<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LLDP &amp;amp; CDP Closed DOT1X Mode in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4719265#M578159</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1310935"&gt;@KatherineTran&lt;/a&gt; correct, CDP/LLDP/DHCP is only sent if the interface is authenticated/authorised.&lt;/P&gt;
&lt;P&gt;Even if the device fails to authenticate, at a minimum ISE should be able to determine the vendor by the MAC OUI and create a database entry. When a device does successfully authenticate/authorise, ISE will learn more information from CDP/LLDP, the endpoint profile is updated.&lt;/P&gt;
&lt;P&gt;Regardless, in an ISE deployment you'd normally start in open/monitor mode, so the endpoints should already be profiled before moving to closed mode.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 11:30:03 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-11-10T11:30:03Z</dc:date>
    <item>
      <title>LLDP &amp; CDP Closed DOT1X Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4717964#M578119</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;From my understanding of documentation, CDP/LLDP would not be allowed until a port is authenticated when in closed mode. Low impact mode can be used for DHCP/DNS etc but CDP/LLDP being a layer 2 protocol what options do we have if using for profiling?&lt;/P&gt;&lt;P&gt;Or should I try to use DHCP for profiling for this reason?&lt;/P&gt;&lt;P&gt;KT&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 14:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4717964#M578119</guid>
      <dc:creator>KatherineTran</dc:creator>
      <dc:date>2022-11-08T14:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: LLDP &amp; CDP Closed DOT1X Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4717978#M578121</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1310935"&gt;@KatherineTran&lt;/a&gt; you'll get more information of the connected endpoints if you use CDP, LLDP and DHCP via device sensor.&lt;/P&gt;
&lt;P&gt;On ISE you can configure a Change of Authorisation (CoA) to be sent when a device is matched against a new profile, this can enabled globally or per profile. So therefore when the device connect for the first time, once profiled, a CoA is automatically sent and the device re-runs through authorisation and potentially matches a different authorisation rule.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 14:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4717978#M578121</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-08T14:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: LLDP &amp; CDP Closed DOT1X Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4719241#M578158</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;I believe dot1x in closed mode will not allow CDP/LLDP/DHCP to function and therefore profile the device initially so it will not be able to get to that state?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;KT&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 10:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4719241#M578158</guid>
      <dc:creator>KatherineTran</dc:creator>
      <dc:date>2022-11-10T10:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: LLDP &amp; CDP Closed DOT1X Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4719265#M578159</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1310935"&gt;@KatherineTran&lt;/a&gt; correct, CDP/LLDP/DHCP is only sent if the interface is authenticated/authorised.&lt;/P&gt;
&lt;P&gt;Even if the device fails to authenticate, at a minimum ISE should be able to determine the vendor by the MAC OUI and create a database entry. When a device does successfully authenticate/authorise, ISE will learn more information from CDP/LLDP, the endpoint profile is updated.&lt;/P&gt;
&lt;P&gt;Regardless, in an ISE deployment you'd normally start in open/monitor mode, so the endpoints should already be profiled before moving to closed mode.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 11:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4719265#M578159</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-10T11:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: LLDP &amp; CDP Closed DOT1X Mode</title>
      <link>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4721453#M578270</link>
      <description>&lt;P&gt;Chapter 23 Closed Mode of the book Cisco ISE for BYOD and Secure Unified Access has a figure, showing EAP and CDP allowed before authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 02:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lldp-amp-cdp-closed-dot1x-mode/m-p/4721453#M578270</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-11-15T02:46:15Z</dc:date>
    </item>
  </channel>
</rss>

