<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 3.0 - AD Profiling Probe Rescan in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-0-ad-profiling-probe-rescan/m-p/4822636#M581403</link>
    <description>&lt;P&gt;Hello! I'm confused about the ISE AD profiling probe slightly.&lt;/P&gt;
&lt;P&gt;The ISE 3.0 admin guide (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html#id_17552" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html#id_17552&lt;/A&gt;) and the ISE profiling guide here on the Cisco Community (&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1348091918" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1348091918&lt;/A&gt;) both have statements regarding the AD probe rescan timer that I'm not 100% clear on.&lt;/P&gt;
&lt;P&gt;The admin guide says &lt;EM&gt;"If there is additional profiling activity on the endpoint, the AD is queried again."&lt;/EM&gt; and the profiling guide says (with regard to the rescan interval) that &lt;EM&gt;"This value specifies the number of days the PSN waits before querying AD again for the same host when new profile data is learned."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Both of those make me think that ISE will only query AD for an endpoint after the rescan timer &lt;EM&gt;only if there is new profiling information for the endpoint received from other probes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The profiling guide also says this however - &lt;EM&gt;"Once Microsoft AD is queried for the host, the Policy Service node will not attempt to query AD again for the same endpoint until a rescan timer expires."&lt;/EM&gt; - which I read to mean that ISE will re-query AD for each endpoint after the rescan timer expires, irrespective of whether any new profiling data has been gathered.&lt;/P&gt;
&lt;P&gt;My observations so far suggest that the rescan only happens if there's new information learned via other probes, is this the case?&lt;/P&gt;
&lt;P&gt;What we're seeing are some endpoints showing up in ISE being profiled as a generic &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; profile when they are connected (via an SDA fabric, using MAB authentication because there's no 802.1x supplicant configured on the endpoints for reasons outside of my control!), rather than matching the custom profiling policy (let's call that other profile &lt;EM&gt;Windows10-DomainPC&lt;/EM&gt;) the customer has (that is a child of that &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; one) to match their AD-joined machines, that relies on the AD-Host-Exists attribute being true.&lt;/P&gt;
&lt;P&gt;If I disconnect the host, delete the endpoint, then reconnect it - it seems to get profiled as an AD-joined machine matching that custom profile (&lt;EM&gt;Windows10-DomainPC&lt;/EM&gt;) rather than the generic &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; profile. If I leave it for several days so that the AD rescan timer has definitely expired, it never seems to get re-profiled to that &lt;EM&gt;Windows10-DomainPC&lt;/EM&gt; profile.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2023 03:15:49 GMT</pubDate>
    <dc:creator>David Milne</dc:creator>
    <dc:date>2023-04-27T03:15:49Z</dc:date>
    <item>
      <title>ISE 3.0 - AD Profiling Probe Rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-ad-profiling-probe-rescan/m-p/4822636#M581403</link>
      <description>&lt;P&gt;Hello! I'm confused about the ISE AD profiling probe slightly.&lt;/P&gt;
&lt;P&gt;The ISE 3.0 admin guide (&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html#id_17552" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ISE_admin_3_0/b_ISE_admin_30_asset_visibility.html#id_17552&lt;/A&gt;) and the ISE profiling guide here on the Cisco Community (&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1348091918" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1348091918&lt;/A&gt;) both have statements regarding the AD probe rescan timer that I'm not 100% clear on.&lt;/P&gt;
&lt;P&gt;The admin guide says &lt;EM&gt;"If there is additional profiling activity on the endpoint, the AD is queried again."&lt;/EM&gt; and the profiling guide says (with regard to the rescan interval) that &lt;EM&gt;"This value specifies the number of days the PSN waits before querying AD again for the same host when new profile data is learned."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Both of those make me think that ISE will only query AD for an endpoint after the rescan timer &lt;EM&gt;only if there is new profiling information for the endpoint received from other probes.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The profiling guide also says this however - &lt;EM&gt;"Once Microsoft AD is queried for the host, the Policy Service node will not attempt to query AD again for the same endpoint until a rescan timer expires."&lt;/EM&gt; - which I read to mean that ISE will re-query AD for each endpoint after the rescan timer expires, irrespective of whether any new profiling data has been gathered.&lt;/P&gt;
&lt;P&gt;My observations so far suggest that the rescan only happens if there's new information learned via other probes, is this the case?&lt;/P&gt;
&lt;P&gt;What we're seeing are some endpoints showing up in ISE being profiled as a generic &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; profile when they are connected (via an SDA fabric, using MAB authentication because there's no 802.1x supplicant configured on the endpoints for reasons outside of my control!), rather than matching the custom profiling policy (let's call that other profile &lt;EM&gt;Windows10-DomainPC&lt;/EM&gt;) the customer has (that is a child of that &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; one) to match their AD-joined machines, that relies on the AD-Host-Exists attribute being true.&lt;/P&gt;
&lt;P&gt;If I disconnect the host, delete the endpoint, then reconnect it - it seems to get profiled as an AD-joined machine matching that custom profile (&lt;EM&gt;Windows10-DomainPC&lt;/EM&gt;) rather than the generic &lt;EM&gt;Windows10-Workstation&lt;/EM&gt; profile. If I leave it for several days so that the AD rescan timer has definitely expired, it never seems to get re-profiled to that &lt;EM&gt;Windows10-DomainPC&lt;/EM&gt; profile.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 03:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-ad-profiling-probe-rescan/m-p/4822636#M581403</guid>
      <dc:creator>David Milne</dc:creator>
      <dc:date>2023-04-27T03:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.0 - AD Profiling Probe Rescan</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-0-ad-profiling-probe-rescan/m-p/4824334#M581446</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/21294"&gt;@David Milne&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;what is my understanding about this ...&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&amp;nbsp;ISE&lt;/STRONG&gt; does not attempt to &lt;STRONG&gt;Query AD&lt;/STRONG&gt; &lt;U&gt;again&lt;/U&gt; for the same &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; until a the &lt;STRONG&gt;Rescan Timer&lt;/STRONG&gt; expires (configurable in &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Deployment &amp;gt; Profiling Configuration &amp;gt; Active Directory&lt;/STRONG&gt;, field&amp;nbsp;&lt;STRONG&gt;Days Before Rescan&lt;/STRONG&gt;), this is &lt;U&gt;to limit the load&lt;/U&gt; on &lt;STRONG&gt;AD&lt;/STRONG&gt; for &lt;STRONG&gt;Attribute Queries&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: "&lt;EM&gt; ...&amp;nbsp;&lt;STRONG&gt;Load&lt;/STRONG&gt; due to &lt;STRONG&gt;Authentication&lt;/STRONG&gt; is typically the &lt;STRONG&gt;Primary Source&lt;/STRONG&gt; of load on &lt;STRONG&gt;AD&lt;/STRONG&gt;, not &lt;STRONG&gt;Profiler&lt;/STRONG&gt; activity ...&lt;/EM&gt; "&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt;&amp;nbsp;since &lt;STRONG&gt;ISE&lt;/STRONG&gt; fetches the &lt;STRONG&gt;AD Attributes&lt;/STRONG&gt; for a new &lt;STRONG&gt;Endpoint&lt;/STRONG&gt; as soon as it receives a &lt;STRONG&gt;Hostname&lt;/STRONG&gt;&amp;nbsp;and the &lt;STRONG&gt;Hostname&lt;/STRONG&gt; is typically learned from the &lt;STRONG&gt;DHCP&lt;/STRONG&gt; or &lt;STRONG&gt;DNS Probes&lt;/STRONG&gt;,&amp;nbsp;via&amp;nbsp;the following &lt;STRONG&gt;Profile Attributes&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI&gt;&lt;EM&gt;Hostname (DHCP probe)&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;FQDN (DNS probe)&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;DHCP&lt;/STRONG&gt; and/or &lt;STRONG&gt;DNS Probe&lt;/STRONG&gt; must be enabled !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3rd&lt;/STRONG&gt;&amp;nbsp;if the &lt;STRONG&gt;Rescan Timer&lt;/STRONG&gt;&amp;nbsp;&lt;U&gt;is expired&lt;/U&gt; &lt;STRONG&gt;AND&lt;/STRONG&gt;&amp;nbsp;there is &lt;U&gt;additional&lt;/U&gt; &lt;STRONG&gt;Profiling&lt;/STRONG&gt; activity on the &lt;STRONG&gt;Endpoint&lt;/STRONG&gt;, then the &lt;STRONG&gt;AD&lt;/STRONG&gt; is &lt;U&gt;queried again&lt;/U&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 17:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-0-ad-profiling-probe-rescan/m-p/4824334#M581446</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-04-28T17:08:19Z</dc:date>
    </item>
  </channel>
</rss>

