<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE performing NMAP scans at regular intervals. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621449#M575107</link>
    <description>&lt;P&gt;what ISE version, how is your autoscan profile looks like compare to Manual scan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check some reference guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design" target="_blank"&gt;https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1651437215" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1651437215&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 13:06:23 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-05-31T13:06:23Z</dc:date>
    <item>
      <title>Cisco ISE performing NMAP scans at regular intervals.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621403#M575106</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;I understand that the Cisco ISE PSN's should do some NMAP scans on the network at regular intervals.&lt;/P&gt;&lt;P&gt;However, I do not see that to be the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g. we have few devices where the OS and ports detected in NMAP scan do not show up.&lt;/P&gt;&lt;P&gt;However, if we do a manual scan to this device from the ISE it shows up correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have all the nodes configured to NMAP in the "Profiling Configuration".&lt;/P&gt;&lt;P&gt;It reads "The NMAP probe will scan endpoints for open ports and OS."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our challenge is where are we going wrong and why the results show up only after a manual scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;N!&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 12:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621403#M575106</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2022-05-31T12:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE performing NMAP scans at regular intervals.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621449#M575107</link>
      <description>&lt;P&gt;what ISE version, how is your autoscan profile looks like compare to Manual scan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check some reference guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design" target="_blank"&gt;https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-profiling-design&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1651437215" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-profiling-design-guide/ta-p/3739456#toc-hId-1651437215&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621449#M575107</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-05-31T13:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE performing NMAP scans at regular intervals.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621470#M575108</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;See this previous post on how/when ISE performs nmap scans&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/nmap-scan-questions/td-p/3776212" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/nmap-scan-questions/td-p/3776212&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;NMAP can be triggered in the following cases:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Manual NMAP scan&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Automatically when endpoint discovered and profile set to Unknown&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Automatically by matching a profile and one of the matching conditions has action to trigger NMAP. The NMAP scan type is defined under the NMAP Scan Actions (under Policy &amp;gt; Policy Elements &amp;gt; Results &amp;gt; Profiling &amp;gt; NMAP Scan Actions).&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621470#M575108</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-05-31T13:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE performing NMAP scans at regular intervals.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621500#M575109</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;&lt;P&gt;Thanks! The ISE version is 3.0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say autoscan, I understand you are referring to NMAP Scan Actions under "Policy Elements".&lt;/P&gt;&lt;P&gt;If yes, there is no difference in the autoscan and the manual scan I did.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4621500#M575109</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2022-05-31T13:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE performing NMAP scans at regular intervals.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4622941#M575149</link>
      <description>&lt;P&gt;ISE needs the mapping of the IP address to the MAC address in order to update the NMAP results to the endpoint.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 02:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-performing-nmap-scans-at-regular-intervals/m-p/4622941#M575149</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-02T02:58:19Z</dc:date>
    </item>
  </channel>
</rss>

