;nbsp;also resolved to the same IP address. FYI.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 03:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596509#M574281</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-04-21T03:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596800#M574291</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;:&amp;nbsp; Cisco had the same issue with ISE 1.1 back in 2013.&amp;nbsp;&amp;nbsp; Since you are working for Cisco, you can easily find that ticket.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4596800#M574291</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-04-21T12:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 trying to connect to http://moleman.w3.org</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4599303#M574341</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;A id="link_27" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533" target="_self" aria-label="View Profile of adamscottmaster2013"&gt;adamscottmaster&lt;WBR /&gt;2013&lt;/A&gt;&amp;nbsp;Please provide the defect ID if you have it and let the assigned TAC known the earlier ticket. This is the first I heard of this issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 13:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-trying-to-connect-to-http-moleman-w3-org/m-p/4599303#M574341</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-04-25T13:57:31Z</dc:date>
    </item>
  </channel>
</rss>

