<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Device Profiling in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670415#M576737</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We've recently connected XBox console to our network. New security rule has been configured on Cisco ISE to allow network access. The device should be recognized and granted network access based on device profile. Pre-defined profile "Gaming Devices" has been used for that purpose. However, the devices was not properly recognized and placed in a guest VLAN (another security policy). In order to make it work, another profiling policy with MAC address has been created. Is there any way to update the list of pre-defined device profiles?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 06:37:59 GMT</pubDate>
    <dc:creator>lnw-team</dc:creator>
    <dc:date>2022-08-17T06:37:59Z</dc:date>
    <item>
      <title>Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670415#M576737</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We've recently connected XBox console to our network. New security rule has been configured on Cisco ISE to allow network access. The device should be recognized and granted network access based on device profile. Pre-defined profile "Gaming Devices" has been used for that purpose. However, the devices was not properly recognized and placed in a guest VLAN (another security policy). In order to make it work, another profiling policy with MAC address has been created. Is there any way to update the list of pre-defined device profiles?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 06:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670415#M576737</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2022-08-17T06:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670449#M576738</link>
      <description>&lt;P&gt;If you are using OUI based List ( where all xbox come with same MAC address as first 4 or 5 as manufacturer)&lt;/P&gt;
&lt;P&gt;Move the Policy above guest and test it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670449#M576738</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-17T07:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670876#M576743</link>
      <description>&lt;P&gt;The policy is above guest but the devices is not recognized properly.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 12:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4670876#M576743</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2022-08-17T12:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671051#M576748</link>
      <description>&lt;P&gt;check the Logs why the policy not matching ?&lt;/P&gt;
&lt;P&gt;take one device and try to connect and see the order of operation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 16:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671051#M576748</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-17T16:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671206#M576749</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/520091"&gt;@lnw-team&lt;/a&gt; if the endpoint matches the new policy the devices should automatically update.&lt;/P&gt;
&lt;P&gt;What is the certainty factor of one of the endpoints?&lt;/P&gt;
&lt;P&gt;In the configuration of the new profiling policy what is the certainty factor you configured?&lt;/P&gt;
&lt;P&gt;Is this higher than the certainty factor under the other policy? If not, it needs to be, otherwise the endpoint will continue to match the other policy.&lt;/P&gt;
&lt;P&gt;Provide some screenshots of the new policy, the existing policy and the output of one of the endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 18:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671206#M576749</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-17T18:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671281#M576750</link>
      <description>&lt;P&gt;ISE has built-in Profile Policies for Xbox360 and XboxOne. It's uses a combination of MAC OUI and DHCP attributes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The main issue with any profiling is, what happens when ISE sees the device for the FIRST TIME? First time means, ISE only gets a MAC address to work with. That might be enough for very crude profiling. But you want to give ISE more time to do a more accurate job. That means, you don't deny/block a device that ISE has not been able to 100% identify (in other words, you failed through all the current Authorization Policies and ended on the Default one at the bottom).&amp;nbsp; In Low-Impact mode you can return a dACL that allows DHCP, DNS and SNMP - in most cases this gives ISE a good chance to process the DHCP data, run an nmap and SNMP poll etc. Within a few seconds, ISE has learned that this is an XBOXONE, and then sends the switch a CoA Reauth. And then it will be caught in the correct Authorization Policy that you setup to put Xboxes in the right VLAN/ACL.&lt;/P&gt;
&lt;P&gt;You don't have to use Cisco's Xbox profiles - but it's a good start.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 21:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4671281#M576750</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-08-17T21:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Device Profiling</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4672846#M576796</link>
      <description>&lt;P&gt;You are using the Gaming Devices logical profile which has these profiles:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/160491i53B07118D1150AC9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Searching the ISE Profiles for "xbox" I see there is also "XBOXONE". Did you also add that? Is that not matching for you?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/160492iF275FDE0FE75F0F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt; &lt;EM&gt;the devices was not properly recognized&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;OK, then what device did it match? You did not provide any details so we cannot suggest corrections.&lt;/P&gt;
&lt;P&gt;Why did it match this other device? Were there similar attributes? Were attributes missing such that the XBOX profiles did not have a match and get a higher certainty factor?&lt;/P&gt;
&lt;P&gt;These are the profiling rules for both XBOX profiles:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;XBOX360Rule1Check1 | DHCP:dhcp-class-identifier EQUALS Xbox 360&lt;/FONT&gt;&lt;BR /&gt;and&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;XBOXONERule1Check1 | DHCP:host-name CONTAINS XBOX-ONE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;XBOXONERule1Check2 | DHCP:host-name EQUALS Xbox-SystemOS&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;XBOXONERule1Check3 | MAC:MACAddress STARTSWITH 50:1A:C5&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Are you seeing these DHCP attributes for these endpoints?&lt;/P&gt;
&lt;P&gt;Does profiling any other endpoints with DHCP work in your environment? Or is it &lt;EM&gt;only&lt;/EM&gt; XBOX&amp;nbsp; devices giving you an incorrect profile?&lt;/P&gt;
&lt;P&gt;If you do not see DHCP attributes, how are you sending ISE DHCP attributes?&lt;/P&gt;
&lt;P&gt;These are the necessary troubleshooting details you need to figure out.&lt;/P&gt;
&lt;P&gt;&lt;LI-MESSAGE title="How to Ask The Community for Help" uid="3704356" url="https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/m-p/3704356#U3704356" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 18:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-device-profiling/m-p/4672846#M576796</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-08-20T18:01:28Z</dc:date>
    </item>
  </channel>
</rss>

