<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device profiled as &amp;quot;Asus-Device&amp;quot; instead of &amp;quot;Window in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4844333#M581991</link>
    <description>&lt;P&gt;I don't see what your "Total Certainty" value is.&lt;/P&gt;
&lt;P&gt;It makes no sense. If other (non Asus) endpoints are correctly profiling as Windows 10, then I don't see why this should be any different - unless the Asus-Device Policy has been modified to have a higher certainty than Windows.&lt;/P&gt;
&lt;P&gt;One other possible reason might be that the switch on which these Asus endpoints are connected, is not handling the CoA requests from ISE (perhaps CoA not configured with the correct ISE IPs or shared secret is wrong). Do you have endpoints on that same switch that are profiling correctly? If so, then disregard that theory.&lt;/P&gt;</description>
    <pubDate>Sun, 28 May 2023 21:38:39 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2023-05-28T21:38:39Z</dc:date>
    <item>
      <title>Device profiled as "Asus-Device" instead of "Windows10-Workstation"</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841649#M581940</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;This is my scenario:&lt;/P&gt;&lt;P&gt;We have several workstations that have "&lt;STRONG&gt;Asus&lt;/STRONG&gt;"-based motherboards. Although these workstations have Windows 10 installed, joined to the domain, and the required attributed are all collected from Active Directory probe (like operating system type and version), ISE profiles these devices as "Asus-Devices"...&lt;/P&gt;&lt;P&gt;We are using ISE 3.1 with Patch 5 installed.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 06:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841649#M581940</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-05-24T06:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841669#M581941</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt; under the endpoint, what result attributes do you get back from the AD Probe? The AD probe performs a lookup based on the computer name of the endpoint, so you need ensure the hostname is learnt by ISE via DHCP, DNS or NMAP probes.&lt;/P&gt;
&lt;P&gt;With the DHCP probe you need device sensor feature configured on the switch to learn DHCP information via DHCP snooping or an IP helper address pointing to the ISE PSN configured on the VLAN SVI. &lt;/P&gt;
&lt;P&gt;The DNS probe will perform a reverse DNS lookup, it does require ISE has already learnt the IP address of the endpoint.&lt;/P&gt;
&lt;P&gt;Refer to the ISE Profiling Guide for more information - &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 07:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841669#M581941</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-05-24T07:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841676#M581942</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;under the endpoint, what result attributes do you get back from the AD Probe?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;All the standard (default) attributes that AD probe can gather, are presented.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;The AD probe performs a lookup based on the computer name of the endpoint, so you need ensure the hostname is learnt by ISE via DHCP, DNS or NMAP probes.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;I have enabled DHCP and DNS probes and all the related attributes are gathered successfully, too.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 07:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4841676#M581942</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-05-24T07:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843139#M581970</link>
      <description>&lt;P&gt;The profile with the highest Certainty score wins. But in your case, it looks like the Windows10 PC is either not using DHCP, since that is what ISE would use as the base policy (called "Workstation") to detect a Microsoft operating system. or DHCP profiling is not working correctly (if the DHCP data is not getting into ISE)&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Asus-Device is 5 points based only on the MAC address prefix (MAC OUI contains "Asustek").&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Windows10-Workstation is based on the parent policy Microsoft-Workstation, which is based on the base policy Workstation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Workstation&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- Microsoft Workstation&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- Windows10 Workstation&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Is your PC enabled with DHCP?&amp;nbsp; Are you sending DHCP data to ISE (using Cisco Device Sensor or via the ip helper) ? When you inspect the Endpoint in ISE, do you see the DHCP Client Identifier for example? If you don't see this in ISE Context Visibility, then ISE won't consider this to be a "Workstation" and then operating system profiling will be doomed.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 20:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843139#M581970</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-25T20:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843463#M581977</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have nearly 150 PCs with Windows 10 installed and ISE correctly profiled them as Windows10-Workstation.&lt;/LI&gt;&lt;LI&gt;I have DHCP service in my network and switches are configured to send DHCP packets to ISE and the actual DHCP servers.&lt;/LI&gt;&lt;LI&gt;As I said before, ISE gathered all the default attributes of AD probe, related to that workstations successfully.&lt;/LI&gt;&lt;LI&gt;As you said, the CF of "Asus-Device" profile policy is 5 (I know this), but I have this problem with only ASUS-based systems.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 10:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843463#M581977</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-05-26T10:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843633#M581981</link>
      <description>&lt;P&gt;I did some lab work to try and reproduce the issue. I don't have an Asustek Ethernet adapter - but I used my raspberry pi connected to a Cisco C9300 switch running device-sensor.&lt;/P&gt;
&lt;P&gt;I changed the MAC address of the raspi to look like an Asustek&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;root@raspberrypi:/home/admin# macchanger --mac=00:0C:6E:01:02:03 eth0
Current MAC:   b8:27:eb:2c:50:0c (Raspberry Pi Foundation)
Permanent MAC: b8:27:eb:2c:50:0c (Raspberry Pi Foundation)
New MAC:       00:0c:6e:01:02:03 (ASUSTEK COMPUTER INC.)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I also created a DHCP request that looks like a Windows DHCP request.&lt;/P&gt;
&lt;P&gt;/etc/dhcp/dhclient.conf&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;send host-name DESKTOP-YT66D2F;
request subnet-mask, broadcast-address, time-offset, routers,
        domain-name, domain-name-servers, domain-search, host-name,
        dhcp6.name-servers, dhcp6.domain-search, dhcp6.fqdn, dhcp6.sntp-servers,
        netbios-name-servers, netbios-scope, interface-mtu,
        rfc3442-classless-static-routes, ntp-servers;
send vendor-class-identifier "MSFT 5.0";
send dhcp-client-identifier 1:00:0c:6e:01:02:03;&lt;/LI-CODE&gt;
&lt;P&gt;The result is that my IE 3.2 p2 deployment correctly profiles the device as a Microsoft-Workstation. Since I don't have an AD, I can't profile my endpoint more accurately (e.g. Windows10) - but at least it's not stuck on Asus-Device.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;CORE01#show device-sensor cache interface gi 1/0/22
Device: 000c.6e01.0203 on port GigabitEthernet1/0/22
----------------------------------------------------------------------------
Proto Type:Name                       Len Value                       Text
DHCP    61:client-identifier            9 3D 07 01 00 0C 6E 01 02 03  =....n...
DHCP    60:class-identifier            10 3C 08 4D 53 46 54 20 35 2E  &amp;lt;.MSFT 5.
                                          30                          0
DHCP    50:requested-address            6 32 04 AC 16 80 B2           2.,.^@2
DHCP    12:host-name                   17 0C 0F 44 45 53 4B 54 4F 50  ..DESKTOP
                                          2D 59 54 36 36 44 32 46     -YT66D2F
&lt;/LI-CODE&gt;
&lt;P&gt;And the Endpoint in ISE&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;AAA-Server	labise02
AllowedProtocolMatchedRule	Default
AuthenticationIdentityStore	Internal Endpoints
AuthenticationMethod	Lookup
AuthenticationStatus	AuthenticationPassed
AuthorizationPolicyMatchedRule	Default
BYODRegistration	Unknown
Called-Station-ID	F8-B7-E2-4F-57-16
Calling-Station-ID	00-0C-6E-01-02-03
ClientLatency	0
DTLSSupport	Unknown
DestinationIPAddress	172.22.137.12
DestinationPort	1812
Device IP Address	172.22.136.1
Device Type	Device Type#All Device Types#SWITCH
DeviceRegistrationStatus	NotRegistered
ElapsedDays	0
EndPointMACAddress	00-0C-6E-01-02-03
EndPointPolicy	Microsoft-Workstation
EndPointProfilerServer	labise02.rnlab.local
EndPointSource	RADIUS Probe
EndPointVersion	196
FQDN	raspberrypi.rnlab.local.
FailureReason	-
Framed-IP-Address	172.22.128.178
Framed-IPv6-Address	fe80::1d20:83:6e62:a123
IPSEC	IPSEC#Is IPSEC Device#No
IdentityGroup	Workstation
IdentityPolicyMatchedRule	Default
IdentitySelectionMatchedRule	Default
InactiveDays	0
IsThirdPartyDeviceFlow	false
Location	Location#All Locations
MACAddress	00:0C:6E:01:02:03
MatchedPolicy	Microsoft-Workstation
MessageCode	3002
NAS-IP-Address	172.22.136.1
NAS-Identifier	CORE01
NAS-Port	50122
NAS-Port-Id	GigabitEthernet1/0/22
NAS-Port-Type	Ethernet
Name	Endpoint Identity Groups:Profiled
Network Device Profile	Cisco
NetworkDeviceGroups	Device Type#All Device Types#SWITCH, IPSEC#Is IPSEC Device#No, Location#All Locations
NetworkDeviceName	CORE01
NetworkDeviceProfileId	b0699505-3150-4215-a80e-6753d45bf56c
NetworkDeviceProfileName	Cisco
OUI	ASUSTek COMPUTER INC.
OriginalUserName	000c6e010203
PolicyVersion	17
PostureApplicable	Yes
PostureAssessmentStatus	NotApplicable
PreviousMACAddress	00:0C:6E:01:02:03
RadiusFlowType	WiredMAB
SSID	F8-B7-E2-4F-57-16
SelectedAccessService	MAB
SelectedAuthenticationIdentityStores	Internal Endpoints
SelectedAuthorizationProfiles	MAB_PERMIT_ALL
Service-Type	Call Check
StaticAssignment	false
StaticGroupAssignment	false
StepData	5= Normalised Radius.RadiusFlowType, 7=Internal Endpoints, 12= EndPoints.EndPointPolicy
Total Certainty Factor	30
TotalAuthenLatency	1
UseCase	Host Lookup
User-AD-Last-Fetch-Time	1685107210384
User-Fetch-User-Name	00-0C-6E-01-02-03
User-Name	00-0C-6E-01-02-03
UserType	Host
allowEasyWiredSession	false
chaddr	00:0c:6e:01:02:03
ciaddr	0.0.0.0
dhcp-class-identifier	MSFT 5.0
dhcp-client-identifier	01:00:0c:6e:01:02:03
dhcp-message-type	DHCPREQUEST
dhcp-parameter-request-list	1, 28, 2, 3, 15, 6, 119, 12, 44, 47, 26, 121, 42
dhcp-requested-address	172.22.128.178
epid	epid:248796463613620224
flags	0x0000
giaddr	172.22.128.1
hlen	6
host-name	DESKTOP-YT66D2F
htype	Ethernet (10Mb)
ip	172.22.128.178
op	BOOTREQUEST
yiaddr	0.0.0.0&lt;/LI-CODE&gt;
&lt;P&gt;Maybe you can share some of your endpoint data and profiling information - to compare notes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 13:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4843633#M581981</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-26T13:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4844292#M581990</link>
      <description>&lt;P&gt;The following is the compressed version of the attributes of one of that clients:&lt;/P&gt;&lt;P&gt;161-udp snmp&lt;BR /&gt;162-udp snmptrap&lt;BR /&gt;AAA-Server ISE-Primary&lt;BR /&gt;AD-Fetch-Host-Name Win-PC-02$&lt;BR /&gt;AD-Host-Candidate-Identities WIN-PC-02$@domain.com&lt;BR /&gt;AD-Host-Exists true&lt;BR /&gt;AD-Join-Point DOMAIN.COM&lt;BR /&gt;AD-Host-NetBios-Name DOMAIN&lt;BR /&gt;AD-Host-Qualified-Name WIN-PC-02$@domain.com&lt;BR /&gt;AD-Host-Resolved-DNs CN=WIN-PC-02\,OU=Network\,DC=domain\,DC=com&lt;BR /&gt;AD-Host-Resolved-Identities WIN-PC-02$@domain.com&lt;BR /&gt;AD-Host-SamAccount-Name WIN-PC-02$&lt;BR /&gt;AD-Last-Fetch-Time 1684323738984&lt;BR /&gt;AD-OS-Version 10.0 (19045)&lt;BR /&gt;AD-Operating-System Windows 10 Enterprise&lt;BR /&gt;AllowedProtocolMatchedRule Dot1X Authentication&lt;BR /&gt;AuthenticationIdentityStore Domain.com&lt;BR /&gt;AuthenticationMethod MSCHAPV2&lt;BR /&gt;AuthenticationStatus AuthenticationPassed&lt;BR /&gt;AuthorizationPolicyMatchedRule Domain Wired - Computers-PEAP&lt;BR /&gt;BYODRegistration Unknown&lt;BR /&gt;Called-Station-ID F8-4F-57-5C-00-85&lt;BR /&gt;Calling-Station-ID 00-0C-6E-6C-C4-72&lt;BR /&gt;ClientLatency 0&lt;BR /&gt;DTLSSupport Unknown&lt;BR /&gt;DestinationIPAddress 192.168.10.122&lt;BR /&gt;DestinationPort 1645&lt;BR /&gt;Device IP Address 192.168.10.251&lt;BR /&gt;Device Name Win10-PC&lt;BR /&gt;Device Type Device Type#All Device Types&lt;BR /&gt;EndPointMACAddress 00-0C-6E-6C-C4-72&lt;BR /&gt;EndPointPolicy Asus-Device&lt;BR /&gt;EndPointProfilerServer ISE.domain.com&lt;BR /&gt;EndPointSource Active Directory Probe&lt;BR /&gt;EndPointVersion 121&lt;BR /&gt;FailureReason -&lt;BR /&gt;IPSEC IPSEC#Is IPSEC Device#No&lt;BR /&gt;IdentityGroup Profiled&lt;BR /&gt;OUI ASUSTek COMPUTER INC.&lt;BR /&gt;RadiusFlowType Wired802_1x&lt;BR /&gt;SelectedAccessService EAP-TLS&lt;BR /&gt;Service-Type Framed&lt;BR /&gt;Software Version 12.2(55)SE12&lt;BR /&gt;StaticAssignment FALSE&lt;BR /&gt;StaticGroupAssignment FALSE&lt;BR /&gt;operating-system-result Windows 10 Enterprise&lt;BR /&gt;chaddr 00-0C-6E-6C-C4-72&lt;BR /&gt;ciaddr 192.168.30.20&lt;BR /&gt;client-fqdn WIN-PC-02.domain.com&lt;BR /&gt;dhcp-class-identifier MSFT 5.0&lt;BR /&gt;dhcp-client-identifier 01:00:0C:6E:6C:C4:72&lt;BR /&gt;dhcp-message-type DHCPINFORM&lt;BR /&gt;dhcp-parameter-request-list 1, 15, 3, 6, 44, 46, 47, 31, 33, 121, 249, 43, 252&lt;BR /&gt;dhcp-requested-address 192.168.30.20&lt;BR /&gt;giaddr 192.168.30.1&lt;BR /&gt;host-name WIN-PC-02&lt;BR /&gt;htype Ethernet (10Mb)&lt;BR /&gt;ip 192.168.30.20&lt;BR /&gt;op BOOTREQUEST&lt;BR /&gt;operating-system-result Windows 10 Enterprise&lt;BR /&gt;yiaddr 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 16:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4844292#M581990</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-05-28T16:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4844333#M581991</link>
      <description>&lt;P&gt;I don't see what your "Total Certainty" value is.&lt;/P&gt;
&lt;P&gt;It makes no sense. If other (non Asus) endpoints are correctly profiling as Windows 10, then I don't see why this should be any different - unless the Asus-Device Policy has been modified to have a higher certainty than Windows.&lt;/P&gt;
&lt;P&gt;One other possible reason might be that the switch on which these Asus endpoints are connected, is not handling the CoA requests from ISE (perhaps CoA not configured with the correct ISE IPs or shared secret is wrong). Do you have endpoints on that same switch that are profiling correctly? If so, then disregard that theory.&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 21:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4844333#M581991</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-28T21:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861113#M582429</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I managed to reproduced the problem again!&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AAA-Server&lt;/TD&gt;&lt;TD&gt;ISE-Primary&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Fetch-Host-Name&lt;/TD&gt;&lt;TD&gt;PC01.DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Groups-Names&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM/DOMAIN Servers &amp;amp; Admins/FAVA/Groups/ISE-SuperAdmin, DOMAIN.COM/Users/Domain Users, IDOMAIN.COM/DOMAIN Servers &amp;amp; Admins/FAVA/Groups/FavaGroup&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Candidate-Identities&lt;/TD&gt;&lt;TD&gt;PC01$@DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-DNS-Domain&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Exists&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Join-Point&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-NetBios-Name&lt;/TD&gt;&lt;TD&gt;DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Qualified-Name&lt;/TD&gt;&lt;TD&gt;PC01$@DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Resolved-DNs&lt;/TD&gt;&lt;TD&gt;CN=PC01\,OU=WorkStations\,OU=FAVA\,OU=DOMAIN Servers &amp;amp; Admins\,DC=DOMAIN\,DC=COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-Resolved-Identities&lt;/TD&gt;&lt;TD&gt;PC01$@domain.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Host-SamAccount-Name&lt;/TD&gt;&lt;TD&gt;PC01$&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Join-Point&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Last-Fetch-Time&lt;/TD&gt;&lt;TD&gt;1.68723E+12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-OS-Version&lt;/TD&gt;&lt;TD&gt;10.0 (19041)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-Operating-System&lt;/TD&gt;&lt;TD&gt;Windows 10 Enterprise&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-User-DNS-Domain&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-User-Join-Point&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-User-NetBios-Name&lt;/TD&gt;&lt;TD&gt;DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AD-User-Resolved-DNs&lt;/TD&gt;&lt;TD&gt;CN=Reza Alikhani\,OU=Users\,OU=FAVA\,OU=DOMAIN Servers &amp;amp; Admins\,DC=DOMAIN\,DC=COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AKI&lt;/TD&gt;&lt;TD&gt;3a:6e:8d:1e:36:ce:b3:97:93:b0:13:9b:b4:1b:7b:d3:e3:b0:db:3e&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AllowedProtocolMatchedRule&lt;/TD&gt;&lt;TD&gt;Authentication Dot1.X-DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AuthenticationIdentityStore&lt;/TD&gt;&lt;TD&gt;DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AuthenticationMethod&lt;/TD&gt;&lt;TD&gt;x509_PKI&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AuthenticationStatus&lt;/TD&gt;&lt;TD&gt;AuthenticationPassed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;AuthorizationPolicyMatchedRule&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;BYODRegistration&lt;/TD&gt;&lt;TD&gt;Unknown&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Called-Station-ID&lt;/TD&gt;&lt;TD&gt;00-64-40-49-C6-2F&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Calling-Station-ID&lt;/TD&gt;&lt;TD&gt;F4-6D-04-39-D9-91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;ClientLatency&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;DTLSSupport&lt;/TD&gt;&lt;TD&gt;Unknown&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Days to Expiry&lt;/TD&gt;&lt;TD&gt;328&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;DestinationIPAddress&lt;/TD&gt;&lt;TD&gt;192.168.124.15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;DestinationPort&lt;/TD&gt;&lt;TD&gt;1645&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Device IP Address&lt;/TD&gt;&lt;TD&gt;192.168.141.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Device Type&lt;/TD&gt;&lt;TD&gt;Device Type#All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;DeviceRegistrationStatus&lt;/TD&gt;&lt;TD&gt;NotRegistered&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;ElapsedDays&lt;/TD&gt;&lt;TD&gt;9&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EndPointMACAddress&lt;/TD&gt;&lt;TD&gt;F4-6D-04-39-D9-91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EndPointPolicy&lt;/TD&gt;&lt;TD&gt;Asus-Device&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EndPointProfilerServer&lt;/TD&gt;&lt;TD&gt;ISE-Primary.domain.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EndPointSource&lt;/TD&gt;&lt;TD&gt;Active Directory Probe&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;EndPointVersion&lt;/TD&gt;&lt;TD&gt;1205&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Extended Key Usage - Name&lt;/TD&gt;&lt;TD&gt;130&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Extended Key Usage - OID&lt;/TD&gt;&lt;TD&gt;1.3.6.1.5.5.7.3.2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;FQDN&lt;/TD&gt;&lt;TD&gt;PC01.DOMAIN.COM.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;FailureReason&lt;/TD&gt;&lt;TD&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Framed-IP-Address&lt;/TD&gt;&lt;TD&gt;192.168.10.15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IPSEC&lt;/TD&gt;&lt;TD&gt;IPSEC#Is IPSEC Device#No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IdentityGroup&lt;/TD&gt;&lt;TD&gt;Profiled&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IdentityPolicyMatchedRule&lt;/TD&gt;&lt;TD&gt;Authentication Dot1.X-DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IdentitySelectionMatchedRule&lt;/TD&gt;&lt;TD&gt;Authentication Dot1.X-DOMAIN&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;InactiveDays&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IsMachineAuthentication&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IsMachineIdentity&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;IsThirdPartyDeviceFlow&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Issuer&lt;/TD&gt;&lt;TD&gt;CN=DOMAIN-RootCA\,DC=DOMAIN\,DC=COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Issuer - Common Name&lt;/TD&gt;&lt;TD&gt;DOMAIN-RootCA&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Issuer - Domain Component&lt;/TD&gt;&lt;TD&gt;DOMAIN, COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Issuer - Fingerprint SHA-256&lt;/TD&gt;&lt;TD&gt;2b293c9133edeec7184cb452d39c273b0170435c6dababf74270971b697aafbf&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Key Usage&lt;/TD&gt;&lt;TD&gt;0, 2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Location&lt;/TD&gt;&lt;TD&gt;Location#All Locations&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MACAddress&lt;/TD&gt;&lt;TD&gt;F4:6D:04:39:D9:91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MatchedPolicy&lt;/TD&gt;&lt;TD&gt;Asus-Device&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;MessageCode&lt;/TD&gt;&lt;TD&gt;3000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NAS-IP-Address&lt;/TD&gt;&lt;TD&gt;192.168.141.11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NAS-Port&lt;/TD&gt;&lt;TD&gt;50147&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NAS-Port-Id&lt;/TD&gt;&lt;TD&gt;GigabitEthernet1/0/47&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NAS-Port-Type&lt;/TD&gt;&lt;TD&gt;Ethernet&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Network Device Profile&lt;/TD&gt;&lt;TD&gt;Cisco&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NetworkDeviceGroups&lt;/TD&gt;&lt;TD&gt;IPSEC#Is IPSEC Device#No, Staged Deployment#Staged Deployment#Low-Impact Mode, Location#All Locations, Device Type#All Device Types&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NetworkDeviceName&lt;/TD&gt;&lt;TD&gt;SW01&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NetworkDeviceProfileId&lt;/TD&gt;&lt;TD&gt;b0699505-3150-4215-a80e-6753d45bf56c&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;NetworkDeviceProfileName&lt;/TD&gt;&lt;TD&gt;Cisco&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;OUI&lt;/TD&gt;&lt;TD&gt;ASUSTek COMPUTER INC.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;PolicyVersion&lt;/TD&gt;&lt;TD&gt;18&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;PostureApplicable&lt;/TD&gt;&lt;TD&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;PostureAssessmentStatus&lt;/TD&gt;&lt;TD&gt;NotApplicable&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;RadiusFlowType&lt;/TD&gt;&lt;TD&gt;Wired802_1x&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SSID&lt;/TD&gt;&lt;TD&gt;00-64-40-49-C6-2F&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SelectedAccessService&lt;/TD&gt;&lt;TD&gt;EAP-TLS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;&lt;TD&gt;Preloaded_Certificate_Profile&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;SelectedAuthorizationProfiles&lt;/TD&gt;&lt;TD&gt;PermitAccess&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Serial Number&lt;/TD&gt;&lt;TD&gt;42 00 00 11 41 44 FA 63 63 17 C2 7B 7F 00 00 00 00 11 41&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Service-Type&lt;/TD&gt;&lt;TD&gt;Framed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Staged Deployment&lt;/TD&gt;&lt;TD&gt;Staged Deployment#Staged Deployment#Low-Impact Mode&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;StaticAssignment&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;StaticGroupAssignment&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Subject Alternative Name - DNS&lt;/TD&gt;&lt;TD&gt;PC01.DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Subject Alternative Name - Other Name&lt;/TD&gt;&lt;TD&gt;r.alikhani@DOMAIN.COM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;TLSCipher&lt;/TD&gt;&lt;TD&gt;ECDHE-RSA-AES256-GCM-SHA384&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;TLSVersion&lt;/TD&gt;&lt;TD&gt;TLSv1.2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Template Name&lt;/TD&gt;&lt;TD&gt;1.3.6.1.4.1.311.21.8.479272.7753234.10046396.6728876.14349427.202.8611382.3759609&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Total Certainty Factor&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;TotalAuthenLatency&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;User-AD-Last-Fetch-Time&lt;/TD&gt;&lt;TD&gt;1.68723E+12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;User-Fetch-First-Name&lt;/TD&gt;&lt;TD&gt;Reza&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;User-Fetch-Last-Name&lt;/TD&gt;&lt;TD&gt;Alikhani&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;allowEasyWiredSession&lt;/TD&gt;&lt;TD&gt;FALSE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;192.168.10.15&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;lldpChassisId&lt;/TD&gt;&lt;TD&gt;04:f4:6d:04:39:d9:91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;lldpPortId&lt;/TD&gt;&lt;TD&gt;03:f4:6d:04:39:d9:91&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;operating-system-result&lt;/TD&gt;&lt;TD&gt;Windows 10 Enterprise&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;As you can see above, although ISE has recognized the OS of the endpoint, but profiled it as "Asus-Device"!&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 06:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861113#M582429</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-06-23T06:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861692#M582455</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt; ISE Profiler Policies are hierarchical. For Windows 10, the profiling order is (1) Workstation, (2) Microsoft-Workstation, and (3) Windows10-Workstation.&lt;/P&gt;
&lt;P&gt;It seems none of your attributes matched with Workstation so that is where it stops. You may either modify the Workstation policy directly or duplicate it and update the duplicated copy and add a condition on AD-Operating-System.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 04:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861692#M582455</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-06-24T04:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861693#M582456</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;My problem is that I have nearly 200 PC as Windows 10 and non of them except 5 of them have this problem. Do you think I still need to modify the Workstation profiling policy?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 05:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861693#M582456</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-06-24T05:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861809#M582458</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt; Please compare the list of endpoint attributes between working and not-working ones. As Arne said, dhcp-class-identifier or User-Agent are used typically. If you are unable to get these attributes for the not-working ones, then yes, customize the profiling policy is the way to go, until our team updates the profiling policies.&lt;/P&gt;
&lt;P&gt;CSCwf74895 open for tracking and you should be able to read it by next week. &lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 15:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4861809#M582458</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-06-24T15:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Device profiled as "Asus-Device" instead of "Window</title>
      <link>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4862444#M582484</link>
      <description>&lt;P&gt;I managed to gather more information regarding this problem:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Several switches are included in this problem. One of them is 2060-X with the Cisco's recommended IOS on it.&lt;/LI&gt;&lt;LI&gt;I have seen this problem with clients with static IP addresses and leased IP addresses from a DHCP server.&lt;/LI&gt;&lt;LI&gt;The involved switch has other clients that ISE correctly profiled them (so CoA configuration is not suspicious).&lt;/LI&gt;&lt;LI&gt;The problematic clients has various operating systems from Windows 7 to Windows 10 and 11.&lt;/LI&gt;&lt;LI&gt;I compared the attributes of two devices, one of them is profiled correctly and one of them is not. Nothing special was there except, the profiled devices had CF as 50 and problematic devices were 5.&lt;/LI&gt;&lt;LI&gt;I tried to import the provided .zip file but I encountered "&lt;STRONG&gt;Internal Error - Import Failed. Unknown enum.&lt;/STRONG&gt;" error message.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 17:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/device-profiled-as-quot-asus-device-quot-instead-of-quot/m-p/4862444#M582484</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2023-06-27T17:23:06Z</dc:date>
    </item>
  </channel>
</rss>

