<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How will EndPointSource shows snmp probe in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657525#M576354</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1344744"&gt;@jinyuanbao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;about "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;I'm not sure how this&amp;nbsp;RADIUS Accounting option works ...&lt;/EM&gt; ", if you are using &lt;STRONG&gt;Cisco SW&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;(config)# aaa accounting network default start-stop group radius&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. it sends a &lt;STRONG&gt;START Accounting&lt;/STRONG&gt; notice at the beginning of the &lt;STRONG&gt;RADIUS Requested&lt;/STRONG&gt; event and a &lt;STRONG&gt;STOP Accounting&lt;/STRONG&gt; notice at the end of the event !!!&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;(config)# aaa accounting update newinfo periodic &lt;U&gt;&lt;EM&gt;2880&lt;/EM&gt;&lt;/U&gt;&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. when the &lt;STRONG&gt;newinfo&lt;/STRONG&gt; keyword is used, &lt;STRONG&gt;I&lt;/STRONG&gt;&lt;STRONG&gt;nterim Accounting&lt;/STRONG&gt; records are sent to the &lt;STRONG&gt;Accounting Server&lt;/STRONG&gt; every time there is &lt;U&gt;new accounting information to report&lt;/U&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. The &lt;STRONG&gt;periodic 2880&lt;/STRONG&gt; results in the &lt;STRONG&gt;SW&lt;/STRONG&gt; sending an &lt;STRONG&gt;Interim Accounting&lt;/STRONG&gt; &lt;U&gt;update&lt;/U&gt; regardless if the &lt;STRONG&gt;SW&lt;/STRONG&gt; observes a change for the &lt;STRONG&gt;Active Session&lt;/STRONG&gt; or not.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 12:27:12 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2022-07-26T12:27:12Z</dc:date>
    <item>
      <title>How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4655400#M576303</link>
      <description>&lt;P&gt;hi guys&lt;/P&gt;&lt;P&gt;i've enabled just snmp probe, and disabled radius probe&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="node.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157861iB2A06A6A190DE18E/image-size/large?v=v2&amp;amp;px=999" role="button" title="node.png" alt="node.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i suppose this lldp information is colleted by snmp&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="lldp.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157860iAC8D00CEA13DF56D/image-size/large?v=v2&amp;amp;px=999" role="button" title="lldp.png" alt="lldp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the endpoint has adopted the policy defined by lldp but the&amp;nbsp;&lt;SPAN&gt;EndPointSource shows&amp;nbsp;RADIUS Probe,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="result-radius probe.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157863iC14DB234314ED94F/image-size/large?v=v2&amp;amp;px=999" role="button" title="result-radius probe.png" alt="result-radius probe.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/157862i8AA64D9AC4CADC34/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.png" alt="policy.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from the captured snmp packets, i can see the snmp did collect the lldp information.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snmp收集lldp.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/158040iF04D90C386F736C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="snmp收集lldp.png" alt="snmp收集lldp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;so why the&amp;nbsp;EndPointSource shows&amp;nbsp;&lt;SPAN&gt;RADIUS Probe and how can i make the EndPointSource shows snmp probe?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 03:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4655400#M576303</guid>
      <dc:creator>jinyuanbao</dc:creator>
      <dc:date>2022-07-26T03:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656031#M576323</link>
      <description>&lt;P&gt;Interesting - are you able to delete that endpoint and repeat the exercise and get the same result?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also don't understand why the EndpointSource says "RADIUS probe". It was my understanding that this would be flagged as RADIUS Probe if ISE was processing RADIUS Accounting Interim Update requests relating to that Calling-Station-ID. Is RADIUS Accounting enabled?&amp;nbsp; If it's a Cisco switch, do you have Device Tracking and/or Device Sensor enabled?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 06:25:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656031#M576323</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-24T06:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656106#M576324</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1344744"&gt;@jinyuanbao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;remember that (at &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_010101.html" target="_blank" rel="noopener"&gt;ISE Administrator Guide - ISE Endpoint Profiling Policies&lt;/A&gt;)&lt;/P&gt;
&lt;P class="p"&gt;"&lt;EM&gt; ... Not ALL &lt;STRONG&gt;Probes&lt;/STRONG&gt; are enabled by default. Some &lt;STRONG&gt;Probes&lt;/STRONG&gt; are &lt;U&gt;partially enabled even when they are NOT explicitly enabled by a check mark&lt;/U&gt;&amp;nbsp;...&lt;/EM&gt; "&lt;/P&gt;
&lt;P class="p"&gt;&lt;STRONG&gt;HTTP&lt;/STRONG&gt; and &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; are examples of &lt;U&gt;partially enabled&lt;/U&gt; &lt;STRONG&gt;Probes&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="p"&gt;" &lt;EM&gt;... e&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;ven when the &lt;STRONG&gt;HTTP Probe&lt;/STRONG&gt; is disabled on the &lt;STRONG&gt;PSN&lt;/STRONG&gt;, the &lt;STRONG&gt;Node&lt;/STRONG&gt; will parse the &lt;STRONG&gt;Browser User Agent&lt;/STRONG&gt; string from the &lt;STRONG&gt;Web Traffic&lt;/STRONG&gt; and correlate the data to the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; based on its associated &lt;STRONG&gt;Session ID&lt;/STRONG&gt; ...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p"&gt;&lt;SPAN&gt;" &lt;EM&gt;...&amp;nbsp;The &lt;STRONG&gt;RADIUS Probe&lt;/STRONG&gt; is running by default, &lt;U&gt;even for systems NOT configured&lt;/U&gt; for &lt;STRONG&gt;Profiling Service&lt;/STRONG&gt; to ensure &lt;STRONG&gt;ISE&lt;/STRONG&gt; can track &lt;STRONG&gt;Endpoint Authentication and Authorization&lt;/STRONG&gt; details for use in &lt;STRONG&gt;Context Visibility Services&lt;/STRONG&gt; ...&lt;/EM&gt; "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 12:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656106#M576324</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-24T12:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656207#M576325</link>
      <description>&lt;P&gt;That's quite an odd way to implement a product in my opinion. If disabling RADIUS Probes still allows the RADIUS accounting data to be processed, then what have we achieved? Nada. And we should never disable RADIUS Accounting when using ISE because ISE relies on that data for session management. But we should be given the choice to NOT process the data. And quite honestly, I think this should be answered by the TAC since in my opinion it smells like a defect - the profiling has LLDP all over it - what has RADIUS probe got to do with that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 21:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656207#M576325</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-07-24T21:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656294#M576328</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I agree with you that " &lt;EM&gt;...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;we should be given the choice to NOT process the data ...&lt;/EM&gt; ".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp;It is also important to make people aware that &lt;STRONG&gt;HTTP&lt;/STRONG&gt; and &lt;STRONG&gt;RADIUS&lt;/STRONG&gt; are &lt;U&gt;partially enabled&lt;/U&gt;, as not all people know this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 02:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4656294#M576328</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-25T02:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657371#M576347</link>
      <description>&lt;P&gt;&lt;EM&gt;are you able to delete that endpoint and repeat the exercise and get the same result?&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;yes, i've deleted and repeated for several times and get the same result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Is RADIUS Accounting enabled?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Administration &amp;gt; System &amp;gt;&lt;BR /&gt;Logging &amp;gt; Logging Categories&amp;gt; RADIUS Accounting.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;do you mean this option, i've tried to disable this, and luckily the&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EndPointSource shows&amp;nbsp;&lt;SPAN&gt;SNMPQuery Probe now, although i'm not sure how this&amp;nbsp;RADIUS Accounting option works.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Thanks!! Helps a lot!&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snmpquery probe.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/158216iE5E5CFC57F33D88B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="snmpquery probe.png" alt="snmpquery probe.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If it's a Cisco switch, do you have Device Tracking and/or Device Sensor enabled?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;it's not a cisco switch sadly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 02:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657371#M576347</guid>
      <dc:creator>jinyuanbao</dc:creator>
      <dc:date>2022-07-27T02:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657379#M576348</link>
      <description>&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 08:28:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657379#M576348</guid>
      <dc:creator>jinyuanbao</dc:creator>
      <dc:date>2022-07-26T08:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: How will EndPointSource shows snmp probe</title>
      <link>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657525#M576354</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1344744"&gt;@jinyuanbao&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;about "&lt;EM&gt; ...&amp;nbsp;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;I'm not sure how this&amp;nbsp;RADIUS Accounting option works ...&lt;/EM&gt; ", if you are using &lt;STRONG&gt;Cisco SW&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;(config)# aaa accounting network default start-stop group radius&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. it sends a &lt;STRONG&gt;START Accounting&lt;/STRONG&gt; notice at the beginning of the &lt;STRONG&gt;RADIUS Requested&lt;/STRONG&gt; event and a &lt;STRONG&gt;STOP Accounting&lt;/STRONG&gt; notice at the end of the event !!!&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;(config)# aaa accounting update newinfo periodic &lt;U&gt;&lt;EM&gt;2880&lt;/EM&gt;&lt;/U&gt;&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;. when the &lt;STRONG&gt;newinfo&lt;/STRONG&gt; keyword is used, &lt;STRONG&gt;I&lt;/STRONG&gt;&lt;STRONG&gt;nterim Accounting&lt;/STRONG&gt; records are sent to the &lt;STRONG&gt;Accounting Server&lt;/STRONG&gt; every time there is &lt;U&gt;new accounting information to report&lt;/U&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;. The &lt;STRONG&gt;periodic 2880&lt;/STRONG&gt; results in the &lt;STRONG&gt;SW&lt;/STRONG&gt; sending an &lt;STRONG&gt;Interim Accounting&lt;/STRONG&gt; &lt;U&gt;update&lt;/U&gt; regardless if the &lt;STRONG&gt;SW&lt;/STRONG&gt; observes a change for the &lt;STRONG&gt;Active Session&lt;/STRONG&gt; or not.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-will-endpointsource-shows-snmp-probe/m-p/4657525#M576354</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-26T12:27:12Z</dc:date>
    </item>
  </channel>
</rss>

