<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.7 - DHCP Probe not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-dhcp-probe-not-working/m-p/4729796#M578545</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;I am attempting to discover laptops connecting to a VPN endpoint that terminates on an F5 Load balancer using the DHCP Probe, but none of the devices get added as ISE Endpoints!&lt;/P&gt;&lt;P&gt;This was my approach:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I&amp;nbsp;added the ISE policy nodes as DHCP servers (Helpers) on the F5 alongside the real ones.&lt;/LI&gt;&lt;LI&gt;Opened up Port 67 on the Firewalls between the F5 and ISE&lt;/LI&gt;&lt;LI&gt;Disconnect my test laptop from the F5 VPN&lt;/LI&gt;&lt;LI&gt;Set up a TCPDump on ISE for traffic from the F5 on port 67.&lt;/LI&gt;&lt;LI&gt;Reconnect my test laptop to the F5 VPN.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The firewall shows the DHCP traffic is permitted, and the TCPDump from ISE shows the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;12:43:06.932974 IP (tos 0x0, ttl 252, id 59525, offset 0, flags [DF], proto UDP (17), length 361)&lt;BR /&gt;  192.168.150.1.13711 &amp;gt; redacted.bootps: BOOTP/DHCP, Request, length 333, htype 20, hlen 4, hops 1, xid 0x36655a71, Flags [none]&lt;BR /&gt;    Gateway-IP XXX.XXX.207.254&lt;BR /&gt;      Vendor-rfc1048 Extensions&lt;BR /&gt;        Magic Cookie 0x63825363&lt;BR /&gt;        DHCP-Message Option 53, length 1: Discover&lt;BR /&gt;        Client-ID Option 61, length 7: ether e8:6a:64:xx:xx:xx&lt;BR /&gt;        Vendor-Class Option 60, length 6: "f5-APM"&lt;BR /&gt;        Hostname Option 12, length 10: "TESTLAPTOP"&lt;BR /&gt;        MSZ Option 57, length 2: 1344&lt;BR /&gt;        Lease-Time Option 51, length 4: 4294967295&lt;BR /&gt;        Agent-Information Option 82, length 48: &lt;BR /&gt;          Circuit-ID SubOption 1, length 14: XXX.XXX.150.16&lt;BR /&gt;          Remote-ID SubOption 2, length 20: XXX.XXX.36.105:65381&lt;BR /&gt;          Subscriber-ID SubOption 6, length 8: testuser&lt;BR /&gt;12:43:06.936788 IP (tos 0x0, ttl 252, id 28432, offset 0, flags [DF], proto UDP (17), length 373)&lt;BR /&gt;  192.168.150.1.bootps &amp;gt; redacted.bootps: BOOTP/DHCP, Request, length 345, htype 20, hlen 4, hops 1, xid 0x36655a71, Flags [none]&lt;BR /&gt;    Gateway-IP 172.30.207.254&lt;BR /&gt;      Vendor-rfc1048 Extensions&lt;BR /&gt;        Magic Cookie 0x63825363&lt;BR /&gt;        DHCP-Message Option 53, length 1: Request&lt;BR /&gt;        Client-ID Option 61, length 7: ether e8:6a:64:xx:xx:xx&lt;BR /&gt;        Server-ID Option 54, length 4: TESTLAPTOP.redacted-domain.uk&lt;BR /&gt;        Requested-IP Option 50, length 4: TESTLAPTOP.redacted-domain.uk&lt;BR /&gt;        Vendor-Class Option 60, length 6: "f5-APM"&lt;BR /&gt;        Hostname Option 12, length 10: "TESTLAPTOP"&lt;BR /&gt;        MSZ Option 57, length 2: 1344&lt;BR /&gt;        Lease-Time Option 51, length 4: 4294967295&lt;BR /&gt;        Agent-Information Option 82, length 48: &lt;BR /&gt;          Circuit-ID SubOption 1, length 14: XXX.XXX.150.16&lt;BR /&gt;          Remote-ID SubOption 2, length 20: XXX.XXX.36.105:65381&lt;BR /&gt;          Subscriber-ID SubOption 6, length 8: testuser&lt;/PRE&gt;&lt;P&gt;In ISE under "WorkCenter | Profiler | Endpoint Classification", the endpoint with MAC address shown in the TCPDUMP (e8:6a:64:xx:xx:xx) does not exist, even though the TCPDump shows traffic is arriving.&lt;/P&gt;&lt;P&gt;I have double checked that the PSN's have the "Policy service" checked and that the DHCP Probe is enabled.&lt;/P&gt;&lt;P&gt;All LAN Devices are using device sensors on the switches, so this is the first real use of the DHCP probe and I've run out of things to check. Any suggestions on where I should look next would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;BR /&gt;Si.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 16:06:35 GMT</pubDate>
    <dc:creator>Scaremonger</dc:creator>
    <dc:date>2022-11-29T16:06:35Z</dc:date>
    <item>
      <title>ISE 2.7 - DHCP Probe not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-dhcp-probe-not-working/m-p/4729796#M578545</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I am attempting to discover laptops connecting to a VPN endpoint that terminates on an F5 Load balancer using the DHCP Probe, but none of the devices get added as ISE Endpoints!&lt;/P&gt;&lt;P&gt;This was my approach:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I&amp;nbsp;added the ISE policy nodes as DHCP servers (Helpers) on the F5 alongside the real ones.&lt;/LI&gt;&lt;LI&gt;Opened up Port 67 on the Firewalls between the F5 and ISE&lt;/LI&gt;&lt;LI&gt;Disconnect my test laptop from the F5 VPN&lt;/LI&gt;&lt;LI&gt;Set up a TCPDump on ISE for traffic from the F5 on port 67.&lt;/LI&gt;&lt;LI&gt;Reconnect my test laptop to the F5 VPN.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The firewall shows the DHCP traffic is permitted, and the TCPDump from ISE shows the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;12:43:06.932974 IP (tos 0x0, ttl 252, id 59525, offset 0, flags [DF], proto UDP (17), length 361)&lt;BR /&gt;  192.168.150.1.13711 &amp;gt; redacted.bootps: BOOTP/DHCP, Request, length 333, htype 20, hlen 4, hops 1, xid 0x36655a71, Flags [none]&lt;BR /&gt;    Gateway-IP XXX.XXX.207.254&lt;BR /&gt;      Vendor-rfc1048 Extensions&lt;BR /&gt;        Magic Cookie 0x63825363&lt;BR /&gt;        DHCP-Message Option 53, length 1: Discover&lt;BR /&gt;        Client-ID Option 61, length 7: ether e8:6a:64:xx:xx:xx&lt;BR /&gt;        Vendor-Class Option 60, length 6: "f5-APM"&lt;BR /&gt;        Hostname Option 12, length 10: "TESTLAPTOP"&lt;BR /&gt;        MSZ Option 57, length 2: 1344&lt;BR /&gt;        Lease-Time Option 51, length 4: 4294967295&lt;BR /&gt;        Agent-Information Option 82, length 48: &lt;BR /&gt;          Circuit-ID SubOption 1, length 14: XXX.XXX.150.16&lt;BR /&gt;          Remote-ID SubOption 2, length 20: XXX.XXX.36.105:65381&lt;BR /&gt;          Subscriber-ID SubOption 6, length 8: testuser&lt;BR /&gt;12:43:06.936788 IP (tos 0x0, ttl 252, id 28432, offset 0, flags [DF], proto UDP (17), length 373)&lt;BR /&gt;  192.168.150.1.bootps &amp;gt; redacted.bootps: BOOTP/DHCP, Request, length 345, htype 20, hlen 4, hops 1, xid 0x36655a71, Flags [none]&lt;BR /&gt;    Gateway-IP 172.30.207.254&lt;BR /&gt;      Vendor-rfc1048 Extensions&lt;BR /&gt;        Magic Cookie 0x63825363&lt;BR /&gt;        DHCP-Message Option 53, length 1: Request&lt;BR /&gt;        Client-ID Option 61, length 7: ether e8:6a:64:xx:xx:xx&lt;BR /&gt;        Server-ID Option 54, length 4: TESTLAPTOP.redacted-domain.uk&lt;BR /&gt;        Requested-IP Option 50, length 4: TESTLAPTOP.redacted-domain.uk&lt;BR /&gt;        Vendor-Class Option 60, length 6: "f5-APM"&lt;BR /&gt;        Hostname Option 12, length 10: "TESTLAPTOP"&lt;BR /&gt;        MSZ Option 57, length 2: 1344&lt;BR /&gt;        Lease-Time Option 51, length 4: 4294967295&lt;BR /&gt;        Agent-Information Option 82, length 48: &lt;BR /&gt;          Circuit-ID SubOption 1, length 14: XXX.XXX.150.16&lt;BR /&gt;          Remote-ID SubOption 2, length 20: XXX.XXX.36.105:65381&lt;BR /&gt;          Subscriber-ID SubOption 6, length 8: testuser&lt;/PRE&gt;&lt;P&gt;In ISE under "WorkCenter | Profiler | Endpoint Classification", the endpoint with MAC address shown in the TCPDUMP (e8:6a:64:xx:xx:xx) does not exist, even though the TCPDump shows traffic is arriving.&lt;/P&gt;&lt;P&gt;I have double checked that the PSN's have the "Policy service" checked and that the DHCP Probe is enabled.&lt;/P&gt;&lt;P&gt;All LAN Devices are using device sensors on the switches, so this is the first real use of the DHCP probe and I've run out of things to check. Any suggestions on where I should look next would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;BR /&gt;Si.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 16:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-dhcp-probe-not-working/m-p/4729796#M578545</guid>
      <dc:creator>Scaremonger</dc:creator>
      <dc:date>2022-11-29T16:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 - DHCP Probe not working</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-dhcp-probe-not-working/m-p/4729928#M578551</link>
      <description>&lt;P&gt;It sounds like you are trying to have ISE add an endpoint to the database solely on information from the DHCP Probe, which will not work. ISE needs to learn the endpoint MAC address from a RADIUS session. I can then supplement that endpoint data with profiling information it may learn from the DHCP Probe.&lt;BR /&gt;The MAC address is not typically something a RADIUS server learns about a VPN endpoint. With Cisco VPN endpoints, the MAC address is provided to ISE by the AnyConnect client via ACIDEX (AnyConnect Identity Extensions).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 21:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-dhcp-probe-not-working/m-p/4729928#M578551</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-11-29T21:17:24Z</dc:date>
    </item>
  </channel>
</rss>

