<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defining &amp;quot;Common Ports&amp;quot; in &amp;quot;Custom Ports&amp;quot; for in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012675#M587069</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;- perhaps open a TAC case for this - it does look like a defect. I have never even seen this dialogue to be honest.&amp;nbsp; I don't tend to probe for open ports much. As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;said, the ISE prediction of what the OS &lt;EM&gt;might be&lt;/EM&gt;, based on open ports is usually wrong. I'd never rely on that. But I am still unsure if SNMP would be killed off if I disabled NMAP scanning,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 04 Feb 2024 21:31:29 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-02-04T21:31:29Z</dc:date>
    <item>
      <title>Defining "Common Ports" in "Custom Ports" for NMAP scanning...</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5011561#M587014</link>
      <description>&lt;P&gt;Hi everybody;&lt;/P&gt;&lt;P&gt;According to Cisco's documents, if a port is defined in "Common Ports", when you want to add it again to the "Custom Ports" section, the "Port is predefined" error message appears (as shown below). In other words,&amp;nbsp;you cannot use the same port numbers that ISE already configured by Cisco to use in &lt;STRONG&gt;Common&lt;/STRONG&gt; &lt;STRONG&gt;Ports&lt;/STRONG&gt; section.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000.png" style="width: 674px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209464iAA7BE899ED99828C/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All is well; however, when utilizing TCP port 515, it can be successfully added, even though it has been defined as a common port, as you can see below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1000.png" style="width: 402px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209465i5B2D1E955E3BE4DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="1000.png" alt="1000.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 07:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5011561#M587014</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-02-02T07:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Defining "Common Ports" in "Custom Ports" for</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5011910#M587029</link>
      <description>&lt;P&gt;I'm not sure of your specific issue here but what is the use-case for the NMAP probe at all?&amp;nbsp; In my experience it doesn't offer much (especially with operating systems becoming more secure) and has led to a number of mis-categorizations in many of my deployments.&amp;nbsp; I typically disable the probe on new deployments and rely on other less resource intensive probes like Device Sensor (RADIUS), DHCP, and HTTP (for captive portal use-cases).&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 13:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5011910#M587029</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-02T13:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Defining "Common Ports" in "Custom Ports" for</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012674#M587068</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;isn't the NMAP probe also responsible to getting the SNMP data from the endpoints? If you didn't enable NMAP probing, would you lose SNMP?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 21:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012674#M587068</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-02-04T21:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Defining "Common Ports" in "Custom Ports" for</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012675#M587069</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;- perhaps open a TAC case for this - it does look like a defect. I have never even seen this dialogue to be honest.&amp;nbsp; I don't tend to probe for open ports much. As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;said, the ISE prediction of what the OS &lt;EM&gt;might be&lt;/EM&gt;, based on open ports is usually wrong. I'd never rely on that. But I am still unsure if SNMP would be killed off if I disabled NMAP scanning,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 21:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012675#M587069</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-02-04T21:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Defining "Common Ports" in "Custom Ports" for</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012764#M587072</link>
      <description>&lt;P&gt;@&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532" target="_self"&gt;&lt;SPAN class=""&gt;Arne Bier&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;- &lt;SPAN&gt;I am using this feature primarily because the target switch does not support Device Sensor, and the connected devices are 'noname' CCTV cameras. However, they have some distinct open ports. By using something like the following example, I can successfully profile them:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1707109657590.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209572i50ED8A58CC86C5A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1707109657590.png" alt="rezaalikhani_0-1707109657590.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 05:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012764#M587072</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-02-05T05:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Defining "Common Ports" in "Custom Ports" for</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012958#M587083</link>
      <description>&lt;P&gt;Yes, to trigger SNMP on endpoints the NMAP probe needs to be used. SNMP Query Probe only polls NADs.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;: The SNMP Query probe queries NADs, not endpoints. To query the actual endpoints connected to network devices, the NMAP probe must be used. The NMAP probe can trigger an endpoint query based on the detection of open SNMP ports on the endpoint. Endpoint query using SNMP is configurable in the NMAP probe configuration. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId--1464449051" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId--1464449051&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-quot-common-ports-quot-in-quot-custom-ports-quot-for/m-p/5012958#M587083</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-02-05T13:46:11Z</dc:date>
    </item>
  </channel>
</rss>

