<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco 9130AXE not profiled by ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779707#M579972</link>
    <description>&lt;P&gt;Working on Dot1x at the moment and having an issue with ISE 3.1 not profiling an Cisco 9130AXE.&lt;/P&gt;&lt;P&gt;I have run the update from the feeds, this downloaded the profile for the 9130AX I then added to the correct group but it is not authorized.&lt;/P&gt;&lt;P&gt;Followed the same for a couple of 9120 and they are working fine.&lt;/P&gt;&lt;P&gt;Am I missing something.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 15:26:10 GMT</pubDate>
    <dc:creator>Garry Cooper</dc:creator>
    <dc:date>2023-02-21T15:26:10Z</dc:date>
    <item>
      <title>Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779707#M579972</link>
      <description>&lt;P&gt;Working on Dot1x at the moment and having an issue with ISE 3.1 not profiling an Cisco 9130AXE.&lt;/P&gt;&lt;P&gt;I have run the update from the feeds, this downloaded the profile for the 9130AX I then added to the correct group but it is not authorized.&lt;/P&gt;&lt;P&gt;Followed the same for a couple of 9120 and they are working fine.&lt;/P&gt;&lt;P&gt;Am I missing something.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779707#M579972</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-21T15:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779718#M579974</link>
      <description>&lt;P&gt;how is the port configuration of the switch that connected to 9130AX, what is the Logs in ISE Live ?&lt;/P&gt;
&lt;P&gt;is 9120 connected to same switch ?&lt;/P&gt;
&lt;P&gt;what switch mode ? and IOS XE code ?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779718#M579974</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-02-21T15:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779721#M579975</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322328"&gt;@Garry Cooper&lt;/a&gt; I assume you are referring to plugging in the 9130AXE AP into a wired dot1x enabled port and you want the AP authorised in ISE?&lt;/P&gt;
&lt;P&gt;Have you updated the ISE profiler feed recently? &lt;/P&gt;
&lt;P&gt;Is the switch configured with device sensor for CDP, LLDP and DHCP to send those attributes to ISE to aid profiling?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779721#M579975</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-21T15:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779737#M579976</link>
      <description>&lt;P&gt;Yes it getting connected to the same switch port as the 9120&lt;/P&gt;&lt;P&gt;I have run the update from the feed.&lt;/P&gt;&lt;P&gt;See attached the template I created for testing I am using the closed option&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779737#M579976</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-21T15:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779744#M579977</link>
      <description>&lt;P&gt;How those APs get profiled on ISE? are they getting profiled as Cisco APs or as unknown devices?, also, would you mind sharing the attributes page of one of those APs to look at what variables you would use to create your own customer profile?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779744#M579977</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-02-21T15:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779745#M579978</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322328"&gt;@Garry Cooper&lt;/a&gt; so what attributes are learnt from device sensor and sent to ISE?&lt;/P&gt;
&lt;P&gt;From the switch run "show device-sensor cache interface gigabitEthernet x/x/x" to see what the switch has learnt. Check the endpoint in ISE and see what attributes ISE has learnt, what the certainty factor is.&lt;/P&gt;
&lt;P&gt;What has ISE profiled the AP as "Cisco-Device" or ?&lt;/P&gt;
&lt;P&gt;Normally you'd start off in open mode, rather than closed mode.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779745#M579978</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-02-21T15:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779754#M579980</link>
      <description>&lt;P&gt;The AP is seen as a cisco switch on ISE.&lt;/P&gt;&lt;P&gt;The certainty factor is set to 30 same as the 9120.&lt;/P&gt;&lt;P&gt;NCC_6th_FLR_West#sh device-sensor cache interface tw3/0/23&lt;BR /&gt;Device: 00df.1d74.029c on port TwoGigabitEthernet3/0/23&lt;BR /&gt;----------------------------------------------------------------------------&lt;BR /&gt;Proto Type:Name Len Value Text&lt;BR /&gt;CDP 6:platform-type 20 00 06 00 14 63 69 73 63 6F ....cisco&lt;BR /&gt;20 43 39 31 33 30 41 58 45 C9130AXE&lt;BR /&gt;2D 45 -E&lt;BR /&gt;CDP 4:capabilities-type 8 00 04 00 08 00 00 00 03 ........&lt;BR /&gt;CDP 1:device-name 20 00 01 00 14 41 50 30 30 44 ....AP00D&lt;BR /&gt;46 2E 31 44 37 34 2E 30 32 F.1D74.02&lt;BR /&gt;39 43 9C&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 16:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779754#M579980</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-21T16:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779755#M579981</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322328"&gt;@Garry Cooper&lt;/a&gt;&amp;nbsp;as per the condition that profiler on ISE needs to hit for the AP series you mention , the minimum certainty factor to be classify an endpoint is 30 , and the 2 conditions that came as default cisco provided rules give that certainty factor as the image attached shows .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RodrigoDiaz_0-1676995226949.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/176991iA1FDABE53332B8E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RodrigoDiaz_0-1676995226949.png" alt="RodrigoDiaz_0-1676995226949.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The conditions that are required are related to : 1 )&amp;nbsp;DHCP:dhcp-class-identifier or 2)&amp;nbsp;CDP:cdpCachePlatform.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the other comments here check if any of those attributes is being sent within the probes sent by the NAD from where the AP gets connection . You can enable profiler in debug level in the PSN from where you are getting the authentication as well to verify if any of the rules stated above for profiler is being hit .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if that helped&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 16:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779755#M579981</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-02-21T16:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779787#M579985</link>
      <description>&lt;P&gt;I enabled the profiler logging but there doent seem to be much that shows the issue.&lt;/P&gt;&lt;P&gt;The mac of the ap is 00:DF:1D:74:02:9C&lt;/P&gt;&lt;P&gt;I attached the logs but dont know if its helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 16:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779787#M579985</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-21T16:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779791#M579987</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/322328"&gt;@Garry Cooper&lt;/a&gt;&amp;nbsp;, from the file you sent there are only INFO logs , you need to ensure that the profiler component&amp;nbsp; is set up first in DEBUG in the PSN owner of the session and then capture the logs in real time from profiler.log , image attached as reference, and from there you need to look to the endpoint you are doing testing with&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RodrigoDiaz_0-1676998235926.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/176997i2311B83AC6F4C7F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RodrigoDiaz_0-1676998235926.png" alt="RodrigoDiaz_0-1676998235926.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Please rate my comment if this is helping you .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 16:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4779791#M579987</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-02-21T16:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4781363#M580046</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/45117"&gt;@rodrigo&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;Thanks for the reply and sorry for my late,&lt;/P&gt;&lt;P&gt;I setup the profiler as debug and have attached the debug zip file.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 12:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4781363#M580046</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-23T12:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9130AXE not profiled by ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4783772#M580115</link>
      <description>&lt;P&gt;Just an update to my issue.&lt;/P&gt;&lt;P&gt;We had to reboot the ISE server and this has fixed the profiling issue.&lt;/P&gt;&lt;P&gt;Thanks for all the help.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 08:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-9130axe-not-profiled-by-ise/m-p/4783772#M580115</guid>
      <dc:creator>Garry Cooper</dc:creator>
      <dc:date>2023-02-28T08:56:37Z</dc:date>
    </item>
  </channel>
</rss>

