<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting LLDP options using ISE Authorization Profile Advanced Attr in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4851289#M582117</link>
    <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What we are looking for is the ability to selectively NOT return certain attributes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Your confusion as to why I'm trying to achieve this is understandable, I myself would be fine with just a default set of returned attributes configured on access ports, but some voices in our organisation are very.. carefull.. about any attributes advertised on access ports.&lt;/P&gt;&lt;P&gt;We have NAC implemented, switch software is up-to-date, so the switches have no horrible vulnerabilities, the risk of advertised lldp attributes seems manageable in my opinion.&lt;/P&gt;&lt;P&gt;But as it is, I was asked to investigate if it is possible, so here we are.&lt;/P&gt;&lt;P&gt;Named Templates, i'll give that a try and will be back, with good or bad news.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2023 10:50:52 GMT</pubDate>
    <dc:creator>netwerkbeheer</dc:creator>
    <dc:date>2023-06-08T10:50:52Z</dc:date>
    <item>
      <title>Setting LLDP options using ISE Authorization Profile Advanced Attrib's</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4817805#M581281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have &lt;EM&gt;ISE 2.7.0.356 patch 9&lt;/EM&gt;, with most of our switches on &lt;EM&gt;Cisco IOS XE Software, Version 16.12.05b&lt;/EM&gt;, and some newer switches running&amp;nbsp;&lt;EM&gt;17.06.04&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For our LAN we would like the option to enable or disable all, or specific LLDP TLV advertisements, depending on what devices authenticates, &lt;EM&gt;(or fails to authenticate)&lt;/EM&gt; on our switch ports.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;We don't yet use Profiling, so no incoming LLDP data in our switches is used in our auth. policies. So that is no issue in this case.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Interface Profiles&lt;/EM&gt;&lt;/STRONG&gt; was my first guess to use for this, but I understood LLDP is &lt;EM&gt;not&lt;/EM&gt; supported by the Interface Profile feature(?)&lt;/P&gt;&lt;P&gt;In the &lt;EM&gt;Advanced Attributes Settings&lt;/EM&gt; for &lt;EM&gt;Authorization Profiles&lt;/EM&gt; the following appears when LLDP is entered in the search bar:&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;LLDP:lldpSystemDescription =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpTimeToLive =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpPortDescription =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpManAddress =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpCapabilitiesMapSupported =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpCacheCapabilities =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpPortId =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpSystemCapabilitiesMapEnabled =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpSystemName =&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:lldpChassisId =&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;LLDP:cdpCacheAddress =&lt;/STRONG&gt;&lt;/PRE&gt;&lt;UL&gt;&lt;LI&gt;But what do I enter or select there to the right of the "=", in the second column?&lt;UL&gt;&lt;LI&gt;Enable/ Disable, On/Off, or .... ?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;(&lt;/EM&gt;Under &lt;EM&gt;&lt;STRONG&gt;Policy&lt;/STRONG&gt;&lt;/EM&gt; &amp;gt; &lt;EM&gt;&lt;STRONG&gt;Policy Elements&lt;/STRONG&gt;&lt;/EM&gt; &amp;gt; &lt;EM&gt;&lt;STRONG&gt;Dictionaries&lt;/STRONG&gt;&lt;/EM&gt; &amp;gt; &lt;EM&gt;&lt;STRONG&gt;LLDP&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;i hoped to find something, but it says &lt;EM&gt;STRING&lt;/EM&gt;, and nothing else which could be usefull.)&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this even a valid set of Attributes, for use to &lt;EM&gt;SET&lt;/EM&gt; options for LLDP on switchports, or could it be a set of Profiling options that should not even appear in an Authorization Profile? &lt;EM&gt;(I ask this in part because all LLDP related ISE search terms only give Profiling-related results.)&lt;BR /&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;If these Advanced Attributes are no option;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is there another way to set LLDP option/ config on switchports using ISE Authorization Profiles?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;And, because I spent all day looking for a more in depth document about this, and failing to find one&lt;/STRONG&gt;&lt;/EM&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is there a &lt;EM&gt;Deep-Dive&lt;/EM&gt;, &lt;EM&gt;Advanced&lt;/EM&gt;, &lt;EM&gt;In Depth&lt;/EM&gt; guide for configuring Authorization Profiles, &lt;EM&gt;including&lt;/EM&gt; of course the options under&amp;nbsp;&lt;EM&gt;Advanced Attributes Settings&lt;/EM&gt;?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone knows, please make my day.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Rick Roersma&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 15:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4817805#M581281</guid>
      <dc:creator>netwerkbeheer</dc:creator>
      <dc:date>2023-04-19T15:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Setting LLDP options using ISE Authorization Profile Advanced Attr</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4819846#M581352</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/311034"&gt;@netwerkbeheer&lt;/a&gt;&amp;nbsp; - I understand what you're trying to achieve, but what is the reason you want to do this - is there a requirement by the endpoints to process custom LLDP attributes?&amp;nbsp; Not sure how this can be done - as far as I understand, the changes in the switch interface should influence what attributes the switch advertises to the endpoint - as opposed to the other way around, where the Device Sensor processes the attributes, it hears from endpoints.&lt;/P&gt;
&lt;P&gt;Do you want the ability to selectively NOT return certain attributes, or do you want to have the ability to set the values of those attributes?&amp;nbsp; Have you tried creating a named template on the switch? Does it accept LLDP commands in the template? If yes, then try returning that template to an endpoint and see if the config accepts it (show derived-config interface xyz)&lt;/P&gt;
&lt;P&gt;I don't know about the LLDP Dictionary - I would assume that this is used by ISE to process the Device Sensor data it receives from the switch as part of the Device Sensor (profiling).&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 20:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4819846#M581352</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-04-23T20:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Setting LLDP options using ISE Authorization Profile Advanced Attr</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4820148#M581360</link>
      <description>&lt;P&gt;You can control the send and receive of TLV on switchport using LLDP-MED&lt;/P&gt;
&lt;H3 id="ariaid-title6" class="title topictitle3 2H_Head2-63752EA5"&gt;LLDP-MED&lt;/H3&gt;
&lt;SECTION class="body conbody"&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;LLDP for Media Endpoint Devices (LLDP-MED) is an extension to LLDP that operates between endpoint devices such as IP phones and network devices. It specifically provides support for voice over IP (VoIP) applications and provides additional TLVs for capabilities discovery, network policy, Power over Ethernet, inventory management and location information. By default, all LLDP-MED TLVs are enabled.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;NAV class="related-links" role="navigation"&gt;
&lt;UL class="ullinks"&gt;
&lt;LI class="link ulchildlink"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/int_hw/b_1612_int_and_hw_9200_cg/configuring_lldp__lldp_med__and_wired_location_service.html#concept_zj4_4dz_g1b" target="_blank"&gt;LLDP-MED Supported TLVs&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/NAV&gt;
&lt;ARTICLE id="concept_zj4_4dz_g1b" class="topic concept nested3" lang="en-US" aria-labelledby="ariaid-title7"&gt;
&lt;H4 id="ariaid-title7" class="title topictitle4"&gt;LLDP-MED Supported TLVs&lt;/H4&gt;
&lt;SECTION class="body conbody"&gt;
&lt;P class="p B1_Body1-F9CE5028"&gt;LLDP-MED supports these TLVs:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="concept_zj4_4dz_g1b__li_01183FB5FC664D6BA5A899111D060CEA" class="li"&gt;
&lt;P class="p Bu1_Bullet1-CC106A77"&gt;LLDP-MED capabilities TLV&lt;/P&gt;
&lt;P class="p B2_Body2-1DD120E0"&gt;Allows LLDP-MED endpoints to determine the capabilities that the connected device supports and has enabled.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;
&lt;/ARTICLE&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/int_hw/b_1612_int_and_hw_9200_cg/configuring_lldp__lldp_med__and_wired_location_service.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/int_hw/b_1612_int_and_hw_9200_cg/configuring_lldp__lldp_med__and_wired_location_service.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 09:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4820148#M581360</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2023-04-24T09:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Setting LLDP options using ISE Authorization Profile Advanced Attr</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4851289#M582117</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What we are looking for is the ability to selectively NOT return certain attributes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Your confusion as to why I'm trying to achieve this is understandable, I myself would be fine with just a default set of returned attributes configured on access ports, but some voices in our organisation are very.. carefull.. about any attributes advertised on access ports.&lt;/P&gt;&lt;P&gt;We have NAC implemented, switch software is up-to-date, so the switches have no horrible vulnerabilities, the risk of advertised lldp attributes seems manageable in my opinion.&lt;/P&gt;&lt;P&gt;But as it is, I was asked to investigate if it is possible, so here we are.&lt;/P&gt;&lt;P&gt;Named Templates, i'll give that a try and will be back, with good or bad news.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 10:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-lldp-options-using-ise-authorization-profile-advanced/m-p/4851289#M582117</guid>
      <dc:creator>netwerkbeheer</dc:creator>
      <dc:date>2023-06-08T10:50:52Z</dc:date>
    </item>
  </channel>
</rss>

