<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HP Aruba Device fingerprinting with Cisco ISE 3.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5119399#M589689</link>
    <description>&lt;P&gt;You don't. Aruba device fingerprinting the switch logs into ClearPass as an API user and uploads its data into the ClearPass endpoint database over HTTPS.&amp;nbsp; This is why you must configure a username/password for ClearPass and have the switch trust ClearPass HTTP certificate.&amp;nbsp; ISE has zero concept of this.&amp;nbsp; You should look at using one of the other probe types like DHCP or SNMP.&lt;/P&gt;
&lt;P&gt;Also FWIW, its far better to send this data to Aruba Central instead.&amp;nbsp; It has much greater device information and visibility than the ClearPass profiler.&amp;nbsp; Then sync those device profile tags as needed from Aruba Central to ClearPass.&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2024 12:05:06 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-05-29T12:05:06Z</dc:date>
    <item>
      <title>HP Aruba Device fingerprinting with Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5114444#M589586</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;We are trying to achieve&amp;nbsp;device profiling with HP Aruba 2930M AOS-S Switch16.10.&lt;/P&gt;
&lt;P&gt;This Aruba OS uses a "Device fingerprinting" function to achieve device profiling, similar to Cisco's&amp;nbsp;"Device Sensor" function in Cisco Switch.&lt;/P&gt;
&lt;P&gt;For&amp;nbsp;Device fingerprinting, it is mentioned that the Prerequisite to Sending Data to ClearPass is "radius-server cppm identity," which requires the&amp;nbsp;username and password of ClearPass to send collected data.&lt;/P&gt;
&lt;P&gt;Now, if I want to send this data to ISE 3.3, what should I do?&lt;/P&gt;
&lt;P&gt;I believe in case of Cisco Switch. The switch gathers raw endpoint data from protocols such as CDP, LLDP &amp;amp; DHCP, and it is made available to ISE through RADIUS accounting messages using "device-sensor accounting" command.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 13:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5114444#M589586</guid>
      <dc:creator>jitendrac</dc:creator>
      <dc:date>2024-05-23T13:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: HP Aruba Device fingerprinting with Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5115247#M589598</link>
      <description>&lt;P&gt;Oh wow - I don't think ISE is expecting to find profiling data in an Aruba AVPair - Aruba should have an option in the AOS switch to send that data in a Cisco AVPair instead. Maybe there is such an option?&amp;nbsp; In ISE there is no configuration to tell ISE which RADIUS attributes to pick apart for profiling - it's assumed to be a Cisco AVPair in the RADIUS Interim-Accounting updates. And the Session ID is also crucial.&lt;/P&gt;
&lt;P&gt;It would be interesting to ask the same question on the Aruba Airheads Community to see what they have to say ... Aruba wants you to use AOS &amp;amp; Clearpass and Cisco want you to use IOS &amp;amp; ISE ... obviously.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you know, you can always just forward the DHCP Discovery packets (e.g. IOS "ip helper") to ISE and decode those with the ISE DHCP Probe. It's an option at least.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 21:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5115247#M589598</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-05-23T21:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: HP Aruba Device fingerprinting with Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5115739#M589617</link>
      <description>&lt;P&gt;See &lt;LI-MESSAGE title="ISE Profiling Design Guide" uid="3739456" url="https://community.cisco.com/t5/security-knowledge-base/ise-profiling-design-guide/m-p/3739456#U3739456" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;for all of the probes and configuration details.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2024 16:14:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5115739#M589617</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-05-24T16:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: HP Aruba Device fingerprinting with Cisco ISE 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5119399#M589689</link>
      <description>&lt;P&gt;You don't. Aruba device fingerprinting the switch logs into ClearPass as an API user and uploads its data into the ClearPass endpoint database over HTTPS.&amp;nbsp; This is why you must configure a username/password for ClearPass and have the switch trust ClearPass HTTP certificate.&amp;nbsp; ISE has zero concept of this.&amp;nbsp; You should look at using one of the other probe types like DHCP or SNMP.&lt;/P&gt;
&lt;P&gt;Also FWIW, its far better to send this data to Aruba Central instead.&amp;nbsp; It has much greater device information and visibility than the ClearPass profiler.&amp;nbsp; Then sync those device profile tags as needed from Aruba Central to ClearPass.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 12:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/hp-aruba-device-fingerprinting-with-cisco-ise-3-3/m-p/5119399#M589689</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-05-29T12:05:06Z</dc:date>
    </item>
  </channel>
</rss>

