<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Profiling based on MAC Address... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4988750#M586026</link>
    <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;Consider a scenario where I want to profile an unknown device with MAC Address parameter of the endpoint. In this regard, we have two options, as show below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000.png" style="width: 622px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206262i630409F7FA1C92C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As my testing experience, if I choose &lt;STRONG&gt;OUI&lt;/STRONG&gt;, I must provide the exact name (not something like &lt;STRONG&gt;OUI STARTWITH AA:AA:AA&lt;/STRONG&gt;) of the vendor that has registered the address with IEEE. &lt;STRONG&gt;Right?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now, if I choose &lt;STRONG&gt;MACAddress&lt;/STRONG&gt;, something with &lt;STRONG&gt;MACADDRESS STARTWITH AA:AA:AA&lt;/STRONG&gt; is valid for matching policy?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2024 07:57:57 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2024-01-03T07:57:57Z</dc:date>
    <item>
      <title>Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4988750#M586026</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;Consider a scenario where I want to profile an unknown device with MAC Address parameter of the endpoint. In this regard, we have two options, as show below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000.png" style="width: 622px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206262i630409F7FA1C92C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As my testing experience, if I choose &lt;STRONG&gt;OUI&lt;/STRONG&gt;, I must provide the exact name (not something like &lt;STRONG&gt;OUI STARTWITH AA:AA:AA&lt;/STRONG&gt;) of the vendor that has registered the address with IEEE. &lt;STRONG&gt;Right?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now, if I choose &lt;STRONG&gt;MACAddress&lt;/STRONG&gt;, something with &lt;STRONG&gt;MACADDRESS STARTWITH AA:AA:AA&lt;/STRONG&gt; is valid for matching policy?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 07:57:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4988750#M586026</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-03T07:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989170#M586034</link>
      <description>&lt;P&gt;Why use only MAC address?&amp;nbsp; Why not also use DHCP or Device Sensor?&amp;nbsp; MAC address / OUI only is really prone to MAC spoofing attacks and doesn't provide much security.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989170#M586034</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-01-03T14:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989173#M586035</link>
      <description>&lt;P&gt;If you only want to match the vendor-ID, you don't need to use the Profiler. You can directly use a condition in your authorization policy:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KarstenIwen_0-1704291643938.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206282iCEF434B108E283F9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KarstenIwen_0-1704291643938.png" alt="KarstenIwen_0-1704291643938.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989173#M586035</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-01-03T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989188#M586036</link>
      <description>&lt;P&gt;I think he facing host with not correct IP' and he decides to use mac profile.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;am I correct?&lt;/P&gt;
&lt;P&gt;His last post mention that the host show not correct IP' and he accpet solution that there is two vlan.&lt;/P&gt;
&lt;P&gt;For me that can be if wrong IP is in different vlan not same one.&lt;/P&gt;
&lt;P&gt;If it different vlan (subnet) then there are two vlan one before authz and other after authz.&lt;/P&gt;
&lt;P&gt;And the ISE list authz host with IP from vlan before authz.&lt;/P&gt;
&lt;P&gt;If both correct and wrong IP in same subnet then there is issue in dhcp profile attribute.&lt;/P&gt;
&lt;P&gt;That what I think&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989188#M586036</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-03T14:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989264#M586040</link>
      <description>&lt;P&gt;I can not use DHCP because the endpoint needs to be assigned static IP address and cannot use Device Sensor because the switch does not support this functionality...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 18:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989264#M586040</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-03T18:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989267#M586041</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;Interesting but does not answer my questions...&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks anyway&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 18:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989267#M586041</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-03T18:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989270#M586042</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005" target="_blank"&gt;@hslai&lt;/A&gt;&amp;nbsp;said, the NAD correctly submits the IP addresses of the second VLAN using RADIUS Accounting Interim Updates but as the NAD does not send it using RADIUS Authentication Request again, ISE does not show the new IP address in its authentication report...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 18:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989270#M586042</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-03T18:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989275#M586043</link>
      <description>&lt;P&gt;Yes friend that case if we use radius attribute profile not dhcp profile.&lt;/P&gt;
&lt;P&gt;Anyway I will make double check and update you.&lt;/P&gt;
&lt;P&gt;Thanks alot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 18:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4989275#M586043</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-03T18:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992147#M586163</link>
      <description>&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992147#M586163</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-01-08T17:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992169#M586165</link>
      <description>&lt;P&gt;I have idea&amp;nbsp;&lt;BR /&gt;you can use DHCP profile&amp;nbsp;&lt;BR /&gt;and add static IP to host using it clinet-id or MAC&amp;nbsp;&lt;BR /&gt;here when DHCP assign IP to host it send copy to ISE&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992169#M586165</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-08T17:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Profiling based on MAC Address...</title>
      <link>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992406#M586171</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your ideas are correct.&lt;/P&gt;
&lt;P&gt;On OUI, take a look at the Cisco Provided Profiler conditions based on it.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-01-08 at 19.31.45.png" style="width: 808px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206736i3A6C7A35FF25DDDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-01-08 at 19.31.45.png" alt="Screenshot 2024-01-08 at 19.31.45.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;On MAC Addresses, I used your condition with ISE 3.2 and it worked! ISE appears to normalize the MAC addresses to dot-separated and all cap.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 03:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/profiling-based-on-mac-address/m-p/4992406#M586171</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2024-01-09T03:34:16Z</dc:date>
    </item>
  </channel>
</rss>

