<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644671#M575931</link>
    <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;- I have read all this stuff in the documentation but it doesn't explain when NOT to use something. in other words, is there a legitimate reason to NOT use these fancy features?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, it's not a very granular mechanism - I assume that every PSN that has Session Services enabled will get this data, whether or not it will ever need it. That's the part that bothers me - especially if one has grouped various PSNs for different tasks (wired, wireless, guest).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I have also sort of understood the reason for the option to enable/disable Endpoint Attribute Filter - again, sounds like a no-brainer to enable this always. But the &lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-design-endpoint-attributes" target="_self"&gt;Profiling Guide&lt;/A&gt; says that you should disable it while "discovering endpoint attributes" in the early stages of deployment for "visibility reasons" only.&amp;nbsp; The excellent 3699 session below seems to indicate that it's ok to enable the attribute filter - not sure what they mean by "other attributes" ? In the case where we use Cisco-Provided rules and also Admin created rules, we should be ok to enable this?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="brksec3699.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155211i52A5B9C71F3EF346/image-size/large?v=v2&amp;amp;px=999" role="button" title="brksec3699.PNG" alt="brksec3699.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 23:49:59 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2022-07-05T23:49:59Z</dc:date>
    <item>
      <title>Can LSD/LDD be grouped to select PSNs only? More Profiler questions</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644623#M575928</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am still wrapping my head around ISE LSD/LDD (Lightweight Session Directory/Lightweight Data Directory) - which I believe is made up of two further acronyms RSD (RADIUS Session Directory) and EPOD (Endpoint Owner Directory).&amp;nbsp; I have read docs explaining what the feature does but I can't understand why this is even exposed to the end-user. &lt;STRONG&gt;If it's such a beneficial feature as the docs say, then why is it optional? It's also on by default. What is the use-case of having to disable this?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have another question relating to Node Groups and LDD in general. Node Groups made sense to me because I could take a bunch of PSNs of interest and put them into a group so that I had some kind of session failover mechanism (PSN1 dies, and PSN2 sends CoA to recover the session etc.) - the reason I like Node Groups is that I can include only the PSNs that matter to me. In a large ISE deployment I might have two PSNs for TACACS only, two PSNs for wireless processing only, and two PSN's for wired processing. At this point I don't want to replicate session data across all 6 PSNs because a wireless session doesn't need to replicate to a TACACS node, nor to a PSN handling wired sessions. How do I tell LDD that I don't want endpoint ownership replicated to all PSNs? Also, I might have PSNs distributed over large geographies and I want to avoid all this replication to happen over a (slow) WAN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone got any ideas about when to change the Batch and TTL settings under LDD &amp;gt; Advanced ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would also love to know whether the Profiler Setting "&lt;STRONG&gt;Enable Profiler Forwarder Persistence Queue&lt;/STRONG&gt;" should be enabled or not.&lt;/P&gt;
&lt;P&gt;And is it safe to simply enable the "&lt;STRONG&gt;EndPoint Attribute Filter&lt;/STRONG&gt;" too? Why is this not an obvious setting (set to on)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I feel like these things are all related, but I would recommend some real world feedback with how best to use them all in combination in large PSN deployments where profiling is used.&lt;/STRONG&gt; No posture or guest is used.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 21:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644623#M575928</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-05T21:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644667#M575929</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st LSD/LDD&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;Since &lt;STRONG&gt;2.7 P3&lt;/STRONG&gt; the &lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt; information (&lt;STRONG&gt;Endpoint Ownership Enhancement&lt;/STRONG&gt;) is stored across &lt;STRONG&gt;ALL&lt;/STRONG&gt; the &lt;STRONG&gt;PSNs&lt;/STRONG&gt; with the help of the &lt;STRONG&gt;LSD&lt;/STRONG&gt; - renamed to &lt;STRONG&gt;LDD RADIUS Session Directory&lt;/STRONG&gt; (introduced in &lt;STRONG&gt;ISE 2.6&lt;/STRONG&gt; - &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Light Data Distribution&lt;/STRONG&gt;). This avoids &lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt; &lt;U&gt;flapping&lt;/U&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;With &lt;STRONG&gt;LDD&lt;/STRONG&gt; every &lt;STRONG&gt;PSN&lt;/STRONG&gt; can find an &lt;U&gt;actual owner&lt;/U&gt; of the &lt;STRONG&gt;Session&lt;/STRONG&gt; from the &lt;U&gt;local&lt;/U&gt; &lt;STRONG&gt;RADIUS Session Directory&lt;/STRONG&gt; &lt;U&gt;cache&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;STRONG&gt;LDD&lt;/STRONG&gt; is used to store &lt;STRONG&gt;User Session Information&lt;/STRONG&gt; and replicate it across the &lt;STRONG&gt;PSNs&lt;/STRONG&gt; in a &lt;STRONG&gt;Deployment&lt;/STRONG&gt;, thereby &lt;U&gt;eliminating the need to be dependent&lt;/U&gt; on the &lt;STRONG&gt;PAN&lt;/STRONG&gt; or &lt;STRONG&gt;MnT Nodes&lt;/STRONG&gt; for &lt;STRONG&gt;User Session&lt;/STRONG&gt; details. In case of &lt;U&gt;connectivity issues&lt;/U&gt; between the &lt;STRONG&gt;PSNs&lt;/STRONG&gt;, for example, when a &lt;STRONG&gt;PSN&lt;/STRONG&gt; is &lt;U&gt;down&lt;/U&gt;, the &lt;STRONG&gt;Session Details&lt;/STRONG&gt; are retrieved from the &lt;STRONG&gt;MnT Session Directory&lt;/STRONG&gt; and &lt;U&gt;stored for future use&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;LDD&lt;/STRONG&gt; uses &lt;STRONG&gt;Cisco ISE Messaging Services&lt;/STRONG&gt; for &lt;U&gt;inter-node communication&lt;/U&gt;, because of that, disabling the &lt;STRONG&gt;ISE Internal CA&lt;/STRONG&gt; is not recommended.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&amp;nbsp;RADIUS Session Directory&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;The &lt;STRONG&gt;RADIUS Session Directory&lt;/STRONG&gt; is used to store the &lt;STRONG&gt;User Session Information&lt;/STRONG&gt; and replicate it across the &lt;STRONG&gt;PSNs&lt;/STRONG&gt; in a &lt;STRONG&gt;Deployment&lt;/STRONG&gt;. This directory stores &lt;U&gt;ONLY&lt;/U&gt; the &lt;STRONG&gt;Session Attributes&lt;/STRONG&gt; that are required for &lt;STRONG&gt;CoA&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;This functionality is &lt;U&gt;enabled by default&lt;/U&gt; from ISE &lt;STRONG&gt;2.7&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3rd&amp;nbsp;Endpoint Owner Directory&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;Until &lt;STRONG&gt;ISE 2.6&lt;/STRONG&gt;, when an &lt;STRONG&gt;Endpoint Probe&lt;/STRONG&gt; is received on a &lt;STRONG&gt;PSN&lt;/STRONG&gt; (that is different from the one that originally handled the requests for that specific &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;), the &lt;STRONG&gt;Endpoint Owner&lt;/STRONG&gt; is changed to the &lt;STRONG&gt;new PSN&lt;/STRONG&gt;. This results in &lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt; &lt;U&gt;flapping&lt;/U&gt; (&lt;STRONG&gt;Change of Ownership&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;From &lt;STRONG&gt;ISE 2.7&lt;/STRONG&gt;, the &lt;STRONG&gt;Endpoint Owner Directory&lt;/STRONG&gt; is used to store the &lt;STRONG&gt;PSN FQDN&lt;/STRONG&gt; of each &lt;STRONG&gt;MAC Addr&lt;/STRONG&gt; connecting to &lt;STRONG&gt;ISE&lt;/STRONG&gt; and to replicate this data across the &lt;STRONG&gt;PSNs&lt;/STRONG&gt; in a &lt;STRONG&gt;Deployment&lt;/STRONG&gt;. This avoids &lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt; &lt;U&gt;flapping&lt;/U&gt; because &lt;STRONG&gt;ALL&lt;/STRONG&gt;&amp;nbsp;the &lt;STRONG&gt;PSNs&lt;/STRONG&gt; are &lt;U&gt;now aware&lt;/U&gt; of all the &lt;STRONG&gt;Endpoint Owners&lt;/STRONG&gt;. The &lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt; now changes &lt;U&gt;ONLY&lt;/U&gt; in case of a successful &lt;STRONG&gt;RADIUS Authentication&lt;/STRONG&gt; of that &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; on another &lt;STRONG&gt;PSN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;In addition, the &lt;STRONG&gt;static Endpoint&lt;/STRONG&gt; assignments are prioritized over the attributes received by an incoming &lt;STRONG&gt;Probe&lt;/STRONG&gt; for the same &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;, &lt;U&gt;avoiding attribute override issues&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;This feature is &lt;U&gt;enabled by default&lt;/U&gt; from &lt;STRONG&gt;ISE 2.7&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;4th&amp;nbsp;Enable Profiler Forwarder Persistence Queue&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;U&gt;Enabled by default&lt;/U&gt;. Helps to &lt;U&gt;prevent data loss&lt;/U&gt;. You can disable this feature to fall back to the original mechanism, where events&amp;nbsp;&lt;U&gt;are sent directly&lt;/U&gt; to the &lt;STRONG&gt;Profiler module&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;5th&amp;nbsp;EndPoint Attribute Filter&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Aka &lt;STRONG&gt;Whitelist Filter&lt;/STRONG&gt;, best practice in &lt;STRONG&gt;Large Deployments&amp;nbsp;&lt;/STRONG&gt;to reduce &lt;STRONG&gt;Global Replication&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;NOTE: approximately every &lt;STRONG&gt;12hrs&lt;/STRONG&gt;, &lt;STRONG&gt;PSNs&lt;/STRONG&gt; sync &lt;STRONG&gt;Endpoint Attributes&lt;/STRONG&gt; with &lt;STRONG&gt;PPAN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 23:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644667#M575929</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-05T23:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644669#M575930</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;sorry ... I forgot to add the last&amp;nbsp; question ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;6th Advanced Settings&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: the following numbers are "magical numbers" for me : ) ...&amp;nbsp; but let's talk about the meaning !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Batch Size&lt;/STRONG&gt;&lt;BR /&gt;The &lt;STRONG&gt;Session Updates&lt;/STRONG&gt; can be &lt;U&gt;sent in batches&lt;/U&gt;. This value specifies the &lt;U&gt;number of records sent in each batch&lt;/U&gt; from a &lt;STRONG&gt;LDD&lt;/STRONG&gt; instance to the &lt;U&gt;other&lt;/U&gt; &lt;STRONG&gt;PSNs&lt;/STRONG&gt; in the &lt;STRONG&gt;Deployment&lt;/STRONG&gt;. If this field is set to &lt;STRONG&gt;1&lt;/STRONG&gt;, the &lt;STRONG&gt;Session Updates&lt;/STRONG&gt; are &lt;U&gt;NOT sent in batches&lt;/U&gt;. The &lt;U&gt;default&lt;/U&gt; value is &lt;STRONG&gt;10 records&lt;/STRONG&gt;.&lt;BR /&gt;&lt;STRONG&gt;TTL&lt;/STRONG&gt;&lt;BR /&gt;This value specifies the &lt;U&gt;maximum time&lt;/U&gt; a &lt;STRONG&gt;Session&lt;/STRONG&gt; will &lt;U&gt;wait for a batch to complete before updating&lt;/U&gt; the &lt;STRONG&gt;LDD&lt;/STRONG&gt;. The default value is &lt;STRONG&gt;1000 ms&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 23:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644669#M575930</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-05T23:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644671#M575931</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt;&amp;nbsp;- I have read all this stuff in the documentation but it doesn't explain when NOT to use something. in other words, is there a legitimate reason to NOT use these fancy features?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, it's not a very granular mechanism - I assume that every PSN that has Session Services enabled will get this data, whether or not it will ever need it. That's the part that bothers me - especially if one has grouped various PSNs for different tasks (wired, wireless, guest).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I have also sort of understood the reason for the option to enable/disable Endpoint Attribute Filter - again, sounds like a no-brainer to enable this always. But the &lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-design-endpoint-attributes" target="_self"&gt;Profiling Guide&lt;/A&gt; says that you should disable it while "discovering endpoint attributes" in the early stages of deployment for "visibility reasons" only.&amp;nbsp; The excellent 3699 session below seems to indicate that it's ok to enable the attribute filter - not sure what they mean by "other attributes" ? In the case where we use Cisco-Provided rules and also Admin created rules, we should be ok to enable this?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="brksec3699.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155211i52A5B9C71F3EF346/image-size/large?v=v2&amp;amp;px=999" role="button" title="brksec3699.PNG" alt="brksec3699.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 23:49:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644671#M575931</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-05T23:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644678#M575932</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;for &lt;STRONG&gt;EndPoint Attribute Filter&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;It's recommended to enabled it at &lt;U&gt;the end of the deployment&lt;/U&gt; to reduce &lt;STRONG&gt;Global Replication&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Profiler&lt;/STRONG&gt; only keep &lt;STRONG&gt;Significant Attributes&lt;/STRONG&gt; and&amp;nbsp;&lt;U&gt;discard all the others&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Remember that&amp;nbsp;replication to &lt;STRONG&gt;PAN&lt;/STRONG&gt; occurs if &lt;STRONG&gt;Significant Attributes&lt;/STRONG&gt;&amp;nbsp;changes, then sync &lt;STRONG&gt;ALL&lt;/STRONG&gt; attributes via &lt;STRONG&gt;PAN&lt;/STRONG&gt;.&lt;SPAN&gt;&amp;nbsp;if &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;Whitelist Filter&lt;/STRONG&gt;&lt;SPAN&gt; enabled, &lt;/SPAN&gt;&lt;U style="font-family: inherit;"&gt;ONLY&lt;/U&gt; &lt;STRONG style="font-family: inherit;"&gt;Whitelist Attributes&lt;/STRONG&gt;&lt;SPAN&gt; synced to &lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;ALL Nodes&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;for "&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt;... it doesn't explain when NOT to use something...&lt;/EM&gt;&amp;nbsp;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;I use the &lt;STRONG&gt;LDD&lt;/STRONG&gt; feature to&amp;nbsp;avoids/minimize&amp;nbsp;&lt;STRONG&gt;Endpoint Ownership&lt;/STRONG&gt;&amp;nbsp;&lt;U&gt;flapping&lt;/U&gt;. (I have a lot of &lt;STRONG&gt;Profiler&lt;/STRONG&gt; problems caused by a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt; with "persistence issues")&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;I use the&amp;nbsp;&lt;STRONG&gt;Enable Profiler Forwarder Persistence Queue&lt;/STRONG&gt; to &lt;U&gt;prevent data loss&lt;/U&gt; ... but this feature I already tested "uncheck" (&lt;STRONG&gt;without issues&lt;/STRONG&gt;), just to make the &lt;U&gt;process faster&lt;/U&gt; since the info was sent directly to the &lt;STRONG&gt;Profiler Module&lt;/STRONG&gt; and not to a &lt;STRONG&gt;Queue&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;SPAN&gt;Note: I already &lt;U&gt;unchecked&lt;/U&gt; ALL these&amp;nbsp;&lt;STRONG&gt;2.7&lt;/STRONG&gt;&amp;nbsp;new feature in a &lt;STRONG&gt;300K+ Deployment&lt;/STRONG&gt; during a &lt;STRONG&gt;2.4 &amp;gt;&amp;gt; 2.7&lt;/STRONG&gt; migration, without issues, just to verify the new features of &lt;STRONG&gt;2.7&lt;/STRONG&gt; step by step (I enabled each one at different time)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644678#M575932</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-06T00:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644680#M575933</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at the following at &lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKSEC-3699.pdf" target="_blank" rel="noopener"&gt;BRKSEC-3699&lt;/A&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Attributes.png" style="width: 813px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155212i7DD1345B0E4D88D9/image-dimensions/813x458?v=v2" width="813" height="458" role="button" title="Attributes.png" alt="Attributes.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644680#M575933</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-06T00:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644684#M575936</link>
      <description>&lt;P&gt;yeah I have seen all this before - but I don't understand it.&lt;/P&gt;
&lt;P&gt;I just did a comparison between attribute filter disabled, and enabled - using a Windows 10 PC authenticating with EAP-PEAP and object exists in AD. When filter is disabled, I see loads of data like the TLS version used, and a lot of data about the object in AD. But as soon as I enable the filter, I no longer see the TLS version and the AD object information. These are just some of the differences. My question is: what is the impact of NOT having these attributes visible in Context Visibility? Is the data still stored in PAN somewhere, but just not replicated to all the PSNs, or is the data simply never collected at all?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand the fact that we don't need to keep or replicate endpoint attributes that we don't use in our Policy Set logic, or in our Profiler logic. I guess I want to be 100% sure that Profiler Logic will keep working when I enable this filter. I have custom profiler conditions in use. From what I read, ISE is smart enough to not prune those attributes that are used in custom profiler conditions.&lt;/P&gt;
&lt;P&gt;Hence ... back to my original question - why isn't this enabled by default?&amp;nbsp; If anything, there should be an option to explicitly REVEAL ALL attributes feature that users can enable if they are curious about what ISE COULD collect if so required. But in most cases if Cisco profiler conditions are in use, and some admin created profiler conditions, then the filter should be on by default.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stated differently, the option we know as Endpoint Attribute Filter=disabled, should be called the "Endpoint Attribute Curiosity" feature ... for those who are curious about their endpoints - because it shows attributes that nobody can use in profiling conditions anyway - so it's a waste of time to collect and purely for curiosity/debugging purposes - right?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644684#M575936</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-06T00:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can LSD/LDD be grouped to select PSNs only? More Profiler question</title>
      <link>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644697#M575939</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;"&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;why isn't this enabled by default?&amp;nbsp;&amp;nbsp; ...&lt;/EM&gt; " in my &lt;U&gt;humble opinion&lt;/U&gt;,&amp;nbsp;the &lt;STRONG&gt;Endpoint Attribute Filter&lt;/STRONG&gt; is not &lt;U&gt;enabled by default&lt;/U&gt; because it is "best used" in&amp;nbsp;&lt;STRONG&gt;Large Deployments&lt;/STRONG&gt; &lt;U&gt;only&lt;/U&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;"&lt;EM&gt; ...&amp;nbsp;&amp;nbsp;Is the data still stored in PAN somewhere ...&lt;/EM&gt; ", my understanding is ... r&lt;/SPAN&gt;&lt;SPAN&gt;eplication to &lt;STRONG&gt;PAN&lt;/STRONG&gt; occurs &lt;U&gt;only&lt;/U&gt; if &lt;STRONG&gt;Significant Attribute&lt;/STRONG&gt; changes. If &lt;STRONG&gt;White List Attributes &lt;/STRONG&gt;changes, then replication occurs &lt;U&gt;only&lt;/U&gt; between &lt;STRONG&gt;PSN&lt;/STRONG&gt; (over &lt;STRONG&gt;Local Cluster Channel&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;"&lt;EM&gt; ...&amp;nbsp;for those who are curious about their endpoints ... "&lt;/EM&gt;, you have a point here !!! I'm in this group of curious people, but at the same time I'm trying to change the fact that "&amp;nbsp;&lt;EM&gt;... nobody can use ...&lt;/EM&gt;". For ex.: at &lt;STRONG&gt;Context Visibility &amp;gt; Endpoints &amp;gt;&lt;/STRONG&gt; click the &lt;STRONG&gt;Cog Wheel&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Create New&lt;/STRONG&gt; &amp;gt; select &lt;STRONG&gt;Attribute Categories = All Attributes (88)&lt;/STRONG&gt; ... &lt;U&gt;only&lt;/U&gt; &lt;STRONG&gt;88&lt;/STRONG&gt; ... unfortunately&amp;nbsp;the&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;InactiveDays&lt;/STRONG&gt; and &lt;STRONG&gt;ElapseDays&lt;/STRONG&gt; attributes are &lt;U&gt;missing&lt;/U&gt; (for me they are important because of&amp;nbsp;&lt;A href="https://community.cisco.com/t5/cisco-insider-user-group-ideas/ise-possibility-to-add-inactivedays-and-elapsedays-as-columns-of/idi-p/4616910" target="_blank" rel="noopener"&gt;ISE: possibility to add InactiveDays and ElapseDays as Columns of the Context Visibility&lt;/A&gt;).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 01:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-lsd-ldd-be-grouped-to-select-psns-only-more-profiler/m-p/4644697#M575939</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-06T01:31:14Z</dc:date>
    </item>
  </channel>
</rss>

