<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE profiling - DHCP probe in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5086798#M589193</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;to profile devices via DHCP , is it enough to use the device-sensor config for it, or I still need DHCP relay config to forward DHCP packets to ISE?&lt;/P&gt;
&lt;P&gt;device-sensor alone ?&amp;nbsp; or&amp;nbsp; device-sensor + dhcp relay (ip helper-address)&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2024 00:36:18 GMT</pubDate>
    <dc:creator>babalao</dc:creator>
    <dc:date>2024-05-02T00:36:18Z</dc:date>
    <item>
      <title>ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5086798#M589193</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;to profile devices via DHCP , is it enough to use the device-sensor config for it, or I still need DHCP relay config to forward DHCP packets to ISE?&lt;/P&gt;
&lt;P&gt;device-sensor alone ?&amp;nbsp; or&amp;nbsp; device-sensor + dhcp relay (ip helper-address)&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 00:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5086798#M589193</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-05-02T00:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087197#M589203</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1487216"&gt;@babalao&lt;/a&gt; if you have configured device sensor to gather DHCP probe information you do NOT need the ip helper-address on the SVI.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 07:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087197#M589203</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-02T07:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087242#M589205</link>
      <description>&lt;P&gt;can I see how you config the device sensor&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 07:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087242#M589205</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-02T07:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087709#M589212</link>
      <description>&lt;P&gt;Thank yor the replies.&lt;/P&gt;
&lt;P&gt;I am going to configure this as device-sensor for dhcp:&lt;/P&gt;
&lt;P&gt;device-sensor filter-list dhcp list ISE-dhcp&lt;BR /&gt;option name host-name&lt;BR /&gt;option name requested-address&lt;BR /&gt;option name parameter-request-list&lt;BR /&gt;option name class-identifier&lt;BR /&gt;option name client-identifier&lt;BR /&gt;device-sensor filter-spec dhcp include list ISE-dhcp&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I read that but I did no get a clear answer...&lt;/P&gt;
&lt;P&gt;One could test this and if gets dhcp attributes in endpoints means it is working right?&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 13:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087709#M589212</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-05-02T13:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087725#M589213</link>
      <description>&lt;P&gt;After filter-spec, don't forget to enable it with, (I think):&lt;BR /&gt;device-sensor accounting&lt;BR /&gt;device-sensor notify all-changes&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 13:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087725#M589213</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2024-05-02T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087726#M589214</link>
      <description>&lt;P&gt;If you get dhcp attribute in ISE sure you dont need dhcp probe' but I will make double check this case update you tonight&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 13:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087726#M589214</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-02T13:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087805#M589217</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1487216"&gt;@babalao&lt;/a&gt; the DHCP probes (helper-address) provide the following:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RobIngram_0-1714661623948.png" style="width: 475px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/217364i6A5C29EBCC633AEA/image-dimensions/475x253?v=v2" width="475" height="253" role="button" title="RobIngram_0-1714661623948.png" alt="RobIngram_0-1714661623948.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Device sensor will provide the same and does allow you to specify more options to send via the filter list.&lt;/P&gt;
&lt;P&gt;So no point enabling both device sensor and helper-adddress to learn the same information.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 14:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5087805#M589217</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-02T14:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5088028#M589223</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1487216"&gt;@babalao&lt;/a&gt;&amp;nbsp;which model and version of the switch ?&amp;nbsp; There is a bug which has been registered about '&lt;SPAN&gt;device-sensor accounting' command.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A href="https://bst.cisco.com/bugsearch/bug/CSCvd12458?rfs=qvlogin" target="_blank"&gt;https://bst.cisco.com/bugsearch/bug/CSCvd12458?rfs=qvlogin&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Interestingly, according to guide&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/ta-p/3739456#toc-hId-1299141482" target="_blank"&gt;ISE Profiling Design Guide - Cisco Community&lt;/A&gt;&amp;nbsp;this issue started 16.3.x but all the official cisco configuration guides still mention to use&amp;nbsp; 'device-sensor accounting' which is not available at all in any on Cat 9K platform.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-6/configuration_guide/sec/b_176_sec_9300_cg/m9-sec-176-device-sensor.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-6/configuration_guide/sec/b_176_sec_9300_cg/m9-sec-176-device-sensor.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-6/configuration_guide/sec/b_176_sec_9300_cg/m9-sec-176-device-sensor.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-6/configuration_guide/sec/b_176_sec_9300_cg/m9-sec-176-device-sensor.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In our case device sensor is not sending updates to ISE and we are having a TAC case going on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 18:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5088028#M589223</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2024-05-02T18:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE profiling - DHCP probe</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5088802#M589235</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;yesterday I tried it (with 2 2960x) and in both cases I only get DHCP attributes of the endpoint if I put the helper-address. Device sensor did not get info. I shut/no shut the port several times to make DHCP happen and nothing... maybe device-sensor is slower??&lt;/P&gt;
&lt;P&gt;At least in my tests....&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 18:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-profiling-dhcp-probe/m-p/5088802#M589235</guid>
      <dc:creator>babalao</dc:creator>
      <dc:date>2024-05-03T18:00:44Z</dc:date>
    </item>
  </channel>
</rss>

