<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the minimum port configuration necessary to profile host? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069784#M588746</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1699627"&gt;@DamianRCL&lt;/a&gt; you'd need to configure MAB&lt;/P&gt;
&lt;P&gt;You'd probably also want to ensure you configure device sensor to learn about the endpoints from the switch and send to ISE in the RADIUS packet, so you have more information to profile the endpoints.&lt;/P&gt;
&lt;P&gt;Refer to the IBNS1.0 configuration for monitor mode and device sensor sections. &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--657806293" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--657806293&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2024 16:52:56 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-04-15T16:52:56Z</dc:date>
    <item>
      <title>What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069768#M588745</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If I simply want to profile network hosts without subjecting them to dot1x, what is the minimum port configuration necessary to accomplish this?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 16:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069768#M588745</guid>
      <dc:creator>DamianRCL</dc:creator>
      <dc:date>2024-04-15T16:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069784#M588746</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1699627"&gt;@DamianRCL&lt;/a&gt; you'd need to configure MAB&lt;/P&gt;
&lt;P&gt;You'd probably also want to ensure you configure device sensor to learn about the endpoints from the switch and send to ISE in the RADIUS packet, so you have more information to profile the endpoints.&lt;/P&gt;
&lt;P&gt;Refer to the IBNS1.0 configuration for monitor mode and device sensor sections. &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--657806293" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--657806293&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 16:52:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069784#M588746</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-04-15T16:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069855#M588748</link>
      <description>&lt;P&gt;Thanks, Rob. I'll take a look.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 18:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5069855#M588748</guid>
      <dc:creator>DamianRCL</dc:creator>
      <dc:date>2024-04-15T18:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5070646#M588770</link>
      <description>&lt;P&gt;If you rely on device sensor then I would say nothing would be required from the switch ports perspective because the device sensor feeds will be sent by the switch to ISE regardless if the port is configured for dot1x or MAB.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 11:22:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5070646#M588770</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-16T11:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5070651#M588771</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/314709"&gt;@Matt Albrecht&lt;/a&gt;&amp;nbsp;- didn't you have a "profile/visibility only" config?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 11:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5070651#M588771</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-16T11:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5071042#M588787</link>
      <description>&lt;P&gt;I do, take a look at the attached template file.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1699627"&gt;@DamianRCL&lt;/a&gt; you may adapt the sensor filters as needed for your environment, the below is an IBNS2.0-based config that puts the interfaces into an authorized state, with no MAB or 802.1x needed, to pull device-sensor information and ship it to ISE for profiling unintrusively.&lt;/P&gt;
&lt;P&gt;The key commands are &lt;STRONG&gt;access-session monitor&lt;/STRONG&gt;, which creates an access session for ALL ports on the switch, and the language of the &lt;STRONG&gt;service-policy&lt;/STRONG&gt; which, essentially, says to immediately authorize the port if a session exists, which it will thanks to the access-session monitor command:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;policy-map type control subscriber ISE_VISIBILITY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;event session-started match-all&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; 10 class always do-until-failure&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp; 10 authorize&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;This results in all interfaces having an up session, in an authorized state without having to interact with the end station at all, and the switch can gather data and send via device-sensor.&lt;/P&gt;
&lt;P&gt;The attached template is distilled directly from here - &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 21:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5071042#M588787</guid>
      <dc:creator>Matt Albrecht</dc:creator>
      <dc:date>2024-04-16T21:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: What is the minimum port configuration necessary to profile host?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5071117#M588794</link>
      <description>&lt;P&gt;This is tremendous, Matt. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 18:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-minimum-port-configuration-necessary-to-profile-host/m-p/5071117#M588794</guid>
      <dc:creator>DamianRCL</dc:creator>
      <dc:date>2024-04-16T18:43:13Z</dc:date>
    </item>
  </channel>
</rss>

